CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
828 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 10 of 17
- CVE-2022-50248HIGHCVSS 7.8EG 7.82025-09-15
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix double free on tx path. We see kernel crashes and lockups and KASAN errors related to ax210 firmware crashes. One of the KASAN dumps pointed at …
- CVE-2022-50303HIGHCVSS 7.8EG 7.82025-09-15
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix double release compute pasid If kfd_process_device_init_vm returns failure after vm is converted to compute vm and vm->pasid set to compute pasid, KFD wi…
- CVE-2022-50401HIGHCVSS 7.8EG 7.82025-09-18
In the Linux kernel, the following vulnerability has been resolved: nfsd: under NFSv4.1, fix double svc_xprt_put on rpc_create failure On error situation `clp->cl_cb_conn.cb_xprt` should not be given a reference to the xprt otherwise bot…
- CVE-2022-50419HIGHCVSS 7.8EG 7.82025-09-18
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sysfs: Fix attempting to call device_add multiple times device_add shall not be called multiple times as stated in its documentation: 'Do not call this …
- CVE-2022-50470HIGHCVSS 7.8EG 7.82025-10-04
In the Linux kernel, the following vulnerability has been resolved: xhci: Remove device endpoints from bandwidth list when freeing the device Endpoints are normally deleted from the bandwidth list when they are dropped, before the virt d…
- CVE-2022-50499HIGHCVSS 7.8EG 7.82025-10-04
In the Linux kernel, the following vulnerability has been resolved: media: dvb-core: Fix double free in dvb_register_device() In function dvb_register_device() -> dvb_register_media_device() -> dvb_create_media_entity(), dvb->entity is a…
- CVE-2022-50536HIGHCVSS 7.8EG 7.82025-10-07
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix repeated calls to sock_put() when msg has more_data In tcp_bpf_send_verdict() redirection, the eval variable is assigned to __SK_REDIRECT after the app…
- CVE-2022-50543HIGHEG 7.82025-10-07
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix mr->map double free rxe_mr_cleanup() which tries to free mr->map again will be called when rxe_mr_init_user() fails: CPU: 0 PID: 4917 Comm: rdma_flush_…
- CVE-2023-1032MEDIUMCVSS 4.7EG 4.72024-01-08
The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15c7691e9b13cbe9bf6c6…
- CVE-2023-1449HIGHCVSS 5.3EG 7.82023-03-17
A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function gf_av1_reset_state of the file media_tools/av_parsers.c. The manipulation leads to double free. I…
- CVE-2023-1999MEDIUMCVSS 5.3EG 5.32023-06-20
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memor…
- CVE-2023-21030HIGHCVSS 7.8EG 7.82023-03-24
In Confirmation of keystore_cli_v2.cpp, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User intera…
- CVE-2023-21106HIGHCVSS 7.8EG 7.82023-05-15
In adreno_set_param of adreno_gpu.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitati…
- CVE-2023-21500MEDIUMCVSS 6.0EG 6.02023-05-04
Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.
- CVE-2023-21629MEDIUMCVSS 6.8EG 6.82023-07-04
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
- CVE-2023-23402HIGHCVSS 7.8EG 7.82023-03-14
Windows Media Remote Code Execution Vulnerability
- CVE-2023-24903HIGHCVSS 8.1EG 8.12023-05-09
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2023-25136CRITICALCVSS 6.5EG 9.82023-02-03
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to…
- CVE-2023-25801HIGHCVSS 8.0EG 8.02023-03-25
TensorFlow is an open source machine learning platform. Prior to versions 2.12.0 and 2.11.1, `nn_ops.fractional_avg_pool_v2` and `nn_ops.fractional_max_pool_v2` require the first and fourth elements of their parameter `pooling_ratio` to be…
- CVE-2023-26545HIGHCVSS 4.7EG 7.82023-02-25
In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device.
- CVE-2023-27320HIGHCVSS 7.2EG 7.22023-02-28
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
- CVE-2023-27537MEDIUMCVSS 5.9EG 5.92023-03-30
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact…
- CVE-2023-28296HIGHCVSS 7.8EG 8.42023-04-11
Visual Studio Remote Code Execution Vulnerability
- CVE-2023-28411MEDIUMCVSS 6.3EG 6.32023-05-10
Double free in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.
- CVE-2023-28464HIGHCVSS 7.8EG 7.82023-03-31
hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escal…
- CVE-2023-28583MEDIUMCVSS 6.7EG 6.72024-01-02
Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address.
- CVE-2023-29366HIGHCVSS 7.8EG 7.82023-06-14
Windows Geolocation Service Remote Code Execution Vulnerability
- CVE-2023-29368HIGHCVSS 7.0EG 7.02023-06-14
Windows Filtering Platform Elevation of Privilege Vulnerability
- CVE-2023-29469MEDIUMCVSS 6.5EG 6.52023-04-24
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double…
- CVE-2023-32824MEDIUMCVSS 6.7EG 6.72023-10-02
In rpmb , there is a possible double free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07912966; Issue ID:…
- CVE-2023-3312HIGHCVSS 7.5EG 7.52023-06-19
A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during device unbind will lead to double release problem leading to denial of service.
- CVE-2023-33137HIGHCVSS 7.8EG 7.82023-06-14
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2023-33161HIGHCVSS 7.8EG 7.82023-07-11
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2023-33952MEDIUMCVSS 6.7EG 6.72023-07-24
A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on…
- CVE-2023-35371HIGHCVSS 7.8EG 7.82023-08-08
Microsoft Office Remote Code Execution Vulnerability
- CVE-2023-35784CRITICALCVSS 9.8EG 9.82023-06-16
A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
- CVE-2023-36418HIGHCVSS 7.8EG 7.82023-10-10
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
- CVE-2023-36420HIGHCVSS 7.8EG 7.82023-10-10
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2023-37365MEDIUMCVSS 6.5EG 6.52023-06-30
Hnswlib 0.7.0 has a double free in init_index when the M argument is a large integer.
- CVE-2023-38434HIGHCVSS 7.5EG 7.52023-07-18
xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method.
- CVE-2023-38562HIGHCVSS 8.7EG 8.72024-02-20
A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An…
- CVE-2023-39975HIGHCVSS 8.8EG 8.82023-08-16
kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.
- CVE-2023-40103HIGHCVSS 7.8EG 7.82023-12-04
In multiple locations, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-41325MEDIUMCVSS 6.7EG 6.72023-09-15
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20 and prior to version 3.22, `shdr_verify_signature` c…
- CVE-2023-41374HIGHCVSS 7.8EG 7.82023-09-20
Double free issue exists in Kostac PLC Programming Software Version 1.6.11.0 and earlier. Arbitrary code may be executed by having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1…
- CVE-2023-41678HIGHCVSS 8.8EG 8.82023-12-13
A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request.
- CVE-2023-41911MEDIUMCVSS 5.5EG 5.52023-09-28
Samsung Mobile Processor Exynos 2200 allows a GPU Double Free (issue 1 of 2).
- CVE-2023-42459HIGHCVSS 7.5EG 7.52023-10-16
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). In affected versions specific DATA submessages can be sent to a discovery locator which may trigger a free error. This c…
- CVE-2023-4256MEDIUMCVSS 5.5EG 5.52023-12-21
Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewri…
- CVE-2023-43281MEDIUMCVSS 6.5EG 6.52023-10-25
Double Free vulnerability in Nothings Stb Image.h v.2.28 allows a remote attacker to cause a denial of service via a crafted file to the stbi_load_gif_main function.
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →