Falhas do tipo CWE-416

5.110 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-79219HIGHUse after free in Bluetooth in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitEPSS 0.4%CVE-2026-17875HIGHUse after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.4%CVE-2026-12291HIGHUse-after-free in the Networking: HTTP componentEPSS 0.4%CVE-2026-87625HIGHUse after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary coEPSS 0.4%CVE-2026-92005MEDIUMUse-after-free in the Audio/Video: Web Codecs componentEPSS 0.4%CVE-2025-59226HIGHMicrosoft Office Visio Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-59223HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-26649HIGHWindows Secure Channel Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-0232MEDIUMSqlite: use-after-free bug in jsonparseaddnodearrayEPSS 0.4%CVE-2025-59225HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-59238HIGHMicrosoft PowerPoint Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-7530CRITICALIncorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.EPSS 0.4%CVE-2025-59224HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-1050—A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commaEPSS 0.4%CVE-2026-27220HIGHAcrobat Reader | Use After Free (CWE-416)EPSS 0.4%CVE-2026-10655MEDIUMUse-after-free race in SNTP async client when closing the socket while the socket service is still polling itEPSS 0.4%CVE-2026-21921HIGHJunos OS and Junos OS Evolved: When telemetry collectors are frequently subscribing and unsubscribing to sensors chassisd or rpd will crashEPSS 0.4%CVE-2023-26384HIGHZDI-CAN-20279: Adobe Substance 3D Stager USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-52115HIGHThe iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.EPSS 0.4%CVE-2023-26414HIGHZDI-CAN-20316: Adobe Substance 3D Designer USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%