Falhas do tipo CWE-416

5.110 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2023-26392HIGHZDI-CAN-20235: Adobe Substance 3D Stager USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-30416HIGHUse After Free (UAF) vulnerability in the underlying driver module. Impact: Successful exploitation of this vulnerability will affect availaEPSS 0.4%CVE-2023-26410HIGHZDI-CAN-20309: Adobe Substance 3D Designer USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-26384HIGHZDI-CAN-20279: Adobe Substance 3D Stager USD File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-52115HIGHThe iaware module has a Use-After-Free (UAF) vulnerability. Successful exploitation of this vulnerability may affect the system functions.EPSS 0.4%CVE-2020-5348MEDIUMDell Latitude 7202 Rugged Tablet BIOS versions prior to A28 contain a UAF vulnerability in EFI_BOOT_SERVICES in system management mode. A loEPSS 0.4%CVE-2026-43726MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, EPSS 0.4%CVE-2025-48806HIGHMicrosoft MPEG-2 Video Extension Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-2312MEDIUMGRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks afterEPSS 0.4%CVE-2026-43742MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, EPSS 0.4%CVE-2025-49660HIGHWindows Event Tracing Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-21219HIGHInbox COM Objects (Global Memory) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-43734MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, EPSS 0.4%CVE-2025-59206HIGHWindows Resilient File System (ReFS) Deduplication Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-43720MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, EPSS 0.4%CVE-2026-43699MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, EPSS 0.4%CVE-2025-49675HIGHKernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-93834HIGHQemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escapeEPSS 0.4%CVE-2026-58613HIGHWindows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-91749CRITICALUse after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside thEPSS 0.4%