VYPR

CWE-415

Double Free

VariantDraftLikelihood: High

Description

The product calls free() twice on the same memory address.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (886)

page 27 of 45
  • CVE-2026-61366HigAug 11, 2026
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.

  • CVE-2026-34341HigMay 12, 2026
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-32219HigApr 14, 2026
    risk 0.46cvss 7.0epss 0.00

    Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26166HigApr 14, 2026
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20863HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

  • CVE-2025-20801HigJan 6, 2026
    risk 0.46cvss 7.0epss 0.00

    In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10251210; Issue ID: MSV-4926.

  • CVE-2025-62469HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62219HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59289HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-23282HigOct 10, 2025
    risk 0.46cvss 7.0epss 0.00

    NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and…

  • CVE-2025-47975HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

  • CVE-2022-49789HigMay 1, 2025
    risk 0.46cvss 7.0epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: scsi: zfcp: Fix double free of FSF request when qdio send fails We used to use the wrong type of integer in 'zfcp_fsf_req_send()' to cache the FSF request ID when sending a new FSF request. This is used in…

  • CVE-2025-26640HigApr 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2024-49095HigDec 12, 2024
    risk 0.46cvss 7.0epss 0.00

    Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

  • CVE-2024-50159HigNov 7, 2024
    risk 0.46cvss 7.0epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix the double free in scmi_debugfs_common_setup() Clang static checker(scan-build) throws below warning: | drivers/firmware/arm_scmi/driver.c:line 2915, column 2 | Attempt to…

  • CVE-2024-38157HigAug 13, 2024
    risk 0.46cvss 7.0epss 0.00

    Azure IoT SDK Remote Code Execution Vulnerability

  • CVE-2024-42123HigJul 30, 2024
    risk 0.46cvss 7.0epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix double free err_addr pointer warnings In amdgpu_umc_bad_page_polling_timeout, the amdgpu_umc_handle_bad_pages will be run many times so that double free err_addr in some special case. So set…

  • CVE-2024-36030HigMay 30, 2024
    risk 0.46cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix the double free in rvu_npc_freemem() Clang static checker(scan-build) warning: drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c:line 2184, column 2 Attempt to free released memory. …

  • CVE-2024-26930HigMay 1, 2024
    risk 0.46cvss 7.0epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix double free of the ha->vp_map pointer Coverity scan reported potential risk of double free of the pointer ha->vp_map. ha->vp_map was freed in qla2x00_mem_alloc(), and again freed in…

  • CVE-2024-21445HigMar 12, 2024
    risk 0.46cvss 7.0epss 0.01

    Windows USB Print Driver Elevation of Privilege Vulnerability