CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
827 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 1 of 17
- CVE-2002-0059CRITICALCVSS 9.8EG 9.82002-03-15
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute ar…
- CVE-2003-0015HIGHCVSS v2 7.5EG 7.52003-02-07
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-pro…
- CVE-2003-0545CRITICALCVSS 9.8EG 9.82003-11-17
Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.
- CVE-2003-1048HIGHCVSS 7.8EG 7.82004-07-27
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.
- CVE-2004-0642HIGHCVSS v2 7.5EG 7.52004-09-28
Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary c…
- CVE-2004-0643MEDIUMCVSS v2 4.6EG 4.62004-09-28
Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.
- CVE-2004-0772CRITICALCVSS 9.8EG 9.82004-10-20
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.
- CVE-2005-0891HIGHCVSS 7.5EG 7.52005-05-02
Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.
- CVE-2007-1216HIGHCVSS v2 9.0EG 9.02007-04-06
Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC librar…
- CVE-2007-4773CRITICALCVSS 9.8EG 9.82020-01-15
Systrace before 1.6.0 has insufficient escape policy enforcement.
- CVE-2008-2944MEDIUMCVSS v2 4.9EG 4.92008-06-30
Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Enterprise Linux (RHEL) 5 and Fedora Core 6 (FC6) allows local users to cause a denial of service (oops), as demonstrated by a crash when runn…
- CVE-2009-1544HIGHCVSS 8.8EG 8.82009-08-12
Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via…
- CVE-2010-3080HIGHCVSS v2 7.2EG 7.22010-09-21
Double free vulnerability in the snd_seq_oss_open function in sound/core/seq/oss/seq_oss_init.c in the Linux kernel before 2.6.36-rc4 might allow local users to cause a denial of service or possibly have unspecified other impact via an uns…
- CVE-2010-3957HIGHCVSS 7.3EG 7.32010-12-16
Double free vulnerability in the OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges…
- CVE-2010-4494HIGHCVSS v2 7.5EG 7.52010-12-07
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors relat…
- CVE-2011-1803MEDIUMCVSS 6.5EG 6.52019-11-12
An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Blink M11 and M12 when trying to access a removed smil element.
- CVE-2011-2335HIGHCVSS 7.5EG 7.52019-11-12
A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function.
- CVE-2011-2821HIGHCVSS v2 7.5EG 7.52011-08-29
Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
- CVE-2011-2834MEDIUMCVSS v2 6.8EG 6.82011-09-19
Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
- CVE-2011-3892HIGHCVSS v2 7.5EG 7.52011-11-11
Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
- CVE-2014-0301HIGHCVSS v2 9.3EG 9.32014-03-12
Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold a…
- CVE-2014-0502CRITICALCVSS 8.8EG 9.0⚠ KEV2014-02-21
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.162…
- CVE-2014-1252HIGHCVSS v2 7.5EG 7.52014-01-24
Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.
- CVE-2014-1767HIGHCVSS v2 7.2EG 7.22014-07-08
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wind…
- CVE-2014-4343HIGHCVSS v2 7.6EG 7.62014-08-14
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (m…
- CVE-2014-9807MEDIUMCVSS 5.5EG 5.52017-03-30
The pdb coder in ImageMagick allows remote attackers to cause a denial of service (double free) via unspecified vectors.
- CVE-2015-0058HIGHCVSS v2 7.2EG 7.22015-02-11
Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a crafted application, aka "Windows Cursor Object Double Free…
- CVE-2015-0312HIGHCVSS v2 9.3EG 9.32015-01-28
Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.0.296 on Windows and OS X and before 11.2.202.440 on Linux allows attackers to execute arbitrary code via unspecified vectors.
- CVE-2015-1207MEDIUMCVSS 6.5EG 6.52017-06-06
Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
- CVE-2015-1239MEDIUMCVSS 6.5EG 6.52017-10-18
Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.
- CVE-2015-5177HIGHCVSS 7.5EG 7.52017-10-22
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.
- CVE-2015-5203MEDIUMCVSS 5.5EG 5.52017-08-02
Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
- CVE-2015-7700CRITICALCVSS 9.8EG 9.82017-08-31
Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.
- CVE-2015-8880CRITICALCVSS 9.8EG 9.82016-05-22
Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error.
- CVE-2015-8894MEDIUMCVSS 5.5EG 5.52017-03-15
Double free vulnerability in coders/tga.c in ImageMagick 7.0.0 and later allows remote attackers to cause a denial of service (application crash) via a crafted tga file.
- CVE-2015-8962HIGHCVSS 7.3EG 7.32016-11-16
Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (memory corruption and system crash) by detaching a device dur…
- CVE-2015-9007HIGHCVSS 7.8EG 7.82017-06-06
In TrustZone in all Android releases from CAF using the Linux kernel, a Double Free vulnerability could potentially exist.
- CVE-2015-9165CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 650/52, SD 808, and S…
- CVE-2016-1516HIGHCVSS 8.8EG 8.82017-04-10
OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.
- CVE-2016-3132CRITICALCVSS 9.8EG 9.82016-08-07
Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to execute arbitrary code via a crafted index.
- CVE-2016-3177CRITICALCVSS 9.8EG 9.82017-01-23
Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors.
- CVE-2016-5384HIGHCVSS 7.8EG 7.82016-08-13
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
- CVE-2016-5768CRITICALCVSS 9.8EG 9.82016-08-07
Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to execute arbitrary code or cause…
- CVE-2016-5772CRITICALCVSS 9.8EG 9.82016-08-07
Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or pos…
- CVE-2016-6912CRITICALCVSS 9.8EG 9.82017-01-26
Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.
- CVE-2016-8360HIGHCVSS 8.1EG 8.12017-02-13
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. A specially crafted URL request sent to the SoftCMS ASP Webserver can cause a double free condition on the server allowing an attacker to modify memory locations and po…
- CVE-2016-8618CRITICALCVSS 5.3EG 9.82018-07-31
The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplication, on systems using 32 bit `size_t` variables.
- CVE-2016-8619CRITICALCVSS 5.3EG 9.82018-08-01
The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.
- CVE-2016-8693HIGHCVSS 7.8EG 7.82017-02-15
Double free vulnerability in the mem_close function in jas_stream.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image to the imginfo command.
- CVE-2016-9806HIGHCVSS 7.8EG 7.82016-12-28
Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that…
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →