Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-66627HIGHWasmi's Linear Memory has a Critical Use After Free VulnerabilityEPSS 0.1%CVE-2025-13120MEDIUMmruby array.c sort_cmp use after freeEPSS 0.1%CVE-2026-54898LOWOj: Use-After-Free in Oj::Parser SAJ Callback via Input MutationEPSS 0.1%CVE-2025-39859HIGHptp: ocp: fix use-after-free bugs causing by ptp_ocp_watchdogEPSS 0.1%CVE-2026-54897LOWOj : Use-After-Free in Oj::Doc Iterators via Reentrant CloseEPSS 0.1%CVE-2026-28733MEDIUMfilemanagement_storage_service has an use after free vulnerabilityEPSS 0.1%CVE-2025-54635MEDIUMVulnerability of returning released pointers in the distributed notification service. Impact: Successful exploitation of this vulnerability EPSS 0.1%CVE-2025-10824MEDIUMaxboe fio init.c __parse_jobs_ini use after freeEPSS 0.1%CVE-2022-25743HIGHMemory corruption in graphics due to use-after-free while importing graphics buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon ConneEPSS 0.1%CVE-2024-49848MEDIUMUse After Free in DSP ServiceEPSS 0.1%CVE-2026-54620LOWsqlite3-ruby has Use-After-Free in SQLite Aggregate Function CallbacksEPSS 0.1%CVE-2026-34764LOWElectron has a use-after-free in offscreen shared texture release() callbackEPSS 0.1%CVE-2026-47505HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an attacker could cause a use-after-free. A suEPSS 0.1%CVE-2026-82325MEDIUMA use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a syEPSS 0.1%CVE-2026-47500HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where improper cleanup of reference countsEPSS 0.1%CVE-2023-33074HIGHUse After Free in AudioEPSS 0.1%CVE-2026-54619LOWsqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different ArityEPSS 0.1%CVE-2026-50263MEDIUMXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow()EPSS 0.1%CVE-2026-95391MEDIUMUse After Free in WiresharkEPSS 0.1%CVE-2025-55308MEDIUMAn issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing JavaScript that calEPSS 0.1%