Falhas do tipo CWE-416

5.110 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2021-34968HIGHFoxit PDF Editor transitionToState Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34963HIGHFoxit PDF Editor PolyLine Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34960HIGHFoxit PDF Editor Circle Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34952HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34961HIGHFoxit PDF Editor Ink Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34962HIGHFoxit PDF Editor Caret Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34964HIGHFoxit PDF Editor Polygon Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34974HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34965HIGHFoxit PDF Editor Squiggly Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34959HIGHFoxit PDF Editor Square Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-49699HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34954HIGHFoxit PDF Editor StrikeOut Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34975HIGHFoxit PDF Reader transitionToState Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34956HIGHFoxit PDF Editor Underline Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34955HIGHFoxit PDF Editor Stamp Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2021-34966HIGHFoxit PDF Editor FileAttachment Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-45476HIGHMicrosoft Azure Network Adapter Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-48011HIGHGPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a heap-use-after-free via the flush_ref_samples function at /gpac/src/isomeEPSS 0.3%CVE-2026-19154HIGHUse after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer procesEPSS 0.3%CVE-2025-27492HIGHWindows Secure Channel Elevation of Privilege VulnerabilityEPSS 0.3%