The product uses an API function, data structure, or other entity in a way that relies on properties that are not always guaranteed to hold for that entity.
Volume of CVEs assigned to CWE-758 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22858CRITICAL FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to b | Jan 14, 2026 | 9.1 | 34 | NO | NO |
CVE-2026-4705CRITICAL Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. | Mar 24, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-24409HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior and Null Poin | Jan 24, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-16441MEDIUM In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated | Jul 21, 2026 | 6.9 | 28 | NO | NO |
CVE-2026-4724CRITICAL Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. | Mar 24, 2026 | 9.1 | 28 | NO | NO |
CVE-2026-24411HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior in CIccTagXml | Jan 24, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-24410HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior and Null Poin | Jan 24, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-24407HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior in icSigCalcO | Jan 24, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-24404HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, CIccXmlArrayType() contains a Nul | Jan 24, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-21677HIGH iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have Undefined Behavior in its CIccCLUT::Init function which i | Jan 6, 2026 | 8.8 | 28 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.