Falhas do tipo CWE-416

5.134 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2022-49129HIGHmt76: mt7921: fix crash when startup fails.EPSS 0.3%CVE-2026-84641HIGHInformation disclosure due to malicious IMAP server responseEPSS 0.3%CVE-2026-10933HIGHUse after free in Audio in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer procesEPSS 0.3%CVE-2026-10961HIGHUse after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer pEPSS 0.3%CVE-2026-10967HIGHUse after free in SurfaceCapture in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderEPSS 0.3%CVE-2021-47356HIGHmISDN: fix possible use-after-free in HFC_cleanup()EPSS 0.3%CVE-2026-10934HIGHUse after free in Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer proEPSS 0.3%CVE-2024-53173HIGHNFSv4.0: Fix a use-after-free problem in the asynchronous open()EPSS 0.3%CVE-2024-30386HIGHJunos OS and Junos OS Evolved: In a EVPN-VXLAN scenario state changes on adjacent systems can cause an l2ald process crashEPSS 0.3%CVE-2022-49419HIGHvideo: fbdev: vesafb: Fix a use-after-free due early fb_info cleanupEPSS 0.3%CVE-2022-49501HIGHusbnet: Run unregister_netdev() before unbind() againEPSS 0.3%CVE-2026-17898HIGHUse after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extensionEPSS 0.3%CVE-2024-38375MEDIUM@fastly/js-compute use-after-free in some host call implementationsEPSS 0.3%CVE-2025-8882HIGHUse after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestEPSS 0.3%CVE-2026-19165HIGHUse after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extensEPSS 0.3%CVE-2025-10500HIGHUse after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a craftEPSS 0.3%CVE-2026-19558HIGHUse after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extensEPSS 0.3%CVE-2024-26907HIGHRDMA/mlx5: Fix fortify source warning while accessing Eth segmentEPSS 0.3%CVE-2026-61929HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69413HIGHWindows USB Audio Class driver (usbaudio.sys) Elevation of Privilege VulnerabilityEPSS 0.3%