Skip to main content

CWE archive

CWE-590 CVEs

Programmatic archive

19 CVEs tagged with CWE-5903 Critical, 10 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2025-7006

Published Jun 12, 2026

Use of stack memory after free vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Denial-of-Service of the antivirus process. This issue affects…

CVSS 5.5 · Medium

CVE-2026-47328

Published May 28, 2026

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking alloc…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-42996

Published Jun 10, 2025

SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without having to re-authenticate giving the ability to access or modif…

CVSS 5.6 · Medium

CVE-2025-42995

Published Jun 10, 2025

SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and…

CVSS 7.5 · High

CVE-2025-42994

Published Jun 10, 2025

SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fa…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-5899

Published Jun 9, 2025

A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the…

CVSS 1.9 · Low

CVE-2025-32911

Published Apr 15, 2025

A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory…

CVSS 9.0 · Critical

CVE-2023-42459

Published Oct 16, 2023

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). In affected versions specific DATA submessages can be sent t…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31973

Published May 9, 2023

yasm v1.3.0 was discovered to contain a use after free via the function expand_mmac_params at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnera…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22291

Published Apr 5, 2023

An invalid free vulnerability exists in the Frame stream parser functionality of Ichitaro 2022 1.0.1.57600. A specially crafted document can lead to an attempt to free a stack poi…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25565

Published Feb 14, 2023

GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, an incorrect free when decoding target information can trigger…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31627

Published Jul 28, 2022

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be u…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-42377

Published Nov 15, 2021

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell misha…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2020-6016

Published Nov 18, 2020

Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_ReceiveUnreliableSegment(), leading to a Heap-…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1