The product attempts to return a memory resource to the system, but it calls a release function that is not compatible with the function that was originally used to allocate that resource.
Volume of CVEs assigned to CWE-762 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-48431HIGH Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade t | Apr 28, 2026 | 7.5 | 34 | NO | NO |
CVE-2023-41056HIGH Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and pote | Jan 10, 2024 | 8.1 | 28 | NO | NO |
CVE-2025-48755CRITICAL In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type). | May 24, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-47737CRITICAL lib.rs in the trailer crate through 0.1.2 for Rust mishandles allocating with a size of zero. | May 9, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-49080HIGH There is a memory management vulnerability in Absolute
Secure Access server versions 9.0 to 13.54. Attackers with network access to
the server can cause a Denial of Service by send | Jun 12, 2025 | 7.5 | 23 | NO | NO |
CVE-2024-32503HIGH An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. Th | Jun 7, 2024 | 7.8 | 23 | NO | NO |
CVE-2024-2955HIGH T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file | Mar 26, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-45510HIGH tsMuxer version git-2539d07 was discovered to contain an alloc-dealloc-mismatch (operator new [] vs operator delete) error. | Oct 12, 2023 | 7.5 | 22 | NO | NO |
CVE-2025-20189HIGH A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could al | May 7, 2025 | 7.4 | 21 | NO | NO |
CVE-2025-11015MEDIUM A weakness has been identified in OGRECave Ogre up to 14.4.1. Impacted is the function STBIImageCodec::encode of the file /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp. This manipu | Sep 26, 2025 | 5.3 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.