Falhas do tipo CWE-416

5.043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2023-36804HIGHWindows GDI Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2024-10459MEDIUMAn attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerabilitEPSS 0.6%CVE-2025-54908HIGHMicrosoft PowerPoint Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-2766CRITICALUse-after-free in the JavaScript Engine: JIT componentEPSS 0.6%CVE-2026-2767HIGHUse-after-free in the JavaScript: WebAssembly componentEPSS 0.6%CVE-2026-2765CRITICALUse-after-free in the JavaScript Engine componentEPSS 0.6%CVE-2026-2758CRITICALUse-after-free in the JavaScript: GC componentEPSS 0.6%CVE-2026-32942HIGHPJSIP has ICE session use-after-free race conditionsEPSS 0.6%CVE-2026-2772HIGHUse-after-free in the Audio/Video: Playback componentEPSS 0.6%CVE-2026-2764CRITICALJIT miscompilation, use-after-free in the JavaScript Engine: JIT componentEPSS 0.6%CVE-2026-2763CRITICALUse-after-free in the JavaScript Engine componentEPSS 0.6%CVE-2026-2770HIGHUse-after-free in the DOM: Bindings (WebIDL) componentEPSS 0.6%CVE-2025-14321CRITICALUse-after-free in the WebRTC: Signaling componentEPSS 0.6%CVE-2025-58718HIGHRemote Desktop Client Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-2769HIGHUse-after-free in the Storage: IndexedDB componentEPSS 0.6%CVE-2024-7000HIGHUse after free in CSS in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gesturEPSS 0.6%CVE-2026-74944CRITICALUse-after-free in the DOM: Core & HTML componentEPSS 0.6%CVE-2026-67300HIGHFreeRDP before 3.29.0 Use-After-Free via async message proxyEPSS 0.6%CVE-2024-4770HIGHWhen saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126,EPSS 0.6%CVE-2026-74936CRITICALUse-after-free in the JavaScript: WebAssembly componentEPSS 0.6%