Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2023-21672HIGHUse After Free in AudioEPSS 0.1%CVE-2023-33021HIGHUse After Free in GraphicsEPSS 0.1%CVE-2026-91805HIGHUse-after-free Vulnerability in Foxit PDF Editor/Reader Page-tree HandlingEPSS 0.1%CVE-2026-91809HIGHFoxit PDF Editor/Reader Annotation Use-After-Free Information Disclosure VulnerabilityEPSS 0.1%CVE-2022-33292HIGHUse after free in Qualcomm IPCEPSS 0.1%CVE-2026-91816HIGHFoxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.1%CVE-2024-31339HIGHIn multiple functions of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalatioEPSS 0.1%CVE-2024-45567HIGHUse After Free in Camera DriverEPSS 0.1%CVE-2022-33263MEDIUMUse after free in CoreEPSS 0.1%CVE-2022-33298MEDIUMUse after free in ModemEPSS 0.1%CVE-2026-10232MEDIUMAssimp ASE File scene.cpp ~aiNode use after freeEPSS 0.1%CVE-2024-45566HIGHUse After Free in Camera DriverEPSS 0.1%CVE-2024-45564HIGHUse After Free in HLOSEPSS 0.1%CVE-2024-43066HIGHUse After Free in HLOSEPSS 0.1%CVE-2026-20507MEDIUMIn Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicEPSS 0.1%CVE-2026-93586LOWImageMagick before 7.1.2-31 Use After Free via ImagesToBlobEPSS 0.1%CVE-2024-23384HIGHUse After Free in Graphics LinuxEPSS 0.1%CVE-2026-49306LOWUAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-20506MEDIUMIn Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicEPSS 0.1%CVE-2026-20517MEDIUMIn geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicEPSS 0.1%