Falhas do tipo CWE-416

5.109 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-16351CRITICALSandbox escape due to use-after-free in the DOM: Navigation componentEPSS 0.4%CVE-2026-16352CRITICALSandbox escape due to use-after-free in the Disability Access APIs componentEPSS 0.4%CVE-2026-5883HIGHUse after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a cEPSS 0.4%CVE-2026-16356CRITICALSandbox escape due to use-after-free in the Disability Access APIs componentEPSS 0.4%CVE-2023-26606HIGHIn the Linux kernel 6.0.8, there is a use-after-free in ntfs_trim_fs in fs/ntfs3/bitmap.c.EPSS 0.4%CVE-2025-27200HIGHAnimate | Use After Free (CWE-416)EPSS 0.4%CVE-2026-13779HIGHUse after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malEPSS 0.4%CVE-2026-19166CRITICALUse after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escEPSS 0.4%CVE-2025-26601HIGHXorg: xwayland: use-after-free in syncinittrigger()EPSS 0.4%CVE-2026-64715MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, EPSS 0.4%CVE-2025-26600HIGHXorg: xwayland: use-after-free in playreleasedevents()EPSS 0.4%CVE-2026-7347HIGHUse after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious netwEPSS 0.4%CVE-2025-26594HIGHX.org: xwayland: use-after-free of the root cursorEPSS 0.4%CVE-2024-27934HIGH*const c_void / ExternalPointer unsoundness leading to use-after-freeEPSS 0.4%CVE-2026-43719MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOSEPSS 0.4%CVE-2025-47986HIGHUniversal Print Management Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-28835MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOEPSS 0.4%CVE-2025-27365MEDIUMIBM MQ Operator denial of serviceEPSS 0.4%CVE-2025-0444MEDIUMUse after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafteEPSS 0.4%CVE-2020-5376MEDIUMDell Inspiron 7347 BIOS versions prior to A13 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to sysEPSS 0.4%