CWE-763
CWE-763 · 3 records · 2 with a public proof-of-concept
Records the NVD classes under CWE-763, highest CVSS first.
- HIGH 8.8CVE-2026-100813
Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
firefox · thunderbird
- HIGH 7.6CVE-2026-88340public PoC
An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild…
- MEDIUM 5.9CVE-2026-105405public PoC
ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 contains an invalid memory free vulnerability in the MVG decoder. Attackers can supply a crafted MVG image for processing to trigger the invalid free and crash the application, causing a denial of service.