CWE-416 释放后使用 类弱点 2492 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-416 释放后使用是一种内存安全漏洞,指程序在释放内存后仍引用该内存区域。攻击者常利用此缺陷,通过重新分配内存并控制其内容,诱导程序执行恶意代码或读取敏感数据,从而引发远程代码执行或信息泄露。开发者应避免此类风险,确保在指针置空前彻底解除引用,采用智能指针等自动内存管理机制,并严格验证内存生命周期,防止悬空指针操作。
#include <stdio.h> #include <unistd.h> #define BUFSIZER1 512 #define BUFSIZER2 ((BUFSIZER1/2) - 8) int main(int argc, char **argv) { char *buf1R1; char *buf2R1; char *buf2R2; char *buf3R2; buf1R1 = (char *) malloc(BUFSIZER1); buf2R1 = (char *) malloc(BUFSIZER1); free(buf2R1); buf2R2 = (char *) malloc(BUFSIZER2); buf3R2 = (char *) malloc(BUFSIZER2); strncpy(buf2R1, argv[1], BUFSIZER1-1); free(buf1R1); free(buf2R2); free(buf3R2); }char* ptr = (char*)malloc (SIZE); if (err) { abrt = 1; free(ptr); } ... if (abrt) { logError("operation aborted before commit", ptr); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-30344 | Foxit PDF Reader 安全漏洞 — PDF Reader | 7.8AI | HighAI | 2024-04-02 |
| CVE-2024-30343 | Foxit PDF Reader 安全漏洞 — PDF Reader | 7.8AI | HighAI | 2024-04-02 |
| CVE-2024-30342 | Foxit PDF Reader 安全漏洞 — PDF Reader | 7.8AI | HighAI | 2024-04-02 |
| CVE-2024-30339 | Foxit PDF Reader 安全漏洞 — PDF Reader | 7.8AI | HighAI | 2024-04-02 |
| CVE-2024-30338 | Foxit PDF Reader 安全漏洞 — PDF Reader | 7.8AI | HighAI | 2024-04-02 |
| CVE-2024-30337 | Foxit PDF Reader 安全漏洞 — PDF Reader | 7.8AI | HighAI | 2024-04-02 |
| CVE-2024-30336 | Foxit PDF Reader 安全漏洞 — PDF Reader | 7.8AI | HighAI | 2024-04-02 |
| CVE-2024-28951 | OpenHarmony 安全漏洞 — OpenHarmony | 5.5 | Medium | 2024-04-02 |
| CVE-2024-22180 | OpenHarmony 安全漏洞 — OpenHarmony | 3.3 | Low | 2024-04-02 |
| CVE-2024-22098 | OpenHarmony 安全漏洞 — OpenHarmony | 6.5 | Medium | 2024-04-02 |
| CVE-2024-21472 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 8.4 | High | 2024-04-01 |
| CVE-2024-21468 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 8.4 | High | 2024-04-01 |
| CVE-2024-21918 | Rockwell Automation Arena Simulation Software 安全漏洞 — Arena Simulation | 7.8 | High | 2024-03-26 |
| CVE-2024-1848 | SolidWorks 安全漏洞 — SOLIDWORKS Desktop | 7.8 | High | 2024-03-22 |
| CVE-2024-20752 | Adobe Bridge 资源管理错误漏洞 — Bridge | 7.8 | High | 2024-03-18 |
| CVE-2024-26182 | Microsoft Windows Kernel 安全漏洞 — Windows 10 Version 1809 | 7.8 | High | 2024-03-12 |
| CVE-2024-21437 | Microsoft Graphics Component 安全漏洞 — Windows 10 Version 1809 | 7.8 | High | 2024-03-12 |
| CVE-2024-21407 | Microsoft Hyper-V 安全漏洞 — Windows 10 Version 1809 | 8.1 | High | 2024-03-12 |
| CVE-2024-21334 | Microsoft Open Management Infrastructure 安全漏洞 — System Center Operations Manager (SCOM) 2019 | 9.8 | Critical | 2024-03-12 |
| CVE-2024-21443 | Microsoft Windows Kernel 安全漏洞 — Windows 10 Version 1809 | 7.3 | High | 2024-03-12 |
| CVE-2024-21439 | Microsoft Windows Telephony Server 安全漏洞 — Windows 10 Version 1809 | 7.0 | High | 2024-03-12 |
| CVE-2024-21426 | Microsoft SharePoint 安全漏洞 — Microsoft SharePoint Enterprise Server 2016 | 7.8 | High | 2024-03-12 |
| CVE-2024-27934 | Deno 安全漏洞 — deno | 8.4 | High | 2024-03-06 |
| CVE-2024-27308 | Mio 安全漏洞 — mio | 7.5 | High | 2024-03-06 |
| CVE-2023-50716 | eProsima Fast DDS 安全漏洞 — Fast-DDS | 9.7 | Critical | 2024-03-06 |
| CVE-2024-27929 | ImageSharp 安全漏洞 — ImageSharp | 7.1 | High | 2024-03-05 |
| CVE-2024-0155 | Dell Digital Delivery 资源管理错误漏洞 — Dell Digital Delivery (D3) | 7.0 | High | 2024-03-04 |
| CVE-2023-6241 | ARM Mali GPU Kernel Driver 安全漏洞 — Midgard GPU Kernel Driver | 7.0AI | HighAI | 2024-03-04 |
| CVE-2023-43552 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 9.8 | Critical | 2024-03-04 |
| CVE-2023-43547 | Qualcomm Chipsets 安全漏洞 — Snapdragon | 8.4 | High | 2024-03-04 |
CWE-416(释放后使用) 是常见的弱点类别,本平台收录该类弱点关联的 2492 条 CVE 漏洞。