CWE-763 · 93 записей
Release of Invalid Pointer or Reference
CVE этого класса
92 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-11930Эксплойта нет | An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution.facebook · hhvm · CWE-763 | Критическая9,8 | — | 3,2 % | 4 дек. 2019 г. |
40В плане | CVE-2018-6836Эксплойта нет | The netmonrec_comment_destroy function in wiretap/netmon.c in Wireshark through 2.4.4 performs a free operation on an uninitialized memory awireshark · wireshark · CWE-763 | Критическая9,8 | — | 2,7 % | 8 февр. 2018 г. |
40В плане | CVE-2021-30473Эксплойта нет | aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.aomedia · aomedia · CWE-763 | Критическая9,8 | — | 2,1 % | 6 мая 2021 г. |
40В плане | CVE-2020-11105Эксплойта нет | An issue was discovered in USC iLab cereal through 1.3.0.usc · cereal · CWE-763 | Критическая9,8 | — | 2,0 % | 30 мар. 2020 г. |
40В плане | CVE-2021-24028Эксплойта нет | An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other unfacebook · thrift · CWE-763 | Критическая9,8 | — | 1,7 % | 13 апр. 2021 г. |
39Наблюдать | CVE-2007-4367Эксплойта нет | Opera before 9.23 allows remote attackers to execute arbitrary code via crafted Javascript that triggers a "virtual function call on an invaopera · opera browser · CWE-763 | Критическая9,3 | — | 8,2 % | 15 авг. 2007 г. |
39Наблюдать | CVE-2020-0103Эксплойта нет | In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption.google · android · CWE-763 | Критическая9,8 | — | 1,6 % | 14 мая 2020 г. |
39Наблюдать | CVE-2024-44852Эксплойта нет | Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component thetopenrobotics · robot operating system · CWE-763 | Критическая9,8 | — | 0,6 % | 6 дек. 2024 г. |
39Наблюдать | CVE-2026-22770Эксплойта нет | ImageMagick vulnerable to Release of Invalid Pointer in BilateralBlur when memory allocation failsimagemagick · imagemagick · CWE-763 | Критическая9,8 | — | 0,4 % | 19 янв. 2026 г. |
37Наблюдать | CVE-2025-14233Эксплойта нет | Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on thcanon · lbp1238 ii firmware · CWE-763 | Критическая9,3 | — | 0,8 % | 15 янв. 2026 г. |
36Наблюдать | CVE-2025-25215Эксплойта нет | Dell ControlVault3/ControlVault3 Plus cv_close arbitrary free vulnerabilitybroadcom · bcm5820x · CWE-763 | Высокая8,8 | — | 2,6 % | 13 июн. 2025 г. |
35Наблюдать | CVE-2021-3682Эксплойта нет | A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2.qemu · qemu · CWE-763 | Высокая8,5 | — | 2,9 % | 5 авг. 2021 г. |
35Наблюдать | CVE-2024-6607Эксплойта нет | Leaving pointerlock by pressing the escape key could be preventedmozilla · firefox · CWE-763 | Высокая8,8 | — | 0,6 % | 9 июл. 2024 г. |
35Наблюдать | CVE-2026-74947Эксплойта нет | Privilege escalation due to invalid pointer in the Graphics componentmozilla · firefox · CWE-763 | Высокая8,8 | — | 0,4 % | 18 авг. 2026 г. |
35Наблюдать | CVE-2026-84131Эксплойта нет | Privilege escalation due to invalid pointer in the Graphics componentmozilla · firefox · CWE-763 | Высокая8,8 | — | 0,3 % | 1 сент. 2026 г. |
35Наблюдать | CVE-2022-42309Эксплойта нет | Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during xen · xen · CWE-763 | Высокая8,8 | — | 0,3 % | 1 нояб. 2022 г. |
35Наблюдать | CVE-2026-100813Эксплойта нет | Invalid pointer in the JavaScript Engine: JIT componentmozilla · firefox · CWE-763 | Высокая8,8 | — | 0,2 % | 29 сент. 2026 г. |
34Наблюдать | CVE-2025-11838Эксплойта нет | WatchGuard Firebox iked Memory Corruption Vulnerabilitywatchguard · fireware · CWE-763 | Высокая8,7 | — | 0,5 % | 4 дек. 2025 г. |
34Наблюдать | CVE-2026-74860Эксплойта нет | Libxml2: double-free/uaf in libxml2 python bindingsred hat · red hat enterprise linux 10 · CWE-763 | Высокая8,5 | — | 0,4 % | 8 сент. 2026 г. |
34Наблюдать | CVE-2025-13824Эксплойта нет | Micro820®, Micro850®, Micro870® – Specialized Fuzzing Vulnerabilitiesrockwell automation · micro820®, micro850®, micro870® · CWE-763 | Высокая8,7 | — | 0,3 % | 15 дек. 2025 г. |
33Наблюдать | CVE-2013-4695Proof of concept | Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Executionwinamp · winamp · CWE-763 | Высокая7,8 | — | 5,3 % | 27 дек. 2019 г. |
32Наблюдать | CVE-2021-41073Proof of concept | loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFElinux · linux kernel · CWE-763 | Высокая7,8 | — | 1,8 % | 19 сент. 2021 г. |
31Наблюдать | CVE-2020-36224Эксплойта нет | A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting openldap · openldap · CWE-763 | Высокая7,5 | — | 4,3 % | 26 янв. 2021 г. |
31Наблюдать | CVE-2022-37451Эксплойта нет | Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.exim · exim · CWE-763 | Высокая7,5 | — | 3,3 % | 6 авг. 2022 г. |
31Наблюдать | CVE-2020-5139Эксплойта нет | A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due to the release of Insonicwall · sonicos · CWE-763 | Высокая7,5 | — | 1,8 % | 12 окт. 2020 г. |
- CVE-2019-1193040В плане
An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %facebook · hhvm4 дек. 2019 г.
- CVE-2018-683640В плане
The netmonrec_comment_destroy function in wiretap/netmon.c in Wireshark through 2.4.4 performs a free operation on an uninitialized memory a
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %wireshark · wireshark8 февр. 2018 г.
- CVE-2021-3047340В плане
aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %aomedia · aomedia6 мая 2021 г.
- CVE-2020-1110540В плане
An issue was discovered in USC iLab cereal through 1.3.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %usc · cereal30 мар. 2020 г.
- CVE-2021-2402840В плане
An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other un
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %facebook · thrift13 апр. 2021 г.
- CVE-2007-436739Наблюдать
Opera before 9.23 allows remote attackers to execute arbitrary code via crafted Javascript that triggers a "virtual function call on an inva
КритическаяCVSS 9,3Эксплойта нетEPSS 8 %opera · opera browser15 авг. 2007 г.
- CVE-2020-010339Наблюдать
In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %google · android14 мая 2020 г.
- CVE-2024-4485239Наблюдать
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component thet
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openrobotics · robot operating system6 дек. 2024 г.
- CVE-2026-2277039Наблюдать
ImageMagick vulnerable to Release of Invalid Pointer in BilateralBlur when memory allocation fails
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %imagemagick · imagemagick19 янв. 2026 г.
- CVE-2025-1423337Наблюдать
Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on th
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %canon · lbp1238 ii firmware15 янв. 2026 г.
- CVE-2025-2521536Наблюдать
Dell ControlVault3/ControlVault3 Plus cv_close arbitrary free vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %broadcom · bcm5820x13 июн. 2025 г.
- CVE-2021-368235Наблюдать
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2.
ВысокаяCVSS 8,5Эксплойта нетEPSS 3 %qemu · qemu5 авг. 2021 г.
- CVE-2024-660735Наблюдать
Leaving pointerlock by pressing the escape key could be prevented
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mozilla · firefox9 июл. 2024 г.
- CVE-2026-7494735Наблюдать
Privilege escalation due to invalid pointer in the Graphics component
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mozilla · firefox18 авг. 2026 г.
- CVE-2026-8413135Наблюдать
Privilege escalation due to invalid pointer in the Graphics component
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mozilla · firefox1 сент. 2026 г.
- CVE-2022-4230935Наблюдать
Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a wrong pointer during
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %xen · xen1 нояб. 2022 г.
- CVE-2026-10081335Наблюдать
Invalid pointer in the JavaScript Engine: JIT component
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mozilla · firefox29 сент. 2026 г.
- CVE-2025-1183834Наблюдать
WatchGuard Firebox iked Memory Corruption Vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %watchguard · fireware4 дек. 2025 г.
- CVE-2026-7486034Наблюдать
Libxml2: double-free/uaf in libxml2 python bindings
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %red hat · red hat enterprise linux 108 сент. 2026 г.
- CVE-2025-1382434Наблюдать
Micro820®, Micro850®, Micro870® – Specialized Fuzzing Vulnerabilities
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %rockwell automation · micro820®, micro850®, micro870®15 дек. 2025 г.
- CVE-2013-469533Наблюдать
Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution
ВысокаяCVSS 7,8Proof of conceptEPSS 5 %winamp · winamp27 дек. 2019 г.
- CVE-2021-4107332Наблюдать
loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFE
ВысокаяCVSS 7,8Proof of conceptEPSS 2 %linux · linux kernel19 сент. 2021 г.
- CVE-2020-3622431Наблюдать
A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing, resulting
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %openldap · openldap26 янв. 2021 г.
- CVE-2022-3745131Наблюдать
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %exim · exim6 авг. 2022 г.
- CVE-2020-513931Наблюдать
A vulnerability in SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS) due to the release of In
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %sonicwall · sonicos12 окт. 2020 г.