Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2024-56759HIGHbtrfs: fix use-after-free when COWing tree bock and tracing is enabledEPSS 0.2%CVE-2025-65503HIGHUse after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initEPSS 0.2%CVE-2024-57892HIGHocfs2: fix slab-use-after-free due to dangling pointer dqi_privEPSS 0.2%CVE-2026-9946HIGHUse after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potenEPSS 0.2%CVE-2025-1884HIGHUse-After-Free vulnerability exists in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025EPSS 0.2%CVE-2026-84120MEDIUMUse-after-free in the Audio/Video componentEPSS 0.2%CVE-2025-10729CRITICALUse-after-free vulnerability in Qt SVG qsvghandler.cpp allows denial of service via crafted SVGEPSS 0.2%CVE-2022-20568HIGHIn (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilegEPSS 0.2%CVE-2025-21856HIGHs390/ism: add release function for struct deviceEPSS 0.2%CVE-2026-7111HIGHText::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruptionEPSS 0.2%CVE-2024-9826HIGHAutodesk AutoCAD ACTranslators 3DM File Parsing Use-After-Free Code Execution VulnerabilityEPSS 0.2%CVE-2024-8590HIGHAutodesk AutoCAD 3DM File Parsing Use-After-Free Code Execution VulnerabilityEPSS 0.2%CVE-2024-8595HIGHAutodesk AutoCAD MODEL File Parsing Use-After-Free Code Execution VulnerabilityEPSS 0.2%CVE-2026-8201MEDIUMUse-After-Free in MongoDB FLE Query Analysis When Processing Positional Projections on Encrypted FieldsEPSS 0.2%CVE-2022-23090HIGHAIO credential reference count leakEPSS 0.2%CVE-2025-7993HIGHAshlar-Vellum Cobalt LI File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.2%CVE-2024-0671MEDIUMMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2024-56561HIGHPCI: endpoint: Fix PCI domain ID release in pci_epc_destroy()EPSS 0.2%CVE-2025-20046HIGHUse after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentEPSS 0.2%CVE-2026-7920HIGHUse after free in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentiEPSS 0.2%