About “Memory Corruption”

A curated feed of “Memory Corruption”-related CVEs appears below. We currently track 8498 CVEs for this tag (all time). In the last 365 days, 696 were published. Average CVSS is 8.1 (all time; 7.4 over 365d), and 82% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer, CWE-787 - Out-of-bounds Write, CWE-416 - Use After Free.

In our taxonomy this topic maps to a HIGH impact class. Common exploitation patterns for this weakness can lead to high. Use the filters to triage high risk first and validate exposure in your environment. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.

CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).

CVSS ≥ 0.0
2025-05-27
Medium

CVE-2025-5244

A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulatio…

2025-05-23
High

CVE-2025-5100

A double-free condition occurs during the cleanup of temporary image files, which can be exploited to achieve memory corruption and potentially arbitrary code execution.

Critical

CVE-2025-5099

An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory corruption and potentially arbitrary code execution.

2025-05-20
High

CVE-2025-37981

In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Use is_kdump_kernel() to check for kdump The smartpqi driver checks the reset_devices variable to determine wheth…

High

CVE-2025-37943

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a len…

High

CVE-2025-37915

In the Linux kernel, the following vulnerability has been resolved: net_sched: drr: Fix double list add in class with netem as child qdisc As described in Gerrard's report [1], there are use cases…

High

CVE-2025-37914

In the Linux kernel, the following vulnerability has been resolved: net_sched: ets: Fix double list add in class with netem as child qdisc As described in Gerrard's report [1], there are use cases…

High

CVE-2025-37913

In the Linux kernel, the following vulnerability has been resolved: net_sched: qfq: Fix double list add in class with netem as child qdisc As described in Gerrard's report [1], there are use cases…

Medium

CVE-2025-37911

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix out-of-bound memcpy() during ethtool -w When retrieving the FW coredump using ethtool, it can sometimes cause memory…

2025-05-19
High

CVE-2025-24189

The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted w…

2025-05-15
High

CVE-2025-30421

There is a memory corruption vulnerability due to a stack-based buffer overflow in DrObjectStorage::XML_Serialize() when using the SymbolEditor in NI Circuit Design Suite.  This vulnerability may res…

High

CVE-2025-30420

There is a memory corruption vulnerability due to an out of bounds read in Bitmap::InternalDraw() when using the SymbolEditor in NI Circuit Design Suite.  This vulnerability may result in information…

High

CVE-2025-30419

There is a memory corruption vulnerability due to an out of bounds read in GetSymbolBorderRectSize() when using the SymbolEditor in NI Circuit Design Suite.  This vulnerability may result in informat…

High

CVE-2025-30418

There is a memory corruption vulnerability due to an out of bounds write in CheckPins() when using the SymbolEditor in NI Circuit Design Suite.  This vulnerability may result in information disclosur…

High

CVE-2025-30417

There is a memory corruption vulnerability due to an out of bounds write in Library!DecodeBase64() when using the SymbolEditor in NI Circuit Design Suite.  This vulnerability may result in informatio…

2025-05-14
Critical

CVE-2025-47436

Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompre…

2025-05-13
Medium

CVE-2025-4574

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

2025-05-12
High

CVE-2025-31238

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted w…

High

CVE-2025-31223

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted w…

High

CVE-2025-31204

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously…

High

CVE-2025-24223

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously…

Medium

CVE-2025-24111

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.7, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5,…

2025-05-08
Medium

CVE-2025-31946

Pixmeo OsiriX MD is vulnerable to a local use after free scenario, which could allow an attacker to locally import a crafted DICOM file and cause memory corruption or a system crash.

High

CVE-2025-27578

Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM file and cause memory corruption leading to a denial-of-service condition.

2025-05-07
Medium

CVE-2025-20980

Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.

2025-05-06
High

CVE-2025-21475

Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.

High

CVE-2025-21470

Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.

High

CVE-2025-21469

Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.

High

CVE-2025-21468

Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.

High

CVE-2025-21467

Memory corruption while reading the FW response from the shared queue.

High

CVE-2025-21462

Memory corruption while processing an IOCTL request, when buffer significantly exceeds the command argument limit.

