Falhas do tipo CWE-416

5.129 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-91716CRITICALUse after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via aEPSS 0.3%CVE-2026-100790HIGHUse-after-free in the XSLT componentEPSS 0.3%CVE-2023-26991HIGHSWFTools v0.9.2 was discovered to contain a stack-use-after-scope in the swf_ReadSWF2 function in lib/rfxswf.c.EPSS 0.3%CVE-2022-45885HIGHAn issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-aEPSS 0.3%CVE-2026-100777HIGHUse-after-free in the Graphics: Canvas2D componentEPSS 0.3%CVE-2026-100791HIGHUse-after-free in the DOM: Core & HTML componentEPSS 0.3%CVE-2026-100780HIGHUse-after-free in the DOM: Core & HTML componentEPSS 0.3%CVE-2026-100757HIGHUse-after-free in the Widget componentEPSS 0.3%CVE-2026-100772HIGHUse-after-free in the DOM: Core & HTML componentEPSS 0.3%CVE-2026-91710CRITICALUse after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sanEPSS 0.3%CVE-2026-100767HIGHUse-after-free in the Networking: Cache componentEPSS 0.3%CVE-2026-100789HIGHUse-after-free in the Graphics: Canvas2D componentEPSS 0.3%CVE-2026-100776HIGHUse-after-free in the JavaScript: WebAssembly componentEPSS 0.3%CVE-2026-100785HIGHUse-after-free in the DOM: Core & HTML componentEPSS 0.3%CVE-2026-92046HIGHUse-after-free in the Graphics componentEPSS 0.3%CVE-2026-100770CRITICALSandbox escape due to use-after-free in the DOM: Content Processes componentEPSS 0.3%CVE-2026-100778CRITICALSandbox escape due to use-after-free in the DOM: Core & HTML componentEPSS 0.3%CVE-2026-100779HIGHUse-after-free in the XSLT componentEPSS 0.3%CVE-2026-100762CRITICALSandbox escape due to use-after-free in the DOM: Content Processes componentEPSS 0.3%CVE-2026-100774HIGHUse-after-free in the DOM: Core & HTML componentEPSS 0.3%