Falhas do tipo CWE-416

5.110 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2024-50264HIGHvsock/virtio: Initialization of the dangling pointer occurring in vsk->transEPSS 0.4%CVE-2023-43552CRITICALUse After Free in WLAN Host CommunicationEPSS 0.4%CVE-2023-26426HIGHAdobe Illustrator (Beta) has a UAF vulnerability when parsing SVG files Arbitrary code executionEPSS 0.4%CVE-2026-61860MEDIUMImageMagick before 7.1.2-26 Use-After-Free via freetypeEPSS 0.4%CVE-2026-9114HIGHUse after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via EPSS 0.4%CVE-2025-27160HIGHAcrobat Reader | Use After Free (CWE-416)EPSS 0.4%CVE-2026-13035HIGHUse after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a maliciEPSS 0.4%CVE-2024-27929HIGHUse After Free in SixLabors.ImageSharpEPSS 0.4%CVE-2025-27159HIGHAcrobat Reader | Use After Free (CWE-416)EPSS 0.4%CVE-2026-14108HIGHUse after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.4%CVE-2025-27174HIGHAcrobat Reader | Use After Free (CWE-416)EPSS 0.4%CVE-2025-13845HIGHCWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file)EPSS 0.4%CVE-2021-3715—A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changEPSS 0.4%CVE-2023-34475—A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick userEPSS 0.4%CVE-2026-4684HIGHRace condition, use-after-free in the Graphics: WebRender componentEPSS 0.4%CVE-2025-49726HIGHWindows Notification Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-45138HIGHSubstance3D - Stager | Use After Free (CWE-416)EPSS 0.4%CVE-2024-43374MEDIUMVim heap-use-after-free in src/arglist.c:207EPSS 0.4%CVE-2022-3636MEDIUMLinux Kernel Ethernet mtk_ppe.c __mtk_ppe_check_skb use after freeEPSS 0.4%CVE-2026-10638MEDIUMUse-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or errorEPSS 0.4%