The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.
Volume of CVEs assigned to CWE-825 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
85 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23638MEDIUM Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error re | Jan 24, 2024 | 6.5 | 51 | NO | NO |
CVE-2026-6722CRITICAL In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP ob | May 10, 2026 | 9.8 | 45 | NO | NO |
CVE-2026-45447HIGH Issue summary: A specially crafted PKCS#7 or S/MIME signed message could
trigger a use-after-free during PKCS#7 signature verification.
Impact summary: A use-after-free may result | Jun 9, 2026 | 8.8 | 44 | NO | NO |
CVE-2026-3593CRITICAL A use-after-free vulnerability exists within the DNS-over-HTTPS implementation.
This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 thr | May 20, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-53006CRITICAL In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix possible UAF in icmpv6_rcv()
Caching saddr and daddr before pskb_pull() is problematic
since skb->he | Jun 24, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-46243HIGH In the Linux kernel, the following vulnerability has been resolved:
smb: client: reject userspace cifs.spnego descriptions
cifs.spnego key descriptions contain authority-bearing | Jun 1, 2026 | 7.8 | 39 | NO | NO |
CVE-2026-52924CRITICAL In the Linux kernel, the following vulnerability has been resolved:
sctp: purge outqueue on stale COOKIE-ECHO handling
sctp_stream_update() is only invoked when the association i | Jun 24, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-12293CRITICAL Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. | Jun 16, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-45972CRITICAL In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix potential UAF and double free in smb2_open_file()
Zero out @err_iov and @err_buftype before r | May 27, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-58592HIGH Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via the | Jul 1, 2026 | 8.3 | 36 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.