Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.
Volume of CVEs assigned to CWE-244 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-20039HIGH A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an una | Mar 4, 2026 | 8.6 | 30 | NO | NO |
CVE-2025-1719HIGH IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. | Jan 20, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-70873HIGH An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted | Mar 12, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-36118HIGH IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negoti | Nov 17, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-1759HIGH IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. | Aug 18, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-1722HIGH IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. | Jan 20, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-1721HIGH IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory. | Dec 26, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-33101MEDIUM IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniques due to improper clearing of heap memory. | Feb 17, 2026 | 5.9 | 22 | NO | NO |
CVE-2025-45663MEDIUM An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure. | Nov 3, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-26305HIGH A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file. | Feb 20, 2025 | 8.2 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.