High

CVE-2025-21460

Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed continuously.

High

CVE-2025-21453

Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.

High

CVE-2024-49846

Memory corruption while decoding of OTA messages from T3448 IE.

High

CVE-2024-49845

Memory corruption during the FRS UDS generation process.

High

CVE-2024-49844

Memory corruption while triggering commands in the PlayReady Trusted application.

High

CVE-2024-49842

Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.

High

CVE-2024-49841

Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.

High

CVE-2024-49835

Memory corruption while reading secure file.

Medium

CVE-2024-49830

Memory corruption while processing an IOCTL call to set mixer controls.

Medium

CVE-2024-49829

Memory corruption can occur during context user dumps due to inadequate checks on buffer length.

Medium

CVE-2024-45583

Memory corruption while handling multiple IOCTL calls from userspace to operate DMA operations.

Medium

CVE-2024-45581

Memory corruption while sound model registration for voice activation with audio kernel driver.

High

CVE-2024-45579

Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request information, due to a missing memory requirement check.

High

CVE-2024-45578

Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

High

CVE-2024-45577

Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.

High

CVE-2024-45576

Memory corruption while prociesing command buffer buffer in OPE module.

High

CVE-2024-45575

Memory corruption Camera kernel when large number of devices are attached through userspace.

High

CVE-2024-45574

Memory corruption during array access in Camera kernel due to invalid index from invalid command data.

Medium

CVE-2024-45570

Memory corruption may occur during IO configuration processing when the IO port count is invalid.

Medium

CVE-2024-45568

Memory corruption due to improper bounds check while command handling in camera-kernel driver.

High

CVE-2024-45567

Memory corruption while encoding JPEG format.

High

CVE-2024-45566

Memory corruption during concurrent buffer access due to modification of the reference count.

High

CVE-2024-45565

Memory corruption when blob structure is modified by user-space after kernel verification.

High

CVE-2024-45564

Memory corruption during concurrent access to server info object due to incorrect reference count update.

Medium

CVE-2024-45563

Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session.

Medium

CVE-2024-45562

Memory corruption during concurrent access to server info object due to unprotected critical field.

High

CVE-2024-45554

Memory corruption during concurrent SSR execution due to race condition on the global maps list.

2025-05-02
High

CVE-2023-53037

In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Bad drive in topology results kernel crash When the SAS Transport Layer support is enabled and a device exposed to…

2025-05-01
High

CVE-2025-36521

MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption within the application. The user must open a malicious DCM file for exploitation.

Medium

CVE-2022-49828

In the Linux kernel, the following vulnerability has been resolved: hugetlbfs: don't delete error page from pagecache This change is very similar to the change that was made for shmem [1], and it s…

2025-04-29
High

CVE-2025-4093

Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbit…

Medium

CVE-2025-4092

Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited t…

High

CVE-2025-4091

Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort so…

Medium

CVE-2025-4087

A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and…

2025-04-25
High

CVE-2025-46613

OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after the parent stack frame becomes unavailable.

2025-04-23
Medium

CVE-2025-46398

In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.

2025-04-16
Critical

CVE-2025-31200

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing…

Medium

CVE-2025-22089

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Don't expose hw_counters outside of init net namespace Commit 467f432a521a ("RDMA/core: Split port and device counter…

Medium

CVE-2025-22060

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: Prevent parser TCAM memory corruption Protect the parser TCAM/SRAM memory, and the cached (shadow) SRAM information,…

2025-04-15
Medium

CVE-2024-49200

An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use o…

High

CVE-2025-1277

A maliciously crafted PDF file, when parsed through Autodesk applications, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in…

Critical

CVE-2025-32911

A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the li…

Medium

CVE-2025-3608

A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability was fixed in Firefox 137.0…

2025-04-09
High

CVE-2025-30656

An Improper Handling of Additional Special Element vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series with MS-MPC, MS-MIC and SPC3, and SRX Series, allows a…

High

CVE-2025-30644

A Heap-based Buffer Overflow vulnerability in the flexible PIC concentrator (FPC) of Juniper Networks Junos OS on EX2300, EX3400, EX4100, EX4300, EX4300MP, EX4400, EX4600, EX4650-48Y, and QFX5k Serie…

2025-04-08
Medium

CVE-2025-20943

Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption.

