Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-14018HIGHUse after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2025-5991LOWUse after free in QHttp2ProtocolHandlerEPSS 0.1%CVE-2026-71968HIGHOP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCURRENTEPSS 0.1%CVE-2026-91791HIGHFoxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.1%CVE-2025-14569MEDIUMggml-org whisper.cpp common-whisper.cpp read_audio_data use after freeEPSS 0.1%CVE-2023-20920HIGHIn queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of priviEPSS 0.1%CVE-2026-4752MEDIUMUse After Free in No-Chicken Echo-MateEPSS 0.1%CVE-2022-22077HIGHMemory corruption in graphics due to use-after-free in graphics dispatcher logic in Snapdragon MobileEPSS 0.1%CVE-2026-17932MEDIUMUse after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive iEPSS 0.1%CVE-2026-57842HIGHNetBSD COMPAT_NETBSD32 Double Free / Use-After-Free via recvmsg() msg_iovlenEPSS 0.1%CVE-2026-56117MEDIUMdhcpcd Heap Use-After-Free via Control Socket HandlingEPSS 0.1%CVE-2026-91799HIGHFoxit Editor/Reader Array resetForm Use-After-Free VulnerabilityEPSS 0.1%CVE-2026-87514HIGHUse after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via aEPSS 0.1%CVE-2026-13713MEDIUMYAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stackEPSS 0.1%CVE-2026-47516HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successfEPSS 0.1%CVE-2026-79245HIGHUse after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compromised the renderer process to execute arEPSS 0.1%CVE-2026-47551HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause a use-after-free.EPSS 0.1%CVE-2026-47560HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a use-after-freEPSS 0.1%CVE-2024-45553HIGHUse After Free in DSP ServicesEPSS 0.1%CVE-2024-33059MEDIUMUse After Free in Computer VisionEPSS 0.1%