Falhas do tipo CWE-416

5.110 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-58737HIGHRemote Desktop Protocol Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-55549HIGHxsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes.EPSS 0.4%CVE-2025-24855HIGHnumbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but neveEPSS 0.4%CVE-2026-10923HIGHUse after free in WebAppInstalls in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via aEPSS 0.4%CVE-2025-58730HIGHInbox COM Objects (Global Memory) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-58733HIGHInbox COM Objects (Global Memory) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-58738HIGHInbox COM Objects (Global Memory) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-58734HIGHInbox COM Objects (Global Memory) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-50312MEDIUMWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-22956HIGHswftools 0.9.2 was discovered to contain a heap-use-after-free vulnerability via the function removeFromTo at swftools/src/swfc.c:838EPSS 0.4%CVE-2026-49167MEDIUMWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-11791MEDIUM389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()EPSS 0.4%CVE-2025-58731HIGHInbox COM Objects (Global Memory) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-58736HIGHInbox COM Objects (Global Memory) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2021-34968HIGHFoxit PDF Editor transitionToState Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34954HIGHFoxit PDF Editor StrikeOut Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34962HIGHFoxit PDF Editor Caret Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-22004HIGHnet: atm: fix use after free in lec_send()EPSS 0.3%CVE-2024-12548LOWTungsten Automation Power PDF JP2 File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.3%CVE-2021-34955HIGHFoxit PDF Editor Stamp Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%