VYPR

CWE-763

Release of Invalid Pointer or Reference

BaseIncomplete

Description

The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (106)

page 2 of 6
  • CVE-2026-77500HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-47329HigSep 24, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while handling invalid inputs in application info setup.

  • CVE-2025-47749HigMay 19, 2025
    risk 0.51cvss 7.8epss 0.00

    V-SFT v6.2.5.0 and earlier contains an issue with free of pointer not at start of buffer in VS6EditData.dll!CWinFontInf::WinFontMsgCheck function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.

  • CVE-2025-30379HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2024-36890HigMay 30, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: mm/slab: make __free(kfree) accept error pointers Currently, if an automatically freed allocation is an error pointer that will lead to a crash. An example of this is in wm831x_gpio_dbg_show(). 171 char…

  • CVE-2021-47087HigMar 4, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix incorrect page free bug Pointer to the allocated pages (struct page *page) has already progressed towards the end of allocation. It is incorrect to perform __free_pages(page, order) using this…

  • CVE-2023-34312HigJun 1, 2023
    risk 0.51cvss 7.8epss 0.01

    In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition.

  • CVE-2022-4696HigJan 11, 2023
    risk 0.51cvss 7.8epss 0.00

    There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its reference counter is not…

  • CVE-2022-24958HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.

  • CVE-2021-3939HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus…

  • CVE-2020-12963HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows may allow unprivileged users to compromise the system.

  • CVE-2021-28216HigAug 5, 2021
    risk 0.51cvss 7.8epss 0.00

    BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.

  • CVE-2020-36404HigJul 1, 2021
    risk 0.51cvss 7.8epss 0.01

    Keystone Engine 0.9.2 has an invalid free in llvm_ks::SmallVectorImpl<llvm_ks::MCFixup>::~SmallVectorImpl.

  • CVE-2020-12982HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    An invalid object pointer free vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.

  • CVE-2021-22760HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.01

    A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of user-supplied input data, when a malicious CGF file is imported to IGSS…

  • CVE-2020-0444HigDec 14, 2020
    risk 0.51cvss 7.8epss 0.00

    In audit_free_lsm_field of auditfilter.c, there is a possible bad kfree due to a logic error in audit_data_to_entry. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2019-18619HigJul 22, 2020
    risk 0.51cvss 7.8epss 0.01

    Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept…

  • CVE-2019-19820HigJan 10, 2020
    risk 0.51cvss 7.8epss 0.01

    An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402405 using METHOD_NEITHER results in a read…

  • CVE-2019-9290HigSep 27, 2019
    risk 0.51cvss 7.8epss 0.00

    In tzdata there is possible memory corruption due to a mismatch between allocation and deallocation functions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product:…

  • CVE-2018-9557HigDec 6, 2018
    risk 0.51cvss 7.8epss 0.00

    In really_install_package of install.cpp, there is a possible free of arbitrary memory due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android.…