Falhas do tipo CWE-416

5.131 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2021-3543—A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave fiEPSS 0.3%CVE-2024-22914MEDIUMA heap-use-after-free was found in SWFTools v0.9.2, in the function input at lex.swf5.c:2620. It allows an attacker to cause denial of serviEPSS 0.3%CVE-2026-92021HIGHUse-after-free in the JavaScript Engine: JIT componentEPSS 0.3%CVE-2026-100765HIGHUse-after-free in the JavaScript: WebAssembly componentEPSS 0.3%CVE-2026-49171HIGHWindows Speech Runtime Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-49291HIGHALSA: pcm: Fix races among concurrent hw_params and hw_free callsEPSS 0.3%CVE-2024-9715HIGHTrimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-9719HIGHTrimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-64183MEDIUMOpenEXR has use after free in PyObject_StealAttrStringEPSS 0.3%CVE-2024-45107MEDIUMZDI-CAN-24186: Adobe Acrobat Reader DC Doc Object Use-After-Free Information Disclosure VulnerabilityEPSS 0.3%CVE-2024-9732HIGHTungsten Automation Power PDF XPS File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-22035HIGHtracing: Fix use-after-free in print_graph_function_flags during tracer switchingEPSS 0.3%CVE-2024-9716HIGHTrimble SketchUp Viewer SKP File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-2013HIGHAshlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-23667HIGHBroadcast DVR Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-3176HIGHUse-after-free in io_uring in Linux KernelEPSS 0.3%CVE-2026-12437HIGHUse after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer prEPSS 0.3%CVE-2026-10637MEDIUMUse-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD QueryEPSS 0.3%CVE-2023-52975HIGHscsi: iscsi_tcp: Fix UAF during logout when accessing the shost ipaddressEPSS 0.3%CVE-2025-54225HIGHInDesign Desktop | Use After Free (CWE-416)EPSS 0.3%