CWE-825

Expired Pointer Dereference

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.

86 vulnerabilities with CWE-825
CVE-2026-46176 HIGH
RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init()
CVSS 7.8
CVE-2026-46166 HIGH
wifi: mac80211: use safe list iteration in radar detect work
CVSS 8.8
CVE-2026-46125 HIGH
wifi: mac80211: remove station if connection prep fails
CVSS 8.8
CVE-2026-45998 HIGH
rxrpc: Fix potential UAF after skb_unshare() failure
CVSS 7.8
CVE-2026-45972 CRITICAL
smb: client: fix potential UAF and double free in smb2_open_file()
CVSS 9.8
CVE-2026-8854 HIGH
IBM HTTP Server is affected by multiple vulnerabilities
CVSS 7.5
CVE-2026-3593 HIGH
Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVSS 7.4
CVE-2026-8947 HIGH
Use-after-free in the DOM: Bindings (WebIDL) component
CVSS 7.3
CVE-2026-8390 HIGH
Use-after-free in the JavaScript: WebAssembly component
CVSS 7.3
CVE-2026-6722 CRITICAL
Use-After-Free in SOAP using Apache map
CVSS 9.8
CVE-2026-8090 HIGH
Use-after-free in the DOM: Networking component
CVSS 7.3
CVE-2026-31703 HIGH
writeback: Fix use after free in inode_switch_wbs_work_fn()
CVSS 7.8
CVE-2026-7111 HIGH
Text::CSV_XS < 1.62 - Use-After-Free via Callback Stack Extension
CVSS 8.4
CVE-2026-34001 HIGH
X.Org X Server Xwayland - XSYNC Fence Use-After-Free
CVSS 7.8
CVE-2026-6754 HIGH
Use-after-free in the JavaScript Engine component
CVSS 7.5
CVE-2026-6747 HIGH
Use-after-free in the WebRTC component
CVSS 7.5
CVE-2026-6746 HIGH
Use-after-free in the DOM: Core & HTML component
CVSS 7.5
CVE-2026-6100 HIGH
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
CVSS 8.1
CVE-2026-34734 HIGH
HDF5: H5T__conv_struct Use After Free
CVSS 7.8
CVE-2026-34774 HIGH
Electron: Use-after-free in offscreen child window paint callback
CVSS 8.1
CVE-2026-35094 LOW
Libinput: libinput: information disclosure via dangling pointer in lua plugin handling
CVSS 3.3
CVE-2026-5165 MEDIUM
Virtio-win: virtio-win: memory corruption via use-after-free in virtio blk device reset
CVSS 6.7
CVE-2026-2436 MEDIUM
Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake
CVSS 6.5
CVE-2026-33526 HIGH
Squid vulnerable to Denial of Service in ICP Request handling
CVSS 7.5
CVE-2026-4729 CRITICAL
Memory safety bugs fixed in Firefox 149 and Thunderbird 149
CVSS 9.8
Details
Vulnerabilities 86