Skip to main content

CWE archive

CWE-825 CVEs

Programmatic archive

86 CVEs tagged with CWE-82516 Critical, 44 High, 24 Medium, 2 Low, 0 Unrated.

CVE-2026-17523

Published Jul 27, 2026

A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-10671

Published Jul 14, 2026

In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c used K_SYSCALL_OBJ() (which requires the kernel object to already be i…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-54778

Published Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer identity resolution use…

CVSS 6.2 · Medium
evidence mentions
6
Buzz score
24.5

CVE-2026-58592

Published Jul 1, 2026

Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via th…

CVSS 8.9 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-12610

Published Jun 30, 2026

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled…

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-57435

Published Jun 25, 2026

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a Ruby wrapper pointing to freed…

CVSS 1.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53085

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: bpf: fix mm lifecycle in open-coded task_vma iterator The open-coded task_vma iterator reads task->mm lockles…

CVSS 7.8 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-53033

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Take state lock for af_unix iter When a BPF iterator program updates a sockmap, there is a race…

CVSS 7.8 · High
evidence mentions
9
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-53006

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->h…

CVSS 9.8 · Critical
evidence mentions
15
Buzz score
40.7
Vendor/product tagsBeta · best-effort

CVE-2026-52976

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() Two error handling issues exist in xe_exec_queue_cr…

CVSS 7.8 · High
evidence mentions
9
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-52973

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: futex: Drop CLONE_THREAD requirement for private default hash alloc Currently need_futex_hash_allocate_defaul…

CVSS 7.8 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-52952

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset In __iommu_group_set_domain_internal(),…

CVSS 8.8 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-52950

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: fix UAF with retry loop Retry doesn't work here, since bo will be freed on error, leading to…

CVSS 7.8 · High
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2026-52924

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association…

CVSS 9.8 · Critical
evidence mentions
12
Buzz score
43.6
Vendor/product tagsBeta · best-effort

CVE-2026-52923

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysctl path can request the next S…

CVSS 7.8 · High
evidence mentions
12
Buzz score
43.6
Vendor/product tagsBeta · best-effort

CVE-2026-12328

Published Jun 16, 2026

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corrupt…

CVSS 8.1 · High
evidence mentions
30
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-12326

Published Jun 16, 2026

Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could h…

CVSS 8.1 · High
evidence mentions
8
Buzz score
36.5
Vendor/product tagsBeta · best-effort

CVE-2026-12291

Published Jun 16, 2026

Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

CVSS 8.8 · High
evidence mentions
30
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-42014

Published Jun 16, 2026

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an…

CVSS 6.6 · Medium
evidence mentions
19
Buzz score
50.0

CVE-2026-6040

Published Jun 15, 2026

A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-46523

Published Jun 10, 2026

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a heap-use…

CVSS 6.2 · Medium
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-45447

Published Jun 9, 2026

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may resul…

CVSS 8.8 · High
evidence mentions
24
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-46243

Published Jun 1, 2026

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing…

CVSS 7.1 · High
evidence mentions
47
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-44422

Published May 29, 2026

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer…

CVSS 7.5 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort
Showing 1-25 of 86 CVEsPage 1 of 4