CWE-823: CWE-823

40
Total CVEs
2
Critical
28
High
7.5
Avg CVSS

Yearly Trend

2026
2
2025
16
2024
12
2023
4
2022
3

Top Affected Vendors

1 Qualcomm 17
2 Cesanta 4
3 Fedoraproject 2
4 Apple 2
5 Debian 2
6 Vim 2
7 Codesys 2
8 Siemens 1
9 Imaginationtech 1
10 Wago 1

All CWE-823 CVEs (40)

CVE-2017-11076
9.8

CVE-2017-11076 is a critical memory corruption vulnerability in Qualcomm hardware VP9 video decoding that allows attackers to execute arbitrary code o...

Nov 26, 2024
CVE-2023-24855
9.8

This vulnerability allows memory corruption in Qualcomm modem chipsets while processing security configuration before AS Security Exchange. Attackers ...

Oct 3, 2023
CVE-2025-27059
8.8

This vulnerability allows memory corruption during SCM (System Control Manager) calls in Qualcomm components, potentially enabling privilege escalatio...

Oct 9, 2025
CVE-2022-0729
8.8

CVE-2022-0729 is a use-after-free vulnerability in Vim's memory handling that allows an attacker to execute arbitrary code by tricking a user into ope...

Feb 23, 2022
CVE-2023-43534
8.6

This vulnerability allows memory corruption when a Wi-Fi station connects to an access point due to improper validation of TID to Link Mapping action ...

Feb 6, 2024
CVE-2023-33066
8.4

This vulnerability allows memory corruption in Qualcomm audio drivers when processing RT proxy port register operations. Attackers could potentially e...

Mar 4, 2024
CVE-2023-33106
8.4

This vulnerability allows memory corruption in Qualcomm GPU drivers when processing large sync point lists in AUX commands. Attackers can potentially ...

Dec 5, 2023
CVE-2025-0467
8.2

This vulnerability allows kernel software within a Guest Virtual Machine to exploit shared memory with GPU firmware to write data outside the Guest's ...

Apr 18, 2025
CVE-2024-42386
8.2

This vulnerability in Cesanta Mongoose Web Server allows attackers to cause a segmentation fault by sending specially crafted TLS packets. It affects ...

Nov 18, 2024
CVE-2022-32142
8.1

CVE-2022-32142 is an out-of-bounds read/write vulnerability in multiple CODESYS products that allows low-privileged remote attackers to cause denial-o...

Jun 24, 2022
CVE-2021-34595
8.1

CVE-2021-34595 is an out-of-bounds read/write vulnerability in CODESYS V2 Runtime Toolkit and PLCWinNT software. Attackers can send crafted requests w...

Oct 26, 2021
CVE-2021-3888
8.1

CVE-2021-3888 is a use-after-free vulnerability in libmobi, a library for handling MOBI eBook files. Attackers can exploit this by crafting malicious ...

Oct 19, 2021
CVE-2020-27009
8.1

This vulnerability allows attackers to execute arbitrary code or cause denial-of-service by exploiting improper validation of DNS pointer offsets duri...

Apr 22, 2021
CVE-2025-47349
7.8

This CVE describes a memory corruption vulnerability in Qualcomm components that occurs while processing escape calls. Attackers could exploit this to...

Oct 9, 2025
CVE-2025-25180
7.8

This GPU driver vulnerability allows non-privileged users to make improper GPU system calls that can write to arbitrary physical memory pages. This co...

Jul 14, 2025
CVE-2024-45557
7.8

This vulnerability allows memory corruption in Qualcomm chipsets when Trusted Execution Environment (TEE) components process untrusted memory addresse...

Apr 7, 2025
CVE-2024-43060
7.8

This CVE describes a memory corruption vulnerability in Qualcomm's voice activation system when sound model parameters are transferred from the HLOS (...

Mar 3, 2025
CVE-2024-49840
7.8

This vulnerability allows memory corruption when user-space applications make IOCTL calls to validate FIPS encryption/decryption functionality. Attack...

Feb 3, 2025
CVE-2024-45573
7.8

This vulnerability allows memory corruption through negative indexing of display ID during test pattern generation. It affects systems using Qualcomm ...

Feb 3, 2025
CVE-2024-47900
7.8

This vulnerability allows non-privileged software to make improper GPU system calls that access out-of-bounds kernel memory. It affects systems using ...

