Falhas do tipo CWE-416

5.134 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-21703HIGHnetem: Update sch->q.qlen before qdisc_tree_reduce_backlog()EPSS 0.3%CVE-2025-13014HIGHUse-after-free in the Audio/Video componentEPSS 0.3%CVE-2022-49465HIGHblk-throttle: Set BIO_THROTTLED when bio has been throttledEPSS 0.3%CVE-2026-8550MEDIUMUse after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process toEPSS 0.3%CVE-2025-27181HIGHSubstance3D - Modeler | Use After Free (CWE-416)EPSS 0.3%CVE-2024-47814LOWuse-after-free when closing buffers in VimEPSS 0.3%CVE-2024-53057HIGHnet/sched: stop qdisc_tree_reduce_backlog on TC_H_ROOTEPSS 0.3%CVE-2021-47634HIGHubi: Fix race condition between ctrl_cdev_ioctl and ubi_cdev_ioctlEPSS 0.3%CVE-2026-11937LOWSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.3%CVE-2025-49733HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-49725HIGHWindows Notification Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-34970MEDIUMMali GPU Kernel Driver Allows Improper GPU Memory Processing OperationsEPSS 0.3%CVE-2023-52974HIGHscsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddressEPSS 0.3%CVE-2025-55678HIGHDirectX Graphics Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2023-22360HIGHUse-after free vulnerability exists in Screen Creator Advance 2 Ver.0.1.1.4 Build01 and earlier due to lack of error handling process even wEPSS 0.3%CVE-2023-33200MEDIUMMali GPU Kernel Driver Allows Improper GPU Memory Processing OperationsEPSS 0.3%CVE-2026-16362HIGHUse-after-free in the WebRTC: Audio/Video componentEPSS 0.3%CVE-2025-54105HIGHMicrosoft Brokering File System Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-55318HIGHIn multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additionEPSS 0.3%CVE-2021-42706HIGHAzeoTech DAQFactoryEPSS 0.3%