Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-58311MEDIUMUAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentialiEPSS 0.1%CVE-2025-20743MEDIUMIn clkdbg, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a maliciouEPSS 0.1%CVE-2026-56914HIGHIn multiple locations, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no EPSS 0.1%CVE-2025-20799HIGHIn c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor EPSS 0.1%CVE-2026-20443MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2025-20744MEDIUMIn pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious aEPSS 0.1%CVE-2018-9417HIGHIn f_hidg_read and hidg_disable of f_hid.c, there is a possible use-after-free due to improper locking. This could lead to local escalation EPSS 0.1%CVE-2026-11115HIGHUse after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2025-36922MEDIUMIn bigo_map of bigo_iommu.c, there is a possible information disclosure due to a use after free. This could lead to local escalation of priEPSS 0.1%CVE-2024-29787HIGHIn lwis_process_transactions_in_queue of lwis_transaction.c, there is a possible use after free due to a use after free. This could lead to EPSS 0.1%CVE-2025-47333MEDIUMUse After Free in HLOSEPSS 0.1%CVE-2025-20745MEDIUMIn apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actoEPSS 0.1%CVE-2026-24082HIGHUse After Free in Automotive GPUEPSS 0.1%CVE-2024-23716HIGHIn DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race condition. This could lead to local escalation EPSS 0.1%CVE-2026-21380HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2024-47033HIGHIn lwis_allocator_free of lwis_allocator.c, there is a possible memory corruption due to a use after free. This could lead to local escalatiEPSS 0.1%CVE-2018-9344HIGHIn several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalationEPSS 0.1%CVE-2025-47381HIGHUse After Free in Automotive AudioEPSS 0.1%CVE-2025-47376HIGHUse After Free in Automotive AudioEPSS 0.1%CVE-2025-47386HIGHUse After Free in Automotive AudioEPSS 0.1%