CWE-763Base

Release of Invalid Pointer or Reference

Incomplete in the CWE catalog · 38 CVEs mapped

38
CVEs mapped
7.7
Median CVSS
What it is

The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.

Recent examples
8.8cvss
CVE-2026-84131

CVE-2026-84131 - HIGH Severity Vulnerability

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

HIGHno explanation yet
0%
epss
6.4cvss
CVE-2023-20511

CVE-2023-20511 - MEDIUM Severity Vulnerability

Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading to arbitrary code execution.

MEDIUMno explanation yet
0%
epss
none
CVE-2026-19315

CVE-2026-19315 - UNKNOWN Severity Vulnerability

A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

no explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-763
Abstraction
Base
Structure
Simple
Status
Incomplete
References (3)