CWE-825

Expired Pointer Dereference

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.

35 vulnerabilities with CWE-825
CVE-2026-42014 MEDIUM
Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin
CVSS 6.6
CVE-2026-8854 HIGH
IBM HTTP Server is affected by multiple vulnerabilities
CVSS 7.5
CVE-2026-7111 HIGH
Text::CSV_XS < 1.62 - Use-After-Free via Callback Stack Extension
CVSS 8.4
CVE-2026-34001 HIGH
X.Org X Server Xwayland - XSYNC Fence Use-After-Free
CVSS 7.8
CVE-2026-35094 LOW
Libinput: libinput: information disclosure via dangling pointer in lua plugin handling
CVSS 3.3
CVE-2026-5165 MEDIUM
Virtio-win: virtio-win: memory corruption via use-after-free in virtio blk device reset
CVSS 6.7
CVE-2026-2436 MEDIUM
Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake
CVSS 6.5
CVE-2026-32873 HIGH
ewe: Loop with Unreachable Exit Condition ('Infinite Loop')
CVSS 7.5
CVE-2026-30978 HIGH
iccdev < 2.3.1.5 - Use-After-Free in CIccCmm::AddXform()
CVSS 7.8
CVE-2025-12119 MEDIUM
MongoDB C Driver - Memory Corruption via Invalid Memory Read
CVSS 6.8
CVE-2025-61664 MEDIUM
GNU grub2 < 2.14 - Use-After-Free in normal_exit Command
CVSS 4.9
CVE-2025-61663 MEDIUM
GNU grub2 < 2.14 - Use-After-Free in Normal Command
CVSS 4.9
CVE-2025-54771 MEDIUM
GNU GRUB2 < 2.14 - Use-After-Free in File System Structure Handling
CVSS 4.9
CVE-2025-54770 MEDIUM
GNU grub2 < 2.14 - Denial of Service via Use-After-Free in Network Module
CVSS 4.9
CVE-2025-10911 MEDIUM
Red Hat Enterprise Linux 10 - Use-After-Free in libxslt XSL Node Parser
CVSS 5.5
CVE-2025-49795 HIGH
libxml2 - Denial of Service
CVSS 7.5
CVE-2025-49794 CRITICAL
Red Hat Enterprise Linux libxml2 - Use-After-Free in XPath Parser with Schema Elements
CVSS 9.1
CVE-2025-30653 MEDIUM
Juniper Junos OS and Junos OS Evolved - Unauthenticated Denial of Service via MPLS LSP Flapping
CVSS 6.5
CVE-2024-45105 MEDIUM
Lenovo ThinkSystem and ThinkAgile BIOS - Authenticated Arbitrary Code Execution via UEFI SMM Callout
CVSS 6.7
CVE-2024-8250 HIGH
Wireshark 4.0.0-4.0.16 and 4.2.0-4.2.6 - Denial of Service via NTLMSSP Dissector
CVSS 7.8
CVE-2024-39792 HIGH
NGINX Plus - Memory Exhaustion via MQTT Pre-Read Module
CVSS 7.5
CVE-2024-28889 MEDIUM
F5 BIG-IP 15.1.0-15.1.10.4 - Denial of Service via SSL Profile Alert Timeout
CVSS 5.9
CVE-2024-23310 CRITICAL
libbiosig 2.5.0 and Master Branch - Use-After-Free in sopen_FAMOS_read
CVSS 9.8
CVE-2024-23638 MEDIUM
Squid 5.0-5.9 and 6.0-6.5 - Denial of Service via Cache Manager Error Response
CVSS 6.5
CVE-2023-48698 MEDIUM
Eclipse ThreadX USBX < 6.3.0 - Expired Pointer Remote Code Execution
CVSS 6.8
Details
Vulnerabilities 35