Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2024-38399HIGHUse After Free in GraphicsEPSS 0.1%CVE-2024-40885HIGHUse after free in the UEFI firmware of some Intel(R) Server M20NTP BIOS may allow a privileged user to potentially enable escalation of privEPSS 0.1%CVE-2025-55308MEDIUMAn issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing JavaScript that calEPSS 0.1%CVE-2023-22383MEDIUMUse After Free in CameraEPSS 0.1%CVE-2026-87533HIGHUse after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox viEPSS 0.1%CVE-2026-63380MEDIUMLibevent: Null Pointer Dereference in `evws_new_session`EPSS 0.1%CVE-2026-13778HIGHUse after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via a malicious pEPSS 0.1%CVE-2023-22668MEDIUMUse After Free in AudioEPSS 0.1%CVE-2026-17716HIGHUse after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via maliciEPSS 0.1%CVE-2022-32607MEDIUMIn aee, there is a possible use after free due to a missing bounds check. This could lead to local escalation of privilege with System execuEPSS 0.1%CVE-2025-25177MEDIUMGPU DDK - Roll-back of pvr_exp_fence not in finalised state can cause UAFEPSS 0.1%CVE-2024-47892HIGHGPU DDK - UAF of kernel memory in PMRUnlockPhysAddressesOSMem for on-demand non-4KB PMRs in system memory (UMA)EPSS 0.1%CVE-2024-46971HIGHGPU DDK - UAF of memory in PMRUnlockSysPhysAddressesLocalMem for on-demand PMRs on PCI (LMA) systemsEPSS 0.1%CVE-2026-17862HIGHUse after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2026-95315HIGHUse after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the saEPSS 0.1%CVE-2026-17699HIGHUse after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a malicEPSS 0.1%CVE-2025-55309MEDIUMAn issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can contain JavaScriEPSS 0.1%CVE-2026-15905HIGHUse after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a maliciEPSS 0.1%CVE-2026-14018HIGHUse after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2026-26071MEDIUMEVerest: OCPP 2.0.1 EVCCID Data Race Leads to Heap Use‑After‑FreeEPSS 0.1%