CWE-825
CWE-825 · 3 records · 0 with a public proof-of-concept
Records the NVD classes under CWE-825, highest CVSS first.
- HIGH 7CVE-2026-102010
A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit …
- MEDIUM 4.7CVE-2026-104039
A flaw was found in SSSD. A local user can cause a denial of service (DoS) by disrupting system authentication services. When handling Generic Security Services Application Programming Interface (GSSAPI) authentication in the Pluggable Authentication Module (P…
- MEDIUM 4.7CVE-2026-104034
A flaw was found in SSSD. A use-after-free vulnerability exists in the Kerberos Credential Manager (KCM) responder during Kerberos ticket-granting ticket (TGT) renewal, where a deferred callback accesses memory that has already been released. An authenticated …