VulnSea

CWE-825

CVEs classified under CWE-825, newest first.

164 CVEsRSS

CVE-2026-65970Medium· 5.3PoC
3d ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a crafted ZIP-compressed TIFF processed with TIFF multithreading enabled can make TIFFIn…

TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.37%via NVD
CVE-2026-92627Medium· 4.6
5d ago

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc()…

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc()…

SunlitThe HDF Group · HDF5EPSS 0.22%via NVD
CVE-2026-19662Medium· 5.9
5d ago

An attacker may be able to cause a `named` resolver to abort

An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the …

SunlitISC · BIND 9EPSS 0.41%via NVD
CVE-2026-78227Medium· 6.5
5d ago

NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'

NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's retrans…

SunlitNLnet Labs · UnboundEPSS 0.27%via NVD
CVE-2026-82720Medium· 5.9
5d ago

NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'

NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a d…

SunlitNLnet Labs · UnboundEPSS 0.29%via NVD
CVE-2026-91947High· 7.5
6d ago

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure message…

TwilightFreeRDP · FreeRDPEPSS 0.30%via NVD
CVE-2026-91957Low· 3.1
6d ago

FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration

FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause …

SunlitFreeRDP · FreeRDPEPSS 0.33%via NVD
CVE-2026-92005Medium· 5.3⚖ disputed
6d ago

Use-after-free in the Audio/Video: Web Codecs component

Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.38%via NVD
CVE-2026-92016High· 8.8
6d ago

Use-after-free in the Disability Access APIs component

Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.33%via NVD
CVE-2026-92023High· 8.8
6d ago

Use-after-free in the XML component

Use-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.34%via NVD
CVE-2026-92021High· 8.8
6d ago

Use-after-free in the JavaScript Engine: JIT component

Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbird 140.16.

TwilightMozilla · FirefoxEPSS 0.30%via NVD
CVE-2026-92026High· 8.8
6d ago

Use-after-free in the Networking component

Use-after-free in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.33%via NVD
CVE-2026-92024High· 8.8
6d ago

Use-after-free in the SVG component

Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.34%via NVD
CVE-2026-92022High· 8.8
6d ago

Use-after-free in the DOM: HTML Parser component

Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.34%via NVD
CVE-2026-92028High· 8.8
6d ago

Use-after-free in the DOM: Core & HTML component

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.34%via NVD
CVE-2026-92027High· 8.8
6d ago

Use-after-free in the DOM: Streams component

Use-after-free in the DOM: Streams component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.34%via NVD
CVE-2026-92025High· 8.8
6d ago

Use-after-free in the DOM: Navigation component

Use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.34%via NVD
CVE-2026-92029High· 8.8
6d ago

Use-after-free in the SVG component

Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.34%via NVD
CVE-2026-92040High· 8.8⚖ disputed
6d ago

Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

TwilightMozilla · FirefoxEPSS 0.30%via NVD
CVE-2026-92046High· 8.8⚖ disputed
6d ago

Use-after-free in the Graphics component

Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.31%via NVD
CVE-2026-92049High· 8.8⚖ disputed
6d ago

Use-after-free in the Widget: Win32 component

Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.25%via NVD
CVE-2026-92054High· 8.8⚖ disputed
6d ago

Privilege escalation in the Memory component

Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.26%via NVD
CVE-2026-92056High· 8.8⚖ disputed
6d ago

Use-after-free in the Graphics: Text component

Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.25%via NVD
CVE-2026-92058High· 8.8⚖ disputed
6d ago

Use-after-free in the Graphics component

Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.25%via NVD
CVE-2026-92060High· 8.8⚖ disputed
6d ago

Use-after-free in the Internationalization component

Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.25%via NVD
CVE-2026-90852High· 7.3PoC
6d ago

A vulnerability has been found in luben zstd-jni up to 1.5.7-13

A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary Sharing. Such manipulation leads to use after …

Midnightluben · zstd-jniEPSS 0.31%via NVD
CVE-2026-89637High· 7.0⚖ disputed
1w ago

kernel: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 (CVE-2026-89637)

A flaw was found in the Linux kernel's Server Message Block (SMB) client. When processing a malformed secondary TRANSACT2 response, a use-after-free (UAF) vulnerability and a buffer leak can occur in the `cifs_check_trans2()` function. Thi…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.59%via CSAF
CVE-2026-80995Medium· 5.5⚖ disputed
1w ago

kernel: net: mctp: hold a reference to the route device in mctp_route_lookup() (CVE-2026-80995)

A flaw was found in the Linux kernel's MCTP (Message Control Transport Protocol) networking implementation. This vulnerability arises because the `mctp_route_lookup()` function accesses a route device without holding a persistent reference…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.12%via CSAF
CVE-2026-80981High· 7.0⚖ disputed
1w ago

kernel: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() (CVE-2026-80981)

A flaw was found in the Linux kernel's net/smc component. A local attacker could exploit a use-after-free vulnerability in the `smc_llc_srv_add_link()` function, where a freed memory region is improperly accessed. This can lead to memory c…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.59%via CSAF
CVE-2026-80955Medium· 5.5⚖ disputed
1w ago

kernel: dm-pcache: fix use-after-free and invalid seg operations in kset_replay() (CVE-2026-80955)

A flaw was found in the Linux kernel's dm-pcache component. This vulnerability, a use-after-free, occurs within the `kset_replay` function when a stale key's segment generation is accessed after it has been freed. This could allow a local …

SunlitRed Hat · LinuxEPSS 0.16%via CSAF
CWE-825 vulnerabilities (CVEs) · VulnSea