Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2021-47669HIGHcan: vxcan: vxcan_xmit: fix use after free bugEPSS 0.2%CVE-2026-33150HIGHUse After Free in libfuseEPSS 0.2%CVE-2024-52568HIGHA vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versiEPSS 0.2%CVE-2026-17737MEDIUMUse after free in Bluetooth in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer prEPSS 0.2%CVE-2026-17746MEDIUMUse after free in GPU in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to pEPSS 0.2%CVE-2026-74766HIGHNet::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycodeEPSS 0.2%CVE-2022-20581MEDIUMIn the Pixel camera driver, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privEPSS 0.2%CVE-2023-53253HIGHHID: nvidia-shield: Reference hid_device devm allocation of input_dev nameEPSS 0.2%CVE-2026-57240HIGHFoxit PDF Editor/Reader Form Field Use-After-Free Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-24187HIGHNVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerEPSS 0.2%CVE-2023-53363HIGHPCI: Fix use-after-free in pci_bus_release_domain_nr()EPSS 0.2%CVE-2024-41157HIGHLiteos-A has an use after free vulnerabilityEPSS 0.2%CVE-2024-22098MEDIUMAVSession has a use after free vulnerabilityEPSS 0.2%CVE-2026-10926HIGHUse after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to execute arbitrary code viEPSS 0.2%CVE-2026-12921HIGHUse after free in AzeoTech DAQFactoryEPSS 0.2%CVE-2026-12035HIGHUse after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruptionEPSS 0.2%CVE-2026-11304HIGHUse after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafEPSS 0.2%CVE-2025-60465MEDIUMA use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers EPSS 0.2%CVE-2026-11249MEDIUMUse after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtaEPSS 0.2%CVE-2026-10014HIGHUse after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer proEPSS 0.2%