CWE-825— Expired Pointer Dereference
The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.— MITRE CWE catalog
97 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-825page 2 of 2
- CVE-2026-23074HIGHCVSS 7.8EG 7.82026-02-04
In the Linux kernel, the following vulnerability has been resolved: net/sched: Enforce that teql can only be used as root qdisc Design intent of teql is that it is only supposed to be used as root qdisc. We need to check for that constra…
- CVE-2024-8250HIGHCVSS 7.8EG 7.82024-08-29
NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file
- CVE-2022-0523HIGHCVSS 7.8EG 7.82022-02-08
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
- CVE-2026-46243HIGHCVSS 7.1EG 7.82026-06-01
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that ci…
- CVE-2026-57435HIGHCVSS 7.5EG 7.52026-06-25
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a Ruby wrapper pointing to freed memory when replacing the value of an XML attribute. If Ru…
- CVE-2026-8854HIGHCVSS 7.5EG 7.52026-05-26
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.
- CVE-2026-6754HIGHCVSS 7.5EG 7.52026-04-21
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-6747HIGHCVSS 7.5EG 7.52026-04-21
Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-6746HIGHCVSS 7.5EG 7.52026-04-21
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-33526HIGHCVSS 7.5EG 7.52026-03-26
Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial o…
- CVE-2026-32873HIGHCVSS 7.5EG 7.52026-03-20
ewe is a Gleam web server. Versions 0.8.0 through 3.0.4 contain a bug in the handle_trailers function where rejected trailer headers (forbidden or undeclared) cause an infinite loop. When handle_trailers encounters such a trailer, three co…
- CVE-2026-24678HIGHCVSS 7.5EG 7.52026-02-09
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. This …
- CVE-2025-49795HIGHCVSS 7.5EG 7.52025-06-16
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
- CVE-2024-39792HIGHCVSS 7.5EG 7.52024-08-14
When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2023-20212HIGHCVSS 7.5EG 7.52023-08-18
A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error in the memory management of a…
- CVE-2026-6040HIGHCVSS 7.3EG 7.32026-06-15
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be pr…
- CVE-2026-8947HIGHCVSS 7.3EG 7.32026-05-19
Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
- CVE-2026-8390HIGHCVSS 7.3EG 7.32026-05-12
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.
- CVE-2026-8090HIGHCVSS 7.3EG 7.32026-05-07
Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.
- CVE-2019-15691HIGHCVSS 7.2EG 7.22019-12-26
TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack memory in ZRLEDecoder. If decoding routine would throw an exception, ZRLEDecoder may try to access stack variable, which…
- CVE-2026-10671HIGHCVSS 7.1EG 7.12026-07-14
In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c used K_SYSCALL_OBJ() (which requires the kernel object to already be initialized) instead of K_SYSCALL_OBJ_NEVER_INIT() (which rej…
- CVE-2026-102010HIGHCVSS 7.0EG 7.02026-09-28
A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this o…
- CVE-2024-45105MEDIUMCVSS 6.7EG 6.72024-09-13
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2026-42014MEDIUMCVSS 6.6EG 6.62026-06-16
A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for…
- CVE-2026-77220MEDIUMCVSS 6.5EG 6.52026-08-21
PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary without copying the string value. In multi-threaded or poole…
- CVE-2026-76891MEDIUMCVSS 6.5EG 6.52026-08-19
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-76890MEDIUMCVSS 6.5EG 6.52026-08-19
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2025-30653MEDIUMCVSS 6.5EG 6.52025-04-09
An Expired Pointer Dereference vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause Denial of Service (DoS).On all Junos OS and Junos OS Evol…
- CVE-2021-39228MEDIUMCVSS 6.5EG 6.52021-09-17
Tremor is an event processing system for unstructured data. A vulnerability exists between versions 0.7.2 and 0.11.6. This vulnerability is a memory safety Issue when using `patch` or `merge` on `state` and assign the result back to `state…
- CVE-2026-12610MEDIUMCVSS 6.4EG 6.42026-06-30
A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating s…
- CVE-2026-54778MEDIUMCVSS 6.2EG 6.22026-06-19
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer identity resolution uses non-reentrant getpwuid and getgrgid calls, allowing concur…
- CVE-2026-46523MEDIUMCVSS 6.2EG 6.22026-05-18
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a heap-use-after-free. Versions 7.1.2.23 and 6.9.13-48 fix the issue.
- CVE-2026-78123MEDIUMCVSS 5.9EG 5.92026-09-11
strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
- CVE-2024-28889MEDIUMCVSS 5.9EG 5.92024-05-08
When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate.�…
- CVE-2025-10911MEDIUMCVSS 5.5EG 5.52025-09-25
A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.
- CVE-2026-65970MEDIUMCVSS 5.3EG 5.32026-09-18
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a crafted ZIP-compressed TIFF processed with TIFF multithreading enabled can make TIFFInpu…
- CVE-2026-26399MEDIUMCVSS 5.3EG 5.32026-04-20
A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function allocates a TIM_HandleTypeDef structure on the stack and passes its address to HAL initialization routines, where it i…
- CVE-2021-25443MEDIUMCVSS 5.3EG 5.32021-08-05
A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an attacker.
- CVE-2026-23868MEDIUMCVSS 5.1EG 5.12026-03-10
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.
- CVE-2025-61664MEDIUMCVSS 4.9EG 4.92025-11-18
A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacke…
- CVE-2025-61663MEDIUMCVSS 4.9EG 4.92025-11-18
A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the normal command is not properly unregistered when the…
- CVE-2025-54771MEDIUMCVSS 4.9EG 4.92025-11-18
A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. …
- CVE-2025-54770MEDIUMCVSS 4.9EG 4.92025-11-18
A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the net_set_vlan command is not properly unregistered wh…
- CVE-2026-104039MEDIUMCVSS 4.7EG 4.72026-10-06
A flaw was found in SSSD. A local user can cause a denial of service (DoS) by disrupting system authentication services. When handling Generic Security Services Application Programming Interface (GSSAPI) authentication in the Pluggable Aut…
- CVE-2026-104034MEDIUMCVSS 4.7EG 4.72026-10-06
A flaw was found in SSSD. A use-after-free vulnerability exists in the Kerberos Credential Manager (KCM) responder during Kerberos ticket-granting ticket (TGT) renewal, where a deferred callback accesses memory that has already been releas…
- CVE-2026-35094LOWCVSS 3.3EG 3.32026-04-01
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a point…
- CVE-2025-12119LOWCVSS 3.3EG 3.32025-11-18
A mongoc_bulk_operation_t may read invalid memory if large options are passed.
Map vulnerabilities like CWE-825 to your infrastructure
EchelonGraph correlates every CVE — across CWE-825 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →