Falhas do tipo CWE-416

5.142 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-84567MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. AnEPSS 0.2%CVE-2026-21486HIGHUse After Free and Heap-based Buffer Overflow and Integer Overflow or Wraparound and Out-of-bounds Write in iccDEVEPSS 0.2%CVE-2026-19108MEDIUMMZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after freeEPSS 0.2%CVE-2026-12445HIGHUse after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extensEPSS 0.2%CVE-2026-65377MEDIUMA memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27EPSS 0.2%CVE-2026-17891MEDIUMUse after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer procesEPSS 0.2%CVE-2026-84552MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden GEPSS 0.2%CVE-2025-39863HIGHwifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info workEPSS 0.2%CVE-2024-41160HIGHLiteos-A has an use after free vulnerabilityEPSS 0.2%CVE-2024-1067HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2023-53263HIGHdrm/nouveau/disp: fix use-after-free in error handling of nouveau_connector_createEPSS 0.2%CVE-2026-77235HIGHMissing privilege check in SecureContext_FreeContext in FreeRTOS-KernelEPSS 0.2%CVE-2024-10074HIGHLiteos_a has an use after free vulnerabilityEPSS 0.2%CVE-2025-23098HIGHAn issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor EPSS 0.2%CVE-2022-50421HIGHrpmsg: char: Avoid double destroy of default endpointEPSS 0.2%CVE-2024-23354HIGHUse After Free in Graphics LinuxEPSS 0.2%CVE-2026-14048MEDIUMUse after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially EPSS 0.2%CVE-2026-73071LOWVim: Use-after-free in JSON DecodingEPSS 0.2%CVE-2026-13879MEDIUMUse after free in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sEPSS 0.2%CVE-2023-5447MEDIUMUse-After-Free in Service for Hardware Support App for Fingerprint DriverEPSS 0.2%