CWE-825: Expired Pointer Dereference
The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.
44 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-23310 — A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Ma
- CVE-2026-17523 — can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet
- CVE-2024-39792 — NGINX Plus MQTT vulnerability
- CVE-2026-30978 — Heap-use-after-free in CIccCmm::AddXform()
- CVE-2025-49794 — Libxml: heap use after free (uaf) leads to denial of service (dos)
- CVE-2026-32873 — ewe: Loop with Unreachable Exit Condition ('Infinite Loop')
- CVE-2026-58592 — Ladybird - Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssembly ESM Integration
- CVE-2026-7111 — Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption
- CVE-2025-12119 — Bulk write with options may read invalid memory
- CVE-2026-34001 — Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption
- CVE-2025-30653 — Junos OS and Junos OS Evolved: LSP flap in a specific MPLS scenario leads to rpd crash
- CVE-2024-23638 — SQUID-2023:11 Denial of Service in Cache Manager
- CVE-2026-8854 — IBM HTTP Server is affected by multiple vulnerabilities
- CVE-2026-77220 — PDFio < 1.6.5 Dangling Pointer via Dictionary String-Formatting
- CVE-2026-10671 — User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`)
- CVE-2024-28889 — BIG-IP SSL vulnerability
- CVE-2026-5165 — Virtio-win: virtio-win: memory corruption via use-after-free in virtio blk device reset
- CVE-2026-2436 — Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake
- CVE-2026-12610 — Sssd: use-after-free crash in sssd' 'sssd_pam' process
- CVE-2026-54778 — CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
Recently published
- CVE-2026-77220 — PDFio < 1.6.5 Dangling Pointer via Dictionary String-Formatting
- CVE-2026-76891 — Expired Pointer Dereference in Wireshark
- CVE-2026-76890 — Expired Pointer Dereference in Wireshark
- CVE-2026-17523 — can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet
- CVE-2026-10671 — User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`)
- CVE-2026-54778 — CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
- CVE-2026-58592 — Ladybird - Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssembly ESM Integration
- CVE-2026-12610 — Sssd: use-after-free crash in sssd' 'sssd_pam' process
- CVE-2026-57435 — Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
- CVE-2026-8854 — IBM HTTP Server is affected by multiple vulnerabilities
- CVE-2026-7111 — Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption
- CVE-2026-34001 — Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption
- CVE-2026-35094 — Libinput: libinput: information disclosure via dangling pointer in lua plugin handling
- CVE-2026-5165 — Virtio-win: virtio-win: memory corruption via use-after-free in virtio blk device reset
- CVE-2026-2436 — Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake
- CVE-2026-32873 — ewe: Loop with Unreachable Exit Condition ('Infinite Loop')
- CVE-2026-30978 — Heap-use-after-free in CIccCmm::AddXform()
- CVE-2025-12119 — Bulk write with options may read invalid memory
- CVE-2025-54770 — Grub2: use-after-free in net_set_vlan
- CVE-2025-61664 — Grub2: missing unregister call for normal_exit command may lead to use-after-free