CVE-2016-7544: Cryptopp Crypto++
High severity, CVSS 7.5. EPSS: 2.7% chance of exploitation in the next 30 days.
Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed.
Affected products
- Cryptopp Crypto++: version 5.6.4 only
Published 2017-01-30. Last modified 2026-06-17.