VYPR

CWE-415

Double Free

VariantDraftLikelihood: High

Description

The product calls free() twice on the same memory address.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (835)

page 22 of 42
  • CVE-2019-20397HigJan 22, 2020
    risk 0.50cvss 8.8epss 0.02

    A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminated. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially code execution.

  • CVE-2019-20394HigJan 22, 2020
    risk 0.50cvss 8.8epss 0.03

    A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notification statement. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially code…

  • CVE-2019-20393HigJan 22, 2020
    risk 0.50cvss 8.8epss 0.03

    A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially code execution.

  • CVE-2018-15518HigDec 26, 2018
    risk 0.50cvss 8.8epss 0.03

    QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.

  • CVE-2016-1516HigApr 10, 2017
    risk 0.50cvss 8.8epss 0.02

    OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.

  • CVE-2026-20338HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could…

  • CVE-2026-12659HigJul 14, 2026
    risk 0.49cvss epss 0.00

    A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O.

  • CVE-2026-11576HigJun 19, 2026
    risk 0.49cvss 7.5epss 0.00

    The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file was never successfully opened. Multiple…

  • CVE-2025-69650HigMar 6, 2026
    risk 0.49cvss 7.5epss 0.01

    GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result,…

  • CVE-2026-25556HigFeb 6, 2026
    risk 0.49cvss 7.5epss 0.00

    MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling…

  • CVE-2026-21918HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX and MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX and MX Series platforms, when during TCP session establishment a…

  • CVE-2025-61990HigOct 15, 2025
    risk 0.49cvss 7.5epss 0.00

    When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2025-53948HigAug 18, 2025
    risk 0.49cvss 7.5epss 0.01

    The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-service condition. The application would require a manual restart and no authentication is required.

  • CVE-2025-50169HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network.

  • CVE-2025-23322HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where multiple requests could cause a double free when a stream is cancelled before it is processed. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-5262HigMay 27, 2025
    risk 0.49cvss 7.5epss 0.00

    A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.

  • CVE-2024-39564HigFeb 5, 2025
    risk 0.49cvss 7.5epss 0.00

    This is a similar, but different vulnerability than the issue reported as CVE-2024-39549. A double-free vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which…

  • CVE-2024-12107HigDec 4, 2024
    risk 0.49cvss 7.5epss 0.01

    Double-Free Vulnerability in uD3TN BPv7 Caused by Malformed Endpoint Identifier allows remote attacker to reliably cause DoS

  • CVE-2024-21606HigJan 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). In a remote access VPN scenario, if a "tcp-encap-profile" is configured and a…

  • CVE-2023-38434HigJul 18, 2023
    risk 0.49cvss 7.5epss 0.01

    xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method.