Falhas do tipo CWE-416

5.043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-57236LOWNokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exceptionEPSS 0.4%CVE-2026-79064CRITICALUse after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execuEPSS 0.4%CVE-2016-9401MEDIUMpopd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.EPSS 0.4%CVE-2024-38137HIGHWindows Resource Manager PSM Service Extension Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-0799MEDIUMLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3701, allowing attackers to cause a denial-of-service via a crafted EPSS 0.4%CVE-2025-62557HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-11756HIGHUse after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised the renderer process EPSS 0.4%CVE-2024-49526HIGHAnimate | Use After Free (CWE-416)EPSS 0.4%CVE-2022-0487—A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. IEPSS 0.4%CVE-2023-38078LOWKofax Power PDF U3D File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-58728HIGHWindows Bluetooth Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-50175HIGHWindows Digital Media Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-7425HIGHLibxslt: libxml2: heap use-after-free in libxslt caused by atype corruption in xmlattrptrEPSS 0.4%CVE-2025-1706HIGHGPU DDK - Improper locking when accessing the pvr_exp_fence objectEPSS 0.4%CVE-2023-51557HIGHFoxit PDF Reader AcroForm Doc Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-51552HIGHFoxit PDF Reader AcroForm Signature Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-51556HIGHFoxit PDF Reader AcroForm Doc Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2020-16119MEDIUMDCCP CCID structure use-after-freeEPSS 0.4%CVE-2023-51551HIGHFoxit PDF Reader AcroForm Signature Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-1454LOWOpensc: memory use after free in authentic driver when updating token infoEPSS 0.4%