VYPR

CWE-415

Double Free

VariantDraftLikelihood: High

Description

The product calls free() twice on the same memory address.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (886)

page 10 of 45
  • CVE-2026-62889HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.01

    Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

  • CVE-2024-43447HigNov 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows SMBv3 Server Remote Code Execution Vulnerability

  • CVE-2024-50215HigNov 9, 2024
    risk 0.53cvss 8.1epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: assign dh_key to NULL after kfree_sensitive ctrl->dh_key might be used across multiple calls to nvmet_setup_dhgroup() for the same controller. So it's better to nullify it after release on error…

  • CVE-2024-3446HigApr 9, 2024
    risk 0.53cvss 8.2epss 0.00

    A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious privileged guest user to crash the QEMU…

  • CVE-2023-24903HigMay 9, 2023
    risk 0.53cvss 8.1epss 0.01

    Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

  • CVE-2022-42915HigOct 29, 2022
    risk 0.53cvss 8.1epss 0.03

    curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the protocol through. An HTTP proxy might…

  • CVE-2022-23459HigAug 19, 2022
    risk 0.53cvss 8.1epss 0.01

    Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value class may lead to memory corruption via a double free or via a use after free. The value class has a default assignment operator which may be used with pointer…

  • CVE-2021-27033HigJul 9, 2021
    risk 0.53cvss 8.1epss 0.03

    A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Review application. A malicious actor may leverage this vulnerability to cause memory corruption and execute arbitrary code in the…

  • CVE-2020-16970HigNov 11, 2020
    risk 0.53cvss 8.1epss 0.01

    Azure Sphere Unsigned Code Execution Vulnerability

  • CVE-2018-21086HigApr 8, 2020
    risk 0.53cvss 8.1epss 0.00

    An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition with a resultant double free in vnswap_init_backing_storage. The Samsung ID is SVE-2017-11177 (February 2018).

  • CVE-2017-10914HigJul 5, 2017
    risk 0.53cvss 8.1epss 0.02

    The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA-218 bug 2.

  • CVE-2016-8360HigFeb 13, 2017
    risk 0.53cvss 8.1epss 0.02

    An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. A specially crafted URL request sent to the SoftCMS ASP Webserver can cause a double free condition on the server allowing an attacker to modify memory locations and possibly cause a denial of service or the…

  • CVE-2003-1048HigJul 27, 2004
    risk 0.53cvss 7.8epss 0.27

    Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.

  • CVE-2026-69876HigSep 8, 2026
    risk 0.52cvss 8.0epss 0.01

    Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.

  • CVE-2026-69322HigSep 8, 2026
    risk 0.52cvss 8.0epss 0.01

    Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-5100HigMay 23, 2025
    risk 0.52cvss 8.0epss 0.00

    A double-free condition occurs during the cleanup of temporary image files, which can be exploited to achieve memory corruption and potentially arbitrary code execution.

  • CVE-2019-5797HigSep 29, 2022
    risk 0.52cvss 7.5epss 0.03

    Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21797HigOct 18, 2021
    risk 0.52cvss 7.8epss 0.15

    An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stored in two different places. When closed, the document will result in the reference being released…

  • CVE-2018-5379HigFeb 19, 2018
    risk 0.52cvss 7.5epss 0.38

    The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute…

  • CVE-2026-23789HigSep 14, 2026
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of…