CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
828 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 15 of 17
- CVE-2025-5351MEDIUMCVSS 6.5EG 6.52025-07-04
A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared…
- CVE-2025-53948HIGHCVSS 7.5EG 7.52025-08-18
The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-service condition. The application would require a manual restart and no authentication is required.
- CVE-2025-55118HIGHCVSS 8.9EG 8.92025-09-16
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting …
- CVE-2025-55158HIGHCVSS 8.8EG 8.82025-08-11
Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tuples during Vim9 script import operations, an error during evaluation can trigger a double-free in Vim’s internal typ…
- CVE-2025-57785MEDIUMCVSS 6.5EG 6.52026-01-26
A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to corrupt data which may lead to arbitrary code execution.
- CVE-2025-5914HIGHCVSS 7.8EG 7.82025-06-09
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a d…
- CVE-2025-59289HIGHCVSS 7.0EG 7.02025-10-14
Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-59505HIGHCVSS 7.8EG 7.82025-11-11
Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
- CVE-2025-61145MEDIUMCVSS 5.0EG 5.52026-02-23
libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
- CVE-2025-61990HIGHCVSS 7.5EG 7.52025-10-15
When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluate…
- CVE-2025-62215CRITICALCVSS 7.0EG 9.0⚠ KEV2025-11-11
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2025-62219HIGHCVSS 7.0EG 7.02025-11-11
Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.
- CVE-2025-62469HIGHCVSS 7.0EG 7.02025-12-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- CVE-2025-65955MEDIUMCVSS 6.1EG 6.12025-12-02
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked wi…
- CVE-2025-68657MEDIUMCVSS 6.4EG 6.42026-01-12
Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hid_host_device_close() can free the same usb_transfer_t twice. The USB event callback and user code share the hid_iface_…
- CVE-2025-68968HIGHCVSS 7.8EG 7.82026-01-14
Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect the input function.
- CVE-2025-69650HIGHCVSS 7.5EG 7.52026-03-06
GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocat…
- CVE-2025-71238HIGHCVSS 7.8EG 7.82026-03-04
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix bsg_done() causing double free Kernel panic observed on system, [5353358.825191] BUG: unable to handle page fault for address: ff5f5e897b024000 [5353…
- CVE-2025-8058MEDIUMCVSS 5.9EG 5.92025-07-23
The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random mal…
- CVE-2025-8585MEDIUMCVSS 5.3EG 5.32025-08-05
A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the file /avtools/avconv.c of the component DSS File Demuxer. The manipulation leads to double free. Atta…
- CVE-2026-10653HIGHCVSS 8.1EG 8.12026-06-30
The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and the per-data-block ref_count at the start of each variable/heap data allocation -- with plain non-atomic C operators (bu…
- CVE-2026-11576HIGHCVSS 7.5EG 7.52026-06-19
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file …
- CVE-2026-12043HIGHCVSS 8.8EG 8.82026-06-12
Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to a…
- CVE-2026-12659HIGHCVSS 8.7EG 8.72026-07-14
A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the…
- CVE-2026-13713MEDIUMCVSS 6.2EG 6.22026-07-16
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the bundled libsyck, when an anchor name is redefined or removed, syck_hdlr_add_anchor and …
- CVE-2026-14164HIGHCVSS 7.5EG 7.52026-06-30
A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent proces…
- CVE-2026-14604MEDIUMCVSS 6.3EG 6.32026-07-03
A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporter::ExportToBlob of the file code/AssetLib/Ply/PlyLoader.cpp of the component PLY Model Handler. This manipulation cause…
- CVE-2026-17573MEDIUMCVSS 4.0EG 4.02026-07-27
A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.
- CVE-2026-20026MEDIUMCVSS 5.8EG 5.82026-01-07
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resu…
- CVE-2026-20415MEDIUMCVSS 5.5EG 5.52026-02-02
In imgsys, there is a possible memory corruption due to improper locking. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID:…
- CVE-2026-20832HIGHCVSS 7.8EG 7.82026-01-13
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
- CVE-2026-20861HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20863HIGHCVSS 7.0EG 7.02026-01-13
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
- CVE-2026-20867HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-21530MEDIUMCVSS 6.7EG 6.72026-05-12
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
- CVE-2026-21918HIGHCVSS 7.5EG 7.52026-01-15
A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX and MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX and MX Series platforms, w…
- CVE-2026-23068HIGHCVSS 7.8EG 7.82026-02-04
In the Linux kernel, the following vulnerability has been resolved: spi: spi-sprd-adi: Fix double free in probe error path The driver currently uses spi_alloc_host() to allocate the controller but registers it using devm_spi_register_con…
- CVE-2026-23098HIGHCVSS 7.8EG 8.82026-02-04
In the Linux kernel, the following vulnerability has been resolved: netrom: fix double-free in nr_route_frame() In nr_route_frame(), old_skb is immediately freed without checking if nr_neigh->ax25 pointer is NULL. Therefore, if nr_neigh-…
- CVE-2026-23162HIGHCVSS 7.8EG 7.82026-02-14
In the Linux kernel, the following vulnerability has been resolved: drm/xe/nvm: Fix double-free on aux add failure After a successful auxiliary_device_init(), aux_dev->dev.release (xe_nvm_release_dev()) is responsible for the kfree(nvm).…
- CVE-2026-23387HIGHCVSS 7.8EG 7.82026-03-25
In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() devm_add_action_or_reset() already invokes the action on failure, so the explicit put causes a double-put.
- CVE-2026-23408HIGHCVSS 7.8EG 7.82026-04-01
In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix double free of ns_name in aa_replace_profiles() if ns_name is NULL after 1071 error = aa_unpack(udata, &lh, &ns_name); and if ent->ns_name contain…
- CVE-2026-23449HIGHCVSS 7.8EG 7.82026-04-03
In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: Fix double-free in teql_master_xmit Whenever a TEQL devices has a lockless Qdisc as root, qdisc_reset should be called using the seq_lock to avoid racin…
- CVE-2026-23868MEDIUMCVSS 5.1EG 5.12026-03-10
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.
- CVE-2026-23918HIGHCVSS 8.8EG 8.92026-05-04
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
- CVE-2026-25556HIGHCVSS 7.5EG 7.52026-02-06
MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly dr…
- CVE-2026-26163HIGHCVSS 7.8EG 7.82026-04-14
Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-26166HIGHCVSS 7.0EG 7.02026-04-14
Double free in Windows Shell allows an authorized attacker to elevate privileges locally.
- CVE-2026-26179HIGHCVSS 7.8EG 7.82026-04-14
Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-28537MEDIUMCVSS 5.5EG 5.52026-03-05
Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-31053MEDIUMCVSS 6.2EG 6.22026-04-06
A double free vulnerability exists in librz/bin/format/le/le.c in the function le_load_fixup_record(). When processing malformed or circular LE fixup chains, relocation entries may be freed multiple times during error handling. A specially…
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →