Falhas do tipo CWE-416

5.103 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-46205HIGHA heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of ServicEPSS 0.4%CVE-2025-5958HIGHUse after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.4%CVE-2024-30031HIGHWindows CNG Key Isolation Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-3066HIGHUse after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed a remote attacker to potentially exploit heap corruption viEPSS 0.4%CVE-2024-9243HIGHFoxit PDF Reader AcroForm Doc Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-44805MEDIUMWindows Network Controller (NC) Host Agent Denial of Service VulnerabilityEPSS 0.4%CVE-2022-50363CRITICALskmsg: pass gfp argument to alloc_sk_msg()EPSS 0.4%CVE-2025-58719MEDIUMWindows Connected Devices Platform Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2022-1934MEDIUMUse After Free in mruby/mrubyEPSS 0.4%CVE-2023-49554MEDIUMUse After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in tEPSS 0.4%CVE-2026-4711CRITICALUse-after-free in the Widget: Cocoa componentEPSS 0.4%CVE-2026-3921HIGHUse after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via EPSS 0.4%CVE-2026-20822HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-12442HIGHUse after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crEPSS 0.4%CVE-2025-59290HIGHWindows Bluetooth Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-20865HIGHWindows Management Services Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-56373MEDIUMImageMagick - Use-After-Free Write in PDB DecoderEPSS 0.4%CVE-2022-2742HIGHUse after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker who convinced a user tEPSS 0.4%CVE-2026-20842HIGHMicrosoft DWM Core Library Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-44095—Use-After-Free (UAF) vulnerability in the surfaceflinger module.Successful exploitation of this vulnerability can cause system crash.EPSS 0.4%