Falhas do tipo CWE-416

5.043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2024-21339MEDIUMWindows USB Generic Parent Driver Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-4148HIGHExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operatorsEPSS 0.5%CVE-2024-30303HIGHZDI-CAN-23044: Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-40283HIGHAn issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free becEPSS 0.5%CVE-2023-42097HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-42096HIGHFoxit PDF Reader PDF File Parsing Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-42091HIGHFoxit PDF Reader XFA Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-42092HIGHFoxit PDF Reader Doc Object Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-42094HIGHFoxit PDF Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2021-4128MEDIUMWhen transitioning in and out of fullscreen mode, a graphics object was not correctly protected; resulting in memory corruption and a potentEPSS 0.5%CVE-2025-43576HIGHAcrobat Reader | Use After Free (CWE-416)EPSS 0.5%CVE-2023-51612LOWKofax Power PDF JP2 File Parsing Use-After-Free Information Disclosure VulnerabilityEPSS 0.5%CVE-2022-40637HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interactionEPSS 0.5%CVE-2025-1048HIGHSonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-48706LOWVim has heap-use-after-free at /src/charset.c:1770:12 in skipwhiteEPSS 0.5%CVE-2025-48543HIGHIn multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could EPSS 0.5%KEVCVE-2023-4733HIGHUse After Free in vim/vimEPSS 0.5%CVE-2022-1652—Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flEPSS 0.5%CVE-2026-42900HIGHMicrosoft Windows App Store Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2024-49023MEDIUMMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.5%