Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2022-39853MEDIUMA use after free vulnerability in perf-mgr driver prior to SMR Oct-2022 Release 1 allows attacker to cause memory access fault.EPSS 0.1%CVE-2022-25666MEDIUMMemory corruption due to use after free in service while trying to access maps by different threads in Snapdragon Auto, Snapdragon Compute, EPSS 0.1%CVE-2026-34983LOWWasmtime has a use-after-free bug after cloning `wasmtime::Linker`EPSS 0.1%CVE-2026-100503MEDIUMGhidra through 12.1.4 Heap Use-After-Free in DecompilerEPSS 0.1%CVE-2026-21102CRITICALUse after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.EPSS 0.1%CVE-2024-27213HIGHIn BroadcastSystemMessage of servicemgr.cpp, there is a possible Remote Code Execution due to a use after free. This could lead to local escEPSS 0.1%CVE-2024-43057HIGHUse After Free in MProcEPSS 0.1%CVE-2024-45580HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2024-43062HIGHUse After Free in Camera LinuxEPSS 0.1%CVE-2024-23382HIGHUse After Free in Graphics LinuxEPSS 0.1%CVE-2026-97222MEDIUMGnumeric: gnumeric: heap use-after-free when opening a malformed workbookEPSS 0.1%CVE-2024-43061HIGHUse After Free in AudioEPSS 0.1%CVE-2025-21424HIGHUse After Free in NPUEPSS 0.1%CVE-2024-43059HIGHUse After Free in Automotive MultimediaEPSS 0.1%CVE-2024-53023HIGHUse After Free in Automotive Android OSEPSS 0.1%CVE-2026-47597HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module Resource Server where an unprivileEPSS 0.1%CVE-2022-33292HIGHUse after free in Qualcomm IPCEPSS 0.1%CVE-2023-33029HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2023-33021HIGHUse After Free in GraphicsEPSS 0.1%CVE-2026-91816HIGHFoxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.1%