CWE-763— Release of Invalid Pointer or Reference
The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.— MITRE CWE catalog
114 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-763page 3 of 3
- CVE-2023-31082MEDIUMCVSS 5.5EG 5.52023-04-24
An issue was discovered in drivers/tty/n_gsm.c in the Linux kernel 6.2. There is a sleeping function called from an invalid context in gsmld_write, which will block the kernel. Note: This has been disputed by 3rd parties as not a valid vul…
- CVE-2020-27798MEDIUMCVSS 5.5EG 5.52022-08-25
An invalid memory address reference was discovered in the adjABS function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.
- CVE-2020-27797MEDIUMCVSS 5.5EG 5.52022-08-25
An invalid memory address reference was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.
- CVE-2021-45261MEDIUMCVSS 5.5EG 5.52021-12-22
An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.
- CVE-2020-28941MEDIUMCVSS 5.5EG 5.52020-11-19
An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs beca…
- CVE-2020-8715MEDIUMCVSS 5.5EG 5.52020-08-13
Invalid pointer for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable denial of service via local access.
- CVE-2019-20632MEDIUMCVSS 5.5EG 5.52020-03-24
An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_odf_delete_descriptor in odf/desc_private.c that can cause a denial of service via a crafted MP4 file.
- CVE-2019-20631MEDIUMCVSS 5.5EG 5.52020-03-24
An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_list_count in utils/list.c that can cause a denial of service via a crafted MP4 file.
- CVE-2019-20170MEDIUMCVSS 5.5EG 5.52019-12-31
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid pointer dereference in the function GF_IPMPX_AUTH_Delete() in odf/ipmpx_code.c.
- CVE-2025-54333MEDIUMCVSS 5.3EG 5.32025-11-04
An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Invalid Pointer Dereference of node in the get_vs4l_profiler_node function.
- CVE-2020-24371MEDIUMCVSS 5.3EG 5.32020-08-17
lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.
- CVE-2020-13132MEDIUMCVSS 4.6EG 4.62020-07-09
An issue was discovered in Yubico libykpiv before 2.1.0. An attacker can trigger an incorrect free() in the ykpiv_util_generate_key() function in lib/util.c through incorrect error handling code. This could be used to cause a denial of ser…
- CVE-2026-15718MEDIUMCVSS 4.3EG 4.32026-07-14
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 140.13, and Thunderbird 140.13.
- CVE-2024-50057LOWCVSS 3.3EG 3.32024-10-21
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tipd: Free IRQ only if it was requested before In polling mode, if no IRQ was requested there is no need to free it. Call devm_free_irq() only if client->irq…
Map vulnerabilities like CWE-763 to your infrastructure
EchelonGraph correlates every CVE — across CWE-763 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →