Falhas do tipo CWE-416

5.043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2023-5574HIGHXorg-x11-server: use-after-free bug in damagedestroyEPSS 0.6%CVE-2025-29977HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-49703HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.6%CVE-2022-3309MEDIUMUse after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in EPSS 0.6%CVE-2024-54499HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tEPSS 0.6%CVE-2024-35870CRITICALsmb: client: fix UAF in smb2_reconnect_server()EPSS 0.6%CVE-2024-9255HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-7722LOWFoxit PDF Reader Doc Object Use-After-Free Information Disclosure VulnerabilityEPSS 0.6%CVE-2024-9250HIGHFoxit PDF Reader AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.6%CVE-2021-47232CRITICALcan: j1939: fix Use-after-Free, hold skb ref while in useEPSS 0.6%CVE-2022-40638HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interactionEPSS 0.6%CVE-2022-40639HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interactionEPSS 0.6%CVE-2024-6997HIGHUse after free in Tabs in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestuEPSS 0.6%CVE-2024-6292HIGHUse after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a craftEPSS 0.6%CVE-2024-6998HIGHUse after free in User Education in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specifiEPSS 0.6%CVE-2025-62563HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-3856HIGHA use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects FirEPSS 0.6%CVE-2023-4622HIGHUse-after-free in Linux kernel's af_unix componentEPSS 0.6%CVE-2026-12443HIGHUse after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafEPSS 0.6%CVE-2024-56640CRITICALnet/smc: fix LGR and link use-after-free issueEPSS 0.6%