Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2024-23383HIGHUse After Free in Graphics LinuxEPSS 0.1%CVE-2023-33120HIGHUse After Free in AudioEPSS 0.1%CVE-2024-23376MEDIUMUse After Free in ComputerVisionEPSS 0.1%CVE-2024-45540MEDIUMUse After Free in HLOSEPSS 0.1%CVE-2018-11816HIGHUse After Free in VideoEPSS 0.1%CVE-2023-33117HIGHUse After Free in AudioEPSS 0.1%CVE-2023-33118HIGHUse After Free in Automotive AudioEPSS 0.1%CVE-2024-45544MEDIUMUse After Free in Data Network Stack & ConnectivityEPSS 0.1%CVE-2024-23370MEDIUMUse After Free in Automotive MultimediaEPSS 0.1%CVE-2023-43521MEDIUMUse After Free in HLOSEPSS 0.1%CVE-2026-14094HIGHUse after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalaEPSS 0.1%CVE-2026-11891MEDIUMMali GPU Userspace Driver allows access to already freed memoryEPSS 0.1%CVE-2026-12387MEDIUMMali GPU Kernel Driver allows access to already freed memoryEPSS 0.1%CVE-2026-13844HIGHUse after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2026-12449HIGHUse after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escaEPSS 0.1%CVE-2026-13827HIGHUse after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a maliEPSS 0.1%CVE-2024-45554HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2026-34859MEDIUMUAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.EPSS 0.1%CVE-2025-47398HIGHUse After Free in GraphicsEPSS 0.1%CVE-2023-20849MEDIUMIn imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege wEPSS 0.1%