CWE-415
Double Free
Description
The product calls free() twice on the same memory address.
Hierarchy (View 1000)
CVEs mapped to this weakness (835)
page 17 of 42| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21106 | Hig | 0.51 | 7.8 | 0.00 | May 15, 2023 | In adreno_set_param of adreno_gpu.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android… | ||
| CVE-2023-28296 | Hig | 0.51 | 7.8 | 0.01 | Apr 11, 2023 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-28464 | Hig | 0.51 | 7.8 | 0.00 | Mar 31, 2023 | hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escalation. | ||
| CVE-2023-21030 | Hig | 0.51 | 7.8 | 0.00 | Mar 24, 2023 | In Confirmation of keystore_cli_v2.cpp, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-23402 | Hig | 0.51 | 7.8 | 0.01 | Mar 14, 2023 | Windows Media Remote Code Execution Vulnerability | ||
| CVE-2022-40683 | Hig | 0.51 | 7.8 | 0.00 | Feb 16, 2023 | A double free in Fortinet FortiWeb version 7.0.0 through 7.0.3 may allows attacker to execute unauthorized code or commands via specially crafted commands | ||
| CVE-2022-3238 | Hig | 0.51 | 7.8 | 0.00 | Nov 14, 2022 | A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system. | ||
| CVE-2022-25660 | Hig | 0.51 | 7.8 | 0.00 | Oct 19, 2022 | Memory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | ||
| CVE-2022-33033 | Hig | 0.51 | 7.8 | 0.01 | Jun 23, 2022 | LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c. | ||
| CVE-2021-39806 | Hig | 0.51 | 7.8 | 0.00 | Jun 15, 2022 | In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege during startup of servicemanager, if an attacker can trigger an initialization failure, with no additional execution privileges… | ||
| CVE-2022-22103 | Hig | 0.51 | 7.8 | 0.00 | Jun 14, 2022 | Memory corruption in multimedia driver due to double free while processing data from user in Snapdragon Auto | ||
| CVE-2021-42613 | Hig | 0.51 | 7.8 | 0.01 | May 24, 2022 | A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact via a crafted text document. | ||
| CVE-2022-29032 | Hig | 0.51 | 7.8 | 0.01 | May 20, 2022 | A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The CGM_NIST_Loader.dll library contains a double free vulnerability while parsing… | ||
| CVE-2022-27416 | Hig | 0.51 | 7.8 | 0.01 | Apr 12, 2022 | Tcpreplay v4.4.1 was discovered to contain a double-free via __interceptor_free. | ||
| CVE-2022-25796 | Hig | 0.51 | 7.8 | 0.01 | Apr 11, 2022 | A Double Free vulnerability allows remote malicious actors to execute arbitrary code on DWF file in Autodesk Navisworks 2022 within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | ||
| CVE-2021-42533 | Hig | 0.51 | 7.8 | 0.02 | Mar 16, 2022 | Adobe Bridge version 11.1.1 (and earlier) is affected by a double free vulnerability when parsing a crafted DCM file, which could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit. | ||
| CVE-2021-46625 | Hig | 0.51 | 7.8 | 0.02 | Feb 18, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists… | ||
| CVE-2021-46621 | Hig | 0.51 | 7.8 | 0.02 | Feb 18, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The… | ||
| CVE-2021-30703 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2021 | A double free issue was addressed with improved memory management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. An application may be able to execute arbitrary… | ||
| CVE-2021-1875 | Hig | 0.51 | 7.8 | 0.01 | Sep 8, 2021 | A double free issue was addressed with improved memory management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted file may lead to… |
- risk 0.51cvss 7.8epss 0.00
In adreno_set_param of adreno_gpu.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…
- risk 0.51cvss 7.8epss 0.01
Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escalation.
- risk 0.51cvss 7.8epss 0.00
In Confirmation of keystore_cli_v2.cpp, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.01
Windows Media Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
A double free in Fortinet FortiWeb version 7.0.0 through 7.0.3 may allows attacker to execute unauthorized code or commands via specially crafted commands
- risk 0.51cvss 7.8epss 0.00
A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.
- risk 0.51cvss 7.8epss 0.00
Memory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
- risk 0.51cvss 7.8epss 0.01
LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.
- risk 0.51cvss 7.8epss 0.00
In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege during startup of servicemanager, if an attacker can trigger an initialization failure, with no additional execution privileges…
- risk 0.51cvss 7.8epss 0.00
Memory corruption in multimedia driver due to double free while processing data from user in Snapdragon Auto
- risk 0.51cvss 7.8epss 0.01
A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact via a crafted text document.
- risk 0.51cvss 7.8epss 0.01
A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The CGM_NIST_Loader.dll library contains a double free vulnerability while parsing…
- risk 0.51cvss 7.8epss 0.01
Tcpreplay v4.4.1 was discovered to contain a double-free via __interceptor_free.
- risk 0.51cvss 7.8epss 0.01
A Double Free vulnerability allows remote malicious actors to execute arbitrary code on DWF file in Autodesk Navisworks 2022 within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
- risk 0.51cvss 7.8epss 0.02
Adobe Bridge version 11.1.1 (and earlier) is affected by a double free vulnerability when parsing a crafted DCM file, which could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
- risk 0.51cvss 7.8epss 0.02
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists…
- risk 0.51cvss 7.8epss 0.02
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The…
- risk 0.51cvss 7.8epss 0.00
A double free issue was addressed with improved memory management. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave, macOS Big Sur 11.4, watchOS 7.5. An application may be able to execute arbitrary…
- risk 0.51cvss 7.8epss 0.01
A double free issue was addressed with improved memory management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing a maliciously crafted file may lead to…