Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-60486MEDIUMA heap use-after-free in the dasher_process function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a DEPSS 0.1%CVE-2022-20561HIGHIn TBD of aud_hal_tunnel.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege EPSS 0.1%CVE-2024-43701HIGHGPU DDK - PowerVR: TLB invalidate UAF of dma_buf imported into multiple GPU devicesEPSS 0.1%CVE-2026-24914MEDIUMType confusion vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-96889HIGHLibrsvg: use-after-free when xml includes have duplicated entitiesEPSS 0.1%CVE-2025-58408MEDIUMGPU DDK - KASAN Read UAF in the PVRSRVBridgeRGXSubmitTransfer2 due to improper error handling codeEPSS 0.1%CVE-2023-20925HIGHIn setUclampMinLocked of PowerSessionManager.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to locaEPSS 0.1%CVE-2026-24099MEDIUMUse after free for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. System softwEPSS 0.1%CVE-2025-10865HIGHGPU DDK - DevmemIntGetReservationData does not ref the PMR it returnsEPSS 0.1%CVE-2026-95834MEDIUMUse after free in the kitty drag and drop protocol when a drag source item is aborted mid-transferEPSS 0.1%CVE-2026-11742LOWUse-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlockEPSS 0.1%CVE-2024-38401HIGHUse After Free in Qualcomm IPCEPSS 0.1%CVE-2026-12365MEDIUMUse-after-free in Zephyr delayable work-queue cancellation under SMP timing raceEPSS 0.1%CVE-2026-2408MEDIUMUse-after-free in Cloud WorkloadsEPSS 0.1%CVE-2026-91790HIGHFoxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure VulnerabilityEPSS 0.1%CVE-2026-47579HIGHThe NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode driver through which a user might trigger a use-after-EPSS 0.1%CVE-2026-49417HIGHMultiple vulnerabilities in the sound(4) mmap pathEPSS 0.1%CVE-2024-23365HIGHUse After Free in SCE-MinkEPSS 0.1%CVE-2026-91793HIGHFoxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure VulnerabilityEPSS 0.1%CVE-2026-91792HIGHFoxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.1%