CWE-763— Release of Invalid Pointer or Reference
The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.— MITRE CWE catalog
114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-763page 1 of 3
- CVE-2026-52993CRITICALCVSS 9.8EG 9.82026-06-24
In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was be…
- CVE-2026-22770CRITICALCVSS 9.8EG 9.82026-01-20
ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in versions prior to 7.1.2-13, the last ele…
- CVE-2025-14233CRITICALCVSS 9.8EG 9.82026-01-16
Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. …
- CVE-2024-44852CRITICALCVSS 9.8EG 9.82024-12-06
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan().
- CVE-2021-42377CRITICALCVSS 9.8EG 9.82021-11-15
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code exec…
- CVE-2021-30473CRITICALCVSS 9.8EG 9.82021-05-06
aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
- CVE-2021-24028CRITICALCVSS 9.8EG 9.82021-04-14
An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2021.02.22.00.
- CVE-2020-0103CRITICALCVSS 9.8EG 9.82020-05-14
In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for expl…
- CVE-2020-11105CRITICALCVSS 9.8EG 9.82020-03-30
An issue was discovered in USC iLab cereal through 1.3.0. It employs caching of std::shared_ptr values, using the raw pointer address as a unique identifier. This becomes problematic if an std::shared_ptr variable goes out of scope and is …
- CVE-2019-11930CRITICALCVSS 9.8EG 9.82019-12-04
An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4…
- CVE-2018-6836CRITICALCVSS 9.8EG 9.82018-02-08
The netmonrec_comment_destroy function in wiretap/netmon.c in Wireshark through 2.4.4 performs a free operation on an uninitialized memory address, which allows remote attackers to cause a denial of service (application crash) or possibly …
- CVE-2022-31625CRITICALCVSS 8.1EG 9.82022-06-16
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized dat…
- CVE-2026-19315CRITICALCVSS 9.3EG 9.32026-08-27
A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
- CVE-2007-4367HIGHCVSS v2 9.3EG 9.32007-08-15
Opera before 9.23 allows remote attackers to execute arbitrary code via crafted Javascript that triggers a "virtual function call on an invalid pointer."
- CVE-2026-100813HIGHCVSS 8.8EG 8.82026-09-29
Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
- CVE-2026-84131HIGHCVSS 8.8EG 8.82026-09-01
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- CVE-2026-74947HIGHCVSS 8.8EG 8.82026-08-18
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- CVE-2025-25215HIGHCVSS 8.8EG 8.82025-06-13
An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an arbitrary free. An at…
- CVE-2024-6607HIGHCVSS 8.8EG 8.82024-07-09
It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a `<select>` element over certain permission prompts. This could be used to confuse a user into giving a…
- CVE-2022-42309HIGHCVSS 8.8EG 8.82022-11-01
Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during node creation in an error path, resulting in a crash of xenstored or a memory corruption in xenstor…
- CVE-2020-15674HIGHCVSS 8.8EG 8.82020-10-01
Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulner…
- CVE-2020-15673HIGHCVSS 8.8EG 8.82020-10-01
Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitr…
- CVE-2020-15670HIGHCVSS 8.8EG 8.82020-10-01
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.…
- CVE-2025-13824HIGHCVSS 8.7EG 8.72025-12-15
A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault w…
- CVE-2026-74860HIGHCVSS 8.5EG 8.52026-09-08
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This t…
- CVE-2021-3682HIGHCVSS 8.5EG 8.52021-08-05
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could u…
- CVE-2023-43532HIGHCVSS 8.4EG 8.42024-02-06
Memory corruption while reading ACPI config through the user mode app.
- CVE-2022-25661HIGHCVSS 8.4EG 8.42022-10-19
Memory corruption due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2022-26942HIGHCVSS 8.2EG 8.22023-10-19
The Motorola MTM5000 series firmwares lack pointer validation on arguments passed to trusted execution environment (TEE) modules. Two modules are used, one responsible for KVL key management and the other for TETRA cryptographic functional…
- CVE-2026-77500HIGHCVSS 7.8EG 7.82026-09-08
Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-57248HIGHCVSS 7.8EG 7.82026-07-08
When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result, due to the damage to the internal structure of the annotations, it causes the ap…
- CVE-2026-53000HIGHCVSS 7.8EG 7.82026-06-24
In the Linux kernel, the following vulnerability has been resolved: netfilter: nat: use kfree_rcu to release ops Florian Westphal says: "Historically this is not an issue, even for normal base hooks: the data path doesn't use the origin…
- CVE-2026-46189HIGHCVSS 7.8EG 7.82026-05-28
In the Linux kernel, the following vulnerability has been resolved: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path Sashiko points out that pvrdma_uar_free() is already called within pvrdma_dealloc_ucontext(), so c…
- CVE-2026-46116HIGHCVSS 7.8EG 7.82026-05-28
In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete KASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s hlist_del_rcu calls under syzkaller lo…
- CVE-2025-47329HIGHCVSS 7.8EG 7.82025-09-24
Memory corruption while handling invalid inputs in application info setup.
- CVE-2025-47749HIGHCVSS 7.8EG 7.82025-05-19
V-SFT v6.2.5.0 and earlier contains an issue with free of pointer not at start of buffer in VS6EditData.dll!CWinFontInf::WinFontMsgCheck function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbi…
- CVE-2025-30379HIGHCVSS 7.8EG 7.82025-05-13
Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2024-2955HIGHCVSS 7.8EG 7.82024-03-26
T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file
- CVE-2021-47087HIGHCVSS 7.8EG 7.82024-03-04
In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix incorrect page free bug Pointer to the allocated pages (struct page *page) has already progressed towards the end of allocation. It is incorrect to perfo…
- CVE-2023-34312HIGHCVSS 7.8EG 7.82023-06-01
In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition.
- CVE-2022-48425HIGHCVSS 7.8EG 7.82023-03-19
In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before replaying logs.
- CVE-2022-4696HIGHCVSS 7.8EG 7.82023-01-11
There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, …
- CVE-2022-24958HIGHCVSS 7.8EG 7.82022-02-11
drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.
- CVE-2021-3939HIGHCVSS 7.8EG 7.82021-11-17
Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This …
- CVE-2020-12963HIGHCVSS 7.8EG 7.82021-11-15
An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows may allow unprivileged users to compromise the system.
- CVE-2021-41073HIGHCVSS 7.8EG 7.82021-09-19
loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation.
- CVE-2021-28216HIGHCVSS 7.8EG 7.82021-08-05
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
- CVE-2020-36404HIGHCVSS 7.8EG 7.82021-07-01
Keystone Engine 0.9.2 has an invalid free in llvm_ks::SmallVectorImpl<llvm_ks::MCFixup>::~SmallVectorImpl.
- CVE-2020-12982HIGHCVSS 7.8EG 7.82021-06-11
An invalid object pointer free vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.
- CVE-2021-22760HIGHCVSS 7.8EG 7.82021-06-11
A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of user-supplied input data, when …
Map vulnerabilities like CWE-763 to your infrastructure
EchelonGraph correlates every CVE — across CWE-763 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →