Falhas do tipo CWE-416

5.110 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2024-33069HIGHUse After Free in WLAN HostEPSS 0.4%CVE-2025-53133HIGHWindows PrintWorkflowUserSvc Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-20679MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. ProcessingEPSS 0.4%CVE-2022-50386HIGHBluetooth: L2CAP: Fix user-after-freeEPSS 0.4%CVE-2022-49114HIGHscsi: libfc: Fix use after free in fc_exch_abts_resp()EPSS 0.4%CVE-2023-21584MEDIUMAdobe FrameMaker Font Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-53140HIGHWindows Kernel Transaction Manager Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-50167HIGHWindows Hyper-V Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-53721HIGHWindows Connected Devices Platform Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2022-1882—A use-after-free flaw was found in the Linux kernel’s pipes functionality in how a user performs manipulations with the pipe post_one_notifiEPSS 0.4%CVE-2026-91957LOWFreeRDP before 3.31.0 Use-After-Free via smartcard workerEPSS 0.4%CVE-2026-11054HIGHUse after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.4%CVE-2024-3299HIGHOut-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the SLDDRW and SLDPRT file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024EPSS 0.4%CVE-2026-11068HIGHUse after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox viEPSS 0.4%CVE-2026-11074HIGHUse after free in WebRTC in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted EPSS 0.4%CVE-2026-6653HIGHlibxml2: Use after free in xmlParseInternalSubset via improper entity resolution handlingEPSS 0.4%CVE-2026-11147HIGHUse after free in WebML in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.4%CVE-2023-2763HIGHUse-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023EPSS 0.4%CVE-2025-11719CRITICALUse-after-free caused by the native messaging web extension API on WindowsEPSS 0.4%CVE-2021-3760—A flaw was found in the Linux kernel. A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, anEPSS 0.4%