CWE-825Base

Expired Pointer Dereference

Incomplete in the CWE catalog · 55 CVEs mapped

55
CVEs mapped
7.1
Median CVSS
What it is

The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.

Recent examples
6.5cvss
CVE-2026-77220

CVE-2026-77220 - MEDIUM Severity Vulnerability

PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary without copying the string value. In multi-threaded or pooled-request environments, attackers or concurrent users can trigger stack memory reuse across requests, causing cross-tenant document content corruption by silently overwriting one caller's dictionary string values with another caller's data.

MEDIUMno explanation yet
0%
epss
3.1cvss
CVE-2026-76891

CVE-2026-76891 - LOW Severity Vulnerability

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

LOWno explanation yet
0%
epss
3.1cvss
CVE-2026-76890

CVE-2026-76890 - LOW Severity Vulnerability

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-825
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)