Falhas do tipo CWE-416

5.134 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-10894HIGHUse after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer proceEPSS 0.3%CVE-2026-10884HIGHUse after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pEPSS 0.3%CVE-2025-6640HIGHPDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-6645HIGHPDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-10918HIGHUse after free in Viz in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentiaEPSS 0.3%CVE-2025-6644HIGHPDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-94055LOWExim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.EPSS 0.3%CVE-2026-10919HIGHUse after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentEPSS 0.3%CVE-2025-6661HIGHPDF-XChange Editor App Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.3%CVE-2023-1872HIGHUse-after-free in Linux kernel's io_uring subsystemEPSS 0.3%CVE-2026-34770HIGHElectron: Use-after-free in PowerMonitor on Windows and macOSEPSS 0.3%CVE-2026-78376HIGHWebkitgtk: use-after-free of jscvalue function parametersEPSS 0.3%CVE-2024-50267HIGHUSB: serial: io_edgeport: fix use after free in debug printkEPSS 0.3%CVE-2022-49489HIGHdrm/msm/disp/dpu1: set vbif hw config to NULL to avoid use after memory free during pm runtime resumeEPSS 0.3%CVE-2023-4623HIGHUse-after-free in Linux kernel's net/sched: sch_hfsc (HFSC qdisc traffic control) componentEPSS 0.3%CVE-2022-49288HIGHALSA: pcm: Fix races among concurrent prealloc proc writesEPSS 0.3%CVE-2023-4015HIGHUse-after-free in Linux kernel's netfilter: nf_tables componentEPSS 0.3%CVE-2024-1085HIGHUse-after-free in Linux kernel's netfilter: nf_tables componentEPSS 0.3%CVE-2026-22851MEDIUMFreeRDP RDPGFX ResetGraphics race leads to use-after-free in SDL client (sdl->primary)EPSS 0.3%CVE-2026-7970HIGHUse after free in TopChrome in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to poEPSS 0.3%