VYPR

CWE-415

Double Free

VariantDraftLikelihood: High

Description

The product calls free() twice on the same memory address.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (835)

page 17 of 42
  • CVE-2023-21106HigMay 15, 2023
    risk 0.51cvss 7.8epss 0.00

    In adreno_set_param of adreno_gpu.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2023-28296HigApr 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Visual Studio Remote Code Execution Vulnerability

  • CVE-2023-28464HigMar 31, 2023
    risk 0.51cvss 7.8epss 0.00

    hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escalation.

  • CVE-2023-21030HigMar 24, 2023
    risk 0.51cvss 7.8epss 0.00

    In Confirmation of keystore_cli_v2.cpp, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-23402HigMar 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Media Remote Code Execution Vulnerability

  • CVE-2022-40683HigFeb 16, 2023
    risk 0.51cvss 7.8epss 0.00

    A double free in Fortinet FortiWeb version 7.0.0 through 7.0.3 may allows attacker to execute unauthorized code or commands via specially crafted commands

  • CVE-2022-3238HigNov 14, 2022
    risk 0.51cvss 7.8epss 0.00

    A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.

  • CVE-2022-25660HigOct 19, 2022
    risk 0.51cvss 7.8epss 0.00

    Memory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2022-33033HigJun 23, 2022
    risk 0.51cvss 7.8epss 0.01

    LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.

  • CVE-2021-39806HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege during startup of servicemanager, if an attacker can trigger an initialization failure, with no additional execution privileges…

  • CVE-2022-22103HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in multimedia driver due to double free while processing data from user in Snapdragon Auto

  • CVE-2021-42613HigMay 24, 2022
    risk 0.51cvss 7.8epss 0.01

    A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact via a crafted text document.

  • CVE-2022-29032HigMay 20, 2022
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The CGM_NIST_Loader.dll library contains a double free vulnerability while parsing…

  • CVE-2022-27416HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.01

    Tcpreplay v4.4.1 was discovered to contain a double-free via __interceptor_free.

  • CVE-2022-25796HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.01

    A Double Free vulnerability allows remote malicious actors to execute arbitrary code on DWF file in Autodesk Navisworks 2022 within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…

  • CVE-2021-42533HigMar 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Bridge version 11.1.1 (and earlier) is affected by a double free vulnerability when parsing a crafted DCM file, which could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.

  • CVE-2021-46625HigFeb 18, 2022
    risk 0.51cvss 7.8epss 0.02

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists…

  • CVE-2021-46621HigFeb 18, 2022
    risk 0.51cvss 7.8epss 0.02

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The…

  • CVE-2021-30703HigSep 8, 2021
    risk 0.51cvss 7.8epss 0.00

    A double free issue was addressed with improved memory management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. An application may be able to execute arbitrary…

  • CVE-2021-1875HigSep 8, 2021
    risk 0.51cvss 7.8epss 0.01

    A double free issue was addressed with improved memory management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted file may lead to…