Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2022-47371MEDIUMIn bt driver, there is a thread competition leads to early release of resources to be accessed. This could lead to local denial of service iEPSS 0.1%CVE-2025-59617MEDIUMUse After Free in Computer VisionEPSS 0.1%CVE-2025-59615MEDIUMUse After Free in Computer VisionEPSS 0.1%CVE-2025-59616MEDIUMUse After Free in Computer VisionEPSS 0.1%CVE-2025-22438HIGHIn afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local escalation of priviEPSS 0.1%CVE-2025-47315HIGHUse After Free in Automotive Software platform based on QNXEPSS 0.1%CVE-2025-47327HIGHUse After Free in CameraEPSS 0.1%CVE-2025-27077HIGHUse After Free in Automotive Software platform based on QNXEPSS 0.1%CVE-2025-47350HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2025-47354HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2023-21055MEDIUMIn dit_hal_ioctl of dit.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege withEPSS 0.1%CVE-2025-27037HIGHUse After Free in Camera DriverEPSS 0.1%CVE-2024-40651HIGHIn TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the EPSS 0.1%CVE-2024-40649HIGHIn TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the EPSS 0.1%CVE-2025-54626MEDIUMPointer dangling vulnerability in the cjwindow module. Impact: Successful exploitation of this vulnerability may affect function stability.EPSS 0.1%CVE-2025-20779HIGHIn display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege if a malicious actoEPSS 0.1%CVE-2025-47337MEDIUMUse After Free in Camera DriverEPSS 0.1%CVE-2023-40107HIGHIn ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilEPSS 0.1%CVE-2025-47336MEDIUMUse After Free in Camera DriverEPSS 0.1%CVE-2024-23658MEDIUMIn camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution EPSS 0.1%