2025-04-07
High

CVE-2025-21447

Memory corruption may occur while processing device IO control call for session control.

High

CVE-2025-21443

Memory corruption while processing message content in eAVB.

High

CVE-2025-21442

Memory corruption while transmitting packet mapping information with invalid header payload size.

High

CVE-2025-21441

Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.

High

CVE-2025-21440

Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.

High

CVE-2025-21439

Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provided output buffer.

High

CVE-2025-21438

Memory corruption while IOCTL call is invoked from user-space to read board data.

High

CVE-2025-21437

Memory corruption while processing memory map or unmap IOCTL operations simultaneously.

High

CVE-2025-21436

Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threads.

High

CVE-2025-21429

Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.

High

CVE-2025-21428

Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.

High

CVE-2025-21425

Memory corruption may occur due top improper access control in HAB process.

High

CVE-2025-21423

Memory corruption occurs when handling client calls to EnableTestMode through an Escape call.

High

CVE-2025-21421

Memory corruption while processing escape code in API.

Medium

CVE-2024-49848

Memory corruption while processing multiple IOCTL calls from HLOS to DSP.

High

CVE-2024-45557

Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.

Medium

CVE-2024-45544

Memory corruption while processing IOCTL calls to add route entry in the HW.

Medium

CVE-2024-45543

Memory corruption while accessing MSM channel map and mixer functions.

Medium

CVE-2024-45540

Memory corruption while invoking IOCTL map buffer request from userspace.

High

CVE-2024-43067

Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shared memory.

High

CVE-2024-43066

Memory corruption while handling file descriptor during listener registration/de-registration.

High

CVE-2024-43058

Memory corruption while processing IOCTL calls.

High

CVE-2024-33058

Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.

2025-04-04
High

CVE-2025-25178

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause kernel system memory corruption.

2025-04-03
Low

CVE-2025-3145

A vulnerability, which was classified as problematic, has been found in MindSpore 2.5.0. Affected by this issue is the function mindspore.numpy.fft.rfft2. The manipulation leads to memory corruption.…

Low

CVE-2025-3144

A vulnerability classified as problematic was found in MindSpore 2.5.0. Affected by this vulnerability is the function mindspore.numpy.fft.hfftn. The manipulation leads to memory corruption. It is po…

Low

CVE-2025-3136

A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAlloc…

2025-04-02
Low

CVE-2025-3121

A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is…

2025-04-01
Medium

CVE-2024-13941

A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. This affects the function ouch::archive::zip::convert_zip_date_time of the file zip.rs. The manipulation of…

High

CVE-2025-21966

In the Linux kernel, the following vulnerability has been resolved: dm-flakey: Fix memory corruption in optional corrupt_bio_byte feature Fix memory corruption due to incorrect parameter being pass…

High

CVE-2025-21927

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu() nvme_tcp_recv_pdu() doesn't check the validity of the header len…

High

CVE-2025-21919

In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix potential memory corruption in child_cfs_rq_on_list child_cfs_rq_on_list attempts to convert a 'prev' pointer to…

High

CVE-2025-3034

Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited t…

High

CVE-2025-3030

Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort so…

High

CVE-2025-1660

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in t…

2025-03-31
High

CVE-2025-24213

This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A ty…

Medium

CVE-2025-3001

A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approac…

Medium

CVE-2025-3000

A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on…

Medium

CVE-2025-2999

A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Atta…

Medium

CVE-2025-2998

A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory c…

2025-03-23
Medium

CVE-2018-25109

A vulnerability has been found in Nintendo Animal Crossing, Doubutsu no Mori+ and Doubutsu no Mori e+ 1.00/1.01 on GameCube and classified as critical. Affected by this vulnerability is an unknown fu…

2025-03-17
Medium

CVE-2025-2357

A vulnerability was found in DCMTK 3.6.9. It has been declared as critical. This vulnerability affects unknown code of the component dcmjpls JPEG-LS Decoder. The manipulation leads to memory corrupti…

2025-03-14
High

CVE-2024-8176

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references,…