Falhas do tipo CWE-416

5.043 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2023-22402MEDIUMJunos OS Evolved: The kernel might restart in a BGP scenario where "bgp auto-discovery" is enabled and such a neighbor flapsEPSS 0.5%CVE-2024-45063CRITICALMultiple issues in ctl(4) CAM Target LayerEPSS 0.5%CVE-2024-21439HIGHWindows Telephony Server Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2025-62555HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.5%CVE-2022-3297HIGHUse After Free in vim/vimEPSS 0.5%CVE-2025-7657HIGHUse after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a craEPSS 0.5%CVE-2026-22857MEDIUMFreeRDP has a heap-use-after-free in irp_thread_funcEPSS 0.5%CVE-2023-1213HIGHUse after free in Swiftshader in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via aEPSS 0.5%CVE-2026-6759HIGHUse-after-free in the Widget: Cocoa componentEPSS 0.5%CVE-2026-61920MEDIUMWindows DNS Server Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-2458HIGHUse after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker who convinced a user to engEPSS 0.5%CVE-2023-42093LOWFoxit PDF Reader Annotation Use-After-Free Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-53761HIGHMicrosoft PowerPoint Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-16353CRITICALInvalid pointer in the DOM: Bindings (WebIDL) componentEPSS 0.5%CVE-2025-53738HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-7528CRITICALIncorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox EPSS 0.5%CVE-2026-33416HIGHLIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`EPSS 0.5%CVE-2025-59227HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-25983MEDIUMImageMagick has Use After Free in MSLStartElement in "coders/msl.c"EPSS 0.5%CVE-2026-45751MEDIUMSuricata detect/transform: use-after-free in dotprefix transformEPSS 0.5%