The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.
Volume of CVEs assigned to CWE-763 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
98 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-52993CRITICAL In the Linux kernel, the following vulnerability has been resolved:
tipc: fix double-free in tipc_buf_append()
tipc_msg_validate() can potentially reallocate the skb it is valida | Jun 24, 2026 | 9.8 | 39 | NO | NO |
CVE-2025-48431HIGH Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade t | Apr 28, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-9516HIGH Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws.
To skip a leading 3-byte UTF-8 BOM, decod | Jun 3, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-57248HIGH When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result, due to the damage to | Jul 8, 2026 | 7.8 | 32 | NO | NO |
CVE-2026-46116HIGH In the Linux kernel, the following vulnerability has been resolved:
xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete
KASAN reproduces a slab-use-after-free in __x | May 28, 2026 | 7.8 | 32 | NO | NO |
CVE-2025-14233CRITICAL Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affecte | Jan 16, 2026 | 9.8 | 32 | NO | NO |
CVE-2007-4367HIGH Opera before 9.23 allows remote attackers to execute arbitrary code via crafted Javascript that triggers a "virtual function call on an invalid pointer." | Aug 15, 2007 | 9.3 | 32 | NO | NO |
CVE-2026-53000HIGH In the Linux kernel, the following vulnerability has been resolved:
netfilter: nat: use kfree_rcu to release ops
Florian Westphal says:
"Historically this is not an issue, even | Jun 24, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-22770CRITICAL ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBil | Jan 20, 2026 | 9.8 | 31 | NO | NO |
CVE-2021-42377CRITICAL An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishan | Nov 15, 2021 | 9.8 | 31 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.