Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2022-49047HIGHep93xx: clock: Fix UAF in ep93xx_clk_register_gate()EPSS 0.2%CVE-2024-6519HIGHQemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerabilityEPSS 0.2%CVE-2025-59220HIGHWindows Bluetooth Service Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2025-59216HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2023-2162MEDIUMA use-after-free vulnerability was found in iscsi_sw_tcp_session_create in drivers/scsi/iscsi_tcp.c in SCSI sub-component in the Linux KerneEPSS 0.2%CVE-2023-52447HIGHbpf: Defer the free of inner map when necessaryEPSS 0.2%CVE-2025-20006HIGHUse after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentEPSS 0.2%CVE-2022-49669HIGHmptcp: fix race on unaccepted mptcp socketsEPSS 0.2%CVE-2026-92060HIGHUse-after-free in the Internationalization componentEPSS 0.2%CVE-2026-92067HIGHUse-after-free in the Widget: Gtk componentEPSS 0.2%CVE-2026-14390CRITICALUse after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafEPSS 0.2%CVE-2026-92049HIGHUse-after-free in the Widget: Win32 componentEPSS 0.2%CVE-2026-92058HIGHUse-after-free in the Graphics componentEPSS 0.2%CVE-2023-3472HIGHUse after free vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code.EPSS 0.2%CVE-2026-92056HIGHUse-after-free in the Graphics: Text componentEPSS 0.2%CVE-2026-100825HIGHUse-after-free in the JavaScript Engine: JIT componentEPSS 0.2%CVE-2025-6856MEDIUMHDF5 H5FL.c H5FL__reg_gc_list use after freeEPSS 0.2%CVE-2026-100815HIGHUse-after-free in the CSS Parsing and Computation componentEPSS 0.2%CVE-2023-51043HIGHIn the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic comEPSS 0.2%CVE-2024-26875MEDIUMmedia: pvrusb2: fix uaf in pvr2_context_set_notifyEPSS 0.2%