Falhas do tipo CWE-416

5.103 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2023-0358HIGHUse After Free in gpac/gpacEPSS 0.4%CVE-2023-37577HIGHMultiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd filEPSS 0.4%CVE-2026-22264HIGHSuricata detect/alert: heap-use-after-free on alert queue expansionEPSS 0.4%CVE-2023-37573HIGHMultiple use-after-free vulnerabilities exist in the VCD get_vartoken realloc functionality of GTKWave 3.3.115. A specially crafted .vcd filEPSS 0.4%CVE-2024-43472MEDIUMMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-28687MEDIUMImageMagick has a Heap Use-After-Free in ImageMagick MSL decoderEPSS 0.4%CVE-2024-11113HIGHUse after free in Accessibility in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process tEPSS 0.4%CVE-2026-18700MEDIUMUse-After-Free in MongoDB Geospatial Validation Leads to Denial of ServiceEPSS 0.4%CVE-2024-9959HIGHUse after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potEPSS 0.4%CVE-2026-57437LOWNokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetimeEPSS 0.4%CVE-2026-57436LOWNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node typeEPSS 0.4%CVE-2022-1158—A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddEPSS 0.4%CVE-2025-1930HIGHAudioIPC StreamData could trigger a use-after-free in the Browser processEPSS 0.4%CVE-2022-1204—A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protocoEPSS 0.4%CVE-2021-25394MEDIUMA use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radioEPSS 0.4%KEVCVE-2026-56960CRITICALIn multiple locations, there is a possible use-after-free due to a logic error in the code. This could lead to remote escalation of privilegEPSS 0.4%CVE-2022-42408LOWThis vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interactiEPSS 0.4%CVE-2025-21372HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-21860HIGHDsoftbus has a use after free vulnerabilityEPSS 0.4%CVE-2025-0072HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.4%