VYPR

CWE-415

Double Free

VariantDraftLikelihood: High

Description

The product calls free() twice on the same memory address.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (835)

page 26 of 42
  • CVE-2025-20801HigJan 6, 2026
    risk 0.46cvss 7.0epss 0.00

    In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10251210; Issue ID: MSV-4926.

  • CVE-2025-62469HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62219HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59289HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-23282HigOct 10, 2025
    risk 0.46cvss 7.0epss 0.00

    NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and…

  • CVE-2025-47975HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

  • CVE-2022-49789HigMay 1, 2025
    risk 0.46cvss 7.0epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: scsi: zfcp: Fix double free of FSF request when qdio send fails We used to use the wrong type of integer in 'zfcp_fsf_req_send()' to cache the FSF request ID when sending a new FSF request. This is used in…

  • CVE-2025-26640HigApr 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2024-49095HigDec 12, 2024
    risk 0.46cvss 7.0epss 0.00

    Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

  • CVE-2024-50159HigNov 7, 2024
    risk 0.46cvss 7.0epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix the double free in scmi_debugfs_common_setup() Clang static checker(scan-build) throws below warning: | drivers/firmware/arm_scmi/driver.c:line 2915, column 2 | Attempt to…

  • CVE-2024-38157HigAug 13, 2024
    risk 0.46cvss 7.0epss 0.00

    Azure IoT SDK Remote Code Execution Vulnerability

  • CVE-2024-42123HigJul 30, 2024
    risk 0.46cvss 7.0epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix double free err_addr pointer warnings In amdgpu_umc_bad_page_polling_timeout, the amdgpu_umc_handle_bad_pages will be run many times so that double free err_addr in some special case. So set…

  • CVE-2024-36030HigMay 30, 2024
    risk 0.46cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix the double free in rvu_npc_freemem() Clang static checker(scan-build) warning: drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c:line 2184, column 2 Attempt to free released memory. …

  • CVE-2024-26930HigMay 1, 2024
    risk 0.46cvss 7.0epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix double free of the ha->vp_map pointer Coverity scan reported potential risk of double free of the pointer ha->vp_map. ha->vp_map was freed in qla2x00_mem_alloc(), and again freed in…

  • CVE-2024-21445HigMar 12, 2024
    risk 0.46cvss 7.0epss 0.01

    Windows USB Print Driver Elevation of Privilege Vulnerability

  • CVE-2023-4389HigAug 16, 2023
    risk 0.46cvss 7.0epss 0.00

    A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may lead to leaked internal kernel…

  • CVE-2023-29368HigJun 14, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Filtering Platform Elevation of Privilege Vulnerability

  • CVE-2022-31614HigAug 5, 2022
    risk 0.46cvss 7.0epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it may double-free some resources. An attacker may exploit this vulnerability with other vulnerabilities to cause denial of service, code execution, and information disclosure.

  • CVE-2021-1119HigOct 29, 2021
    risk 0.46cvss 7.1epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can double-free a pointer, which may lead to denial of service. This flaw may result in a write-what-where condition, allowing an attacker to execute arbitrary code impacting…

  • CVE-2021-22386HigAug 10, 2021
    risk 0.46cvss 7.0epss 0.00

    A component of the Huawei smartphone has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevation of Privileges.