CWE-825
32 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-825page 1 of 1
- CVE-2019-15691HIGHCVSS 7.2EG 7.22019-12-26
TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack memory in ZRLEDecoder. If decoding routine would throw an exception, ZRLEDecoder may try to access stack variable, which…
- CVE-2021-25443MEDIUMCVSS 5.3EG 5.32021-08-05
A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an attacker.
- CVE-2021-39228MEDIUMCVSS 6.5EG 6.52021-09-17
Tremor is an event processing system for unstructured data. A vulnerability exists between versions 0.7.2 and 0.11.6. This vulnerability is a memory safety Issue when using `patch` or `merge` on `state` and assign the result back to `state…
- CVE-2022-0523HIGHCVSS 7.8EG 7.82022-02-08
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
- CVE-2023-20212HIGHCVSS 7.5EG 7.52023-08-18
A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error in the memory management of a…
- CVE-2023-48315HIGHCVSS 8.8EG 8.82023-12-05
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected…
- CVE-2023-48316CRITICALCVSS 9.8EG 9.82023-12-05
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected…
- CVE-2023-48692CRITICALCVSS 9.0EG 9.02023-12-05
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected…
- CVE-2023-48694MEDIUMCVSS 6.8EG 6.82023-12-05
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference and type confusion vulnerabilities …
- CVE-2023-48696MEDIUMCVSS 6.7EG 6.72023-12-05
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference vulnerabilities in Azure RTOS USBX.…
- CVE-2023-48697MEDIUMCVSS 6.4EG 6.42023-12-05
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to memory buffer and pointer vulnerabilities in Azure RTOS USBX. T…
- CVE-2023-48698MEDIUMCVSS 6.8EG 6.82023-12-05
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference vulnerabilities in Azure RTOS USBX.…
- CVE-2024-23310CRITICALCVSS 9.8EG 9.82024-02-20
A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a…
- CVE-2024-23638MEDIUMCVSS 6.5EG 6.52024-01-24
Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform De…
- CVE-2024-28889MEDIUMCVSS 5.9EG 5.92024-05-08
When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate.�…
- CVE-2024-39792HIGHCVSS 7.5EG 7.52024-08-14
When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2024-45105MEDIUMCVSS 6.7EG 6.72024-09-13
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.
- CVE-2024-8250HIGHCVSS 7.8EG 7.82024-08-29
NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file
- CVE-2025-10911MEDIUMCVSS 5.5EG 5.52025-09-25
A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.
- CVE-2025-12119MEDIUMCVSS 6.8EG 6.82025-11-18
A mongoc_bulk_operation_t may read invalid memory if large options are passed.
- CVE-2025-30653MEDIUMCVSS 6.5EG 6.52025-04-09
An Expired Pointer Dereference vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause Denial of Service (DoS).On all Junos OS and Junos OS Evol…
- CVE-2025-49794CRITICALCVSS 9.1EG 9.12025-06-16
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to cr…
- CVE-2025-49795HIGHCVSS 7.5EG 7.52025-06-16
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
- CVE-2025-54770MEDIUMCVSS 4.9EG 4.92025-11-18
A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the net_set_vlan command is not properly unregistered wh…
- CVE-2025-54771MEDIUMCVSS 4.9EG 4.92025-11-18
A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure. …
- CVE-2025-61663MEDIUMCVSS 4.9EG 4.92025-11-18
A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the normal command is not properly unregistered when the…
- CVE-2025-61664MEDIUMCVSS 4.9EG 4.92025-11-18
A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attacke…
- CVE-2026-26399MEDIUMCVSS 5.3EG 5.32026-04-20
A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function allocates a TIM_HandleTypeDef structure on the stack and passes its address to HAL initialization routines, where it i…
- CVE-2026-34001HIGHCVSS 7.8EG 7.82026-04-23
A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without…
- CVE-2026-35094LOWCVSS 3.3EG 3.32026-04-01
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a point…
- CVE-2026-7111HIGHCVSS 8.4EG 8.42026-04-29
Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke reg…
- CVE-2026-8854HIGHCVSS 7.5EG 7.52026-05-26
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.
Map vulnerabilities like CWE-825 to your infrastructure
EchelonGraph correlates every CVE — across CWE-825 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →