Falhas do tipo CWE-416

5.127 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2020-10720—A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crashEPSS 0.3%CVE-2026-91724HIGHUse after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentEPSS 0.3%CVE-2024-39528MEDIUMJunos OS and Junos OS Evolved: Concurrent deletion of a routing-instance and receipt of an SNMP request cause an RPD crashEPSS 0.3%CVE-2026-7897HIGHUse after free in Mobile in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specificEPSS 0.3%CVE-2026-5284HIGHUse after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to executEPSS 0.3%CVE-2026-20687HIGHA use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadEPSS 0.3%CVE-2022-49416HIGHwifi: mac80211: fix use-after-free in chanctx codeEPSS 0.3%CVE-2025-46709HIGHGPU DDK - Security fix for PP-171570 can lead to an uninitialised pointer dereference and memory leakEPSS 0.3%CVE-2026-7929HIGHUse after free in MediaRecording in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specifiEPSS 0.3%CVE-2025-8578HIGHUse after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafteEPSS 0.3%CVE-2023-5427HIGHMali GPU Kernel Driver allows improper GPU processing operationsEPSS 0.3%CVE-2026-47924MEDIUMAcrobat Reader | Use After Free (CWE-416)EPSS 0.3%CVE-2026-25189HIGHWindows DWM Core Library Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-6817HIGHUse-after-free in Linux kernel's netfilter: nf_tables componentEPSS 0.3%CVE-2026-80162MEDIUMAcrobat Reader | Use After Free (CWE-416)EPSS 0.3%CVE-2025-43589HIGHInDesign Desktop | Use After Free (CWE-416)EPSS 0.3%CVE-2026-81984MEDIUMAcrobat Reader | Use After Free (CWE-416)EPSS 0.3%CVE-2024-43758HIGHIllustrator | Use After Free (CWE-416)EPSS 0.3%CVE-2023-3439MEDIUMA flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resource when a netEPSS 0.3%CVE-2026-27909HIGHWindows Search Service Elevation of Privilege VulnerabilityEPSS 0.3%