CWE-590: CWE-590

9
Total CVEs
3
Critical
5
High
8.0
Avg CVSS

Yearly Trend

2026
1
2025
3
2023
2
2021
2
2020
1

Top Affected Vendors

1 Fedoraproject 1
2 Microsoft 1
3 Netapp 1
4 Canonical 1
5 Busybox 1
6 Valvesoftware 1
7 Justsystems 1
8 Gss Ntlmssp Project 1

All CWE-590 CVEs (9)

CVE-2021-42377
9.8

CVE-2021-42377 is a critical vulnerability in BusyBox's hush shell applet where an attacker-controlled pointer free leads to denial of service and pot...

Nov 15, 2021
CVE-2020-6016
9.8

This vulnerability in Valve's Game Networking Sockets library allows remote attackers to execute arbitrary code by sending specially crafted unreliabl...

Nov 18, 2020
CVE-2025-32911
9.0

A use-after-free vulnerability in libsoup's soup_message_headers_get_content_disposition() function allows malicious HTTP clients to cause memory corr...

Apr 15, 2025
CVE-2026-20810
7.8

This vulnerability in Windows Ancillary Function Driver for WinSock allows an authorized attacker to perform a use-after-free attack on non-heap memor...

Jan 13, 2026
CVE-2021-3939
7.8

This CVE describes a double-free memory corruption vulnerability in Ubuntu's accountsservice. Attackers can exploit this via the SetLanguage D-Bus fun...

Nov 17, 2021
CVE-2025-42994
7.5

CVE-2025-42994 is a denial-of-service vulnerability in SAP MDM Server's ReadString function where specially crafted packets can cause memory access vi...

Jun 10, 2025
CVE-2023-25565
7.5

CVE-2023-25565 is a denial-of-service vulnerability in GSS-NTLMSSP, a GSSAPI plugin for NTLM authentication. An incorrect free operation when decoding...

Feb 14, 2023
CVE-2023-22291
7.0

This CVE describes an invalid free vulnerability in Ichitaro 2022's Frame stream parser. Attackers can craft malicious documents that cause memory cor...

Apr 5, 2023
CVE-2025-42996
5.6

SAP MDM Server has a session fixation vulnerability (CWE-590) that allows attackers to hijack existing client sessions without re-authentication. This...

Jun 10, 2025

About CWE-590 (CWE-590)

Our database tracks 9 CVEs classified as CWE-590, with 3 rated critical and 5 rated high severity. The average CVSS score for CWE-590 vulnerabilities is 8.0.

External reference: View CWE-590 on MITRE CWE →

Monitor CWE-590 Vulnerabilities

Get alerted when new CWE-590 CVEs affect your infrastructure.

Start Monitoring Free