Jan 31, 2025
CVE-2024-52938
7.8

This vulnerability allows kernel software running inside a Guest Virtual Machine to issue improper commands to the GPU Firmware, potentially bypassing...

Jan 13, 2025
CVE-2024-1013
7.8

An out-of-bounds stack write vulnerability in unixODBC on 64-bit architectures allows attackers to corrupt memory by writing 8 bytes into a 4-byte buf...

Mar 18, 2024
CVE-2023-43513
7.8

This vulnerability allows memory corruption in Qualcomm hardware components when processing event rings, where an untrusted context read pointer can b...

Feb 6, 2024
CVE-2023-33110
7.8

This CVE describes a race condition vulnerability in Qualcomm's PCM host voice audio driver where improper session index handling during event callbac...

Jan 2, 2024
CVE-2023-33079
7.8

This vulnerability allows memory corruption in the Audio subsystem when processing invalid audio recording data from the ADSP (Audio Digital Signal Pr...

Dec 5, 2023
CVE-2023-22387
7.8

This vulnerability allows arbitrary memory overwrite when a virtual machine gets compromised during TX write operations, leading to memory corruption....

Jul 4, 2023
CVE-2022-0685
7.8

CVE-2022-0685 is a memory corruption vulnerability in Vim text editor caused by an out-of-range pointer offset. Attackers can exploit this by tricking...

Feb 20, 2022
CVE-2025-11232
7.5

A configuration-dependent denial-of-service vulnerability in ISC Kea DHCP server versions 3.0.1-3.0.1 and 3.1.1-3.1.2. When specific configuration par...

Oct 29, 2025
CVE-2024-47894
7.1

This vulnerability allows kernel software in a Guest VM to issue improper GPU firmware commands, potentially reading data outside the guest's allocate...

Jan 13, 2025
CVE-2024-47895
7.1

This vulnerability allows kernel software in a Guest VM to send improper commands to GPU firmware, potentially reading data outside the Guest's alloca...

Jan 13, 2025
CVE-2024-52937
6.7

This vulnerability allows kernel software running inside a Guest Virtual Machine to write data outside its allocated GPU memory boundaries by exploiti...

Jan 13, 2025
CVE-2024-33036
6.7

This CVE describes a memory corruption vulnerability in Qualcomm camera drivers where a user-space variable is used for kernel memory allocation, pote...

Dec 2, 2024
CVE-2024-23377
6.7

This vulnerability allows memory corruption in Qualcomm EVA drivers when user-space applications modify packet sizes after system properties have been...

Nov 4, 2024
CVE-2024-47893
6.5

This vulnerability allows kernel software running inside a Guest Virtual Machine to exploit shared memory with GPU firmware, potentially reading or wr...

May 17, 2025
CVE-2026-20022
6.1

This vulnerability in Cisco Secure Firewall ASA and FTD Software allows an unauthenticated attacker on the same network segment to cause a denial-of-s...

Mar 4, 2026
CVE-2024-42388
5.3

This vulnerability in Cesanta Mongoose Web Server allows attackers to send specially crafted TLS packets that cause the server to read memory outside ...

Nov 18, 2024
CVE-2024-42390
4.3

This vulnerability in Cesanta Mongoose Web Server v7.14 allows attackers to send specially crafted TLS packets that cause the server to read memory ou...

Nov 18, 2024
CVE-2024-42383
4.2

This vulnerability in Cesanta Mongoose Web Server v7.14 allows attackers to write a NULL byte beyond the allocated memory for hostname fields. This co...

Nov 18, 2024
CVE-2024-52935
4.1

This vulnerability allows kernel software running inside a Guest VM to write data outside its allocated GPU memory boundaries by exploiting shared mem...

Jan 13, 2025
CVE-2026-23764
N/A

This vulnerability allows unprivileged local attackers to trigger a kernel crash (Blue Screen of Death) on Windows systems running vulnerable VB-Audio...

Jan 22, 2026

About CWE-823 (CWE-823)

Our database tracks 40 CVEs classified as CWE-823, with 2 rated critical and 28 rated high severity. The average CVSS score for CWE-823 vulnerabilities is 7.5.

External reference: View CWE-823 on MITRE CWE →

Monitor CWE-823 Vulnerabilities

Get alerted when new CWE-823 CVEs affect your infrastructure.

Start Monitoring Free