VYPR

CWE-415

Double Free

VariantDraftLikelihood: High

Description

The product calls free() twice on the same memory address.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (886)

page 39 of 45
  • CVE-2026-6654MedApr 20, 2026
    risk 0.33cvss 5.1epss 0.00

    Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.

  • CVE-2026-31053MedApr 6, 2026
    risk 0.33cvss 6.2epss 0.00

    A double free vulnerability exists in librz/bin/format/le/le.c in the function le_load_fixup_record(). When processing malformed or circular LE fixup chains, relocation entries may be freed multiple times during error handling. A specially crafted LE binary can trigger heap…

  • CVE-2026-23868MedMar 10, 2026
    risk 0.33cvss 5.1epss 0.00

    Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.

  • CVE-2026-28537MedMar 5, 2026
    risk 0.33cvss 5.1epss 0.00

    Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-61145MedFeb 23, 2026
    risk 0.33cvss 5.0epss 0.00

    libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.

  • CVE-2024-53698MedMar 7, 2025
    risk 0.32cvss 4.9epss 0.00

    A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify memory. We have already fixed the vulnerability in the following versions:…

  • CVE-2022-31117MedJul 5, 2022
    risk 0.32cvss 5.9epss 0.02

    UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0 an error occurring while reallocating a buffer for string decoding can cause the buffer to get freed twice. Due to how UltraJSON uses the internal decoder,…

  • CVE-2026-11894MedAug 11, 2026
    risk 0.31cvss 5.9epss 0.00

    The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-ownership contract. That contract requires the driver to consume (unref) the transmit net_buf only on success; on an error return the…

  • CVE-2026-11893MedAug 11, 2026
    risk 0.31cvss 5.9epss 0.00

    The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetooth/hci/hci_bflb.c, violates the bt_hci_driver_api.send() buffer-ownership contract. That contract (documented at include/zephyr/drivers/bluetooth.h) requires…

  • CVE-2025-8058MedJul 23, 2025
    risk 0.31cvss —epss 0.00

    The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random malloc failures. The double free can allow…

  • CVE-2023-52384MedMay 14, 2024
    risk 0.31cvss 4.7epss 0.00

    Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52383MedMay 14, 2024
    risk 0.31cvss 4.7epss 0.00

    Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-1032MedJan 8, 2024
    risk 0.31cvss 4.7epss 0.00

    The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15c7691e9b13cbe9bf6c65c365350e056067.

  • CVE-2023-41911MedSep 28, 2023
    risk 0.31cvss 4.7epss 0.00

    Samsung Mobile Processor Exynos 2200 allows a GPU Double Free (issue 1 of 2).

  • CVE-2026-5657MedApr 30, 2026
    risk 0.29cvss 5.5epss 0.00

    iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

  • CVE-2024-26846MedApr 17, 2024
    risk 0.29cvss 4.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: nvme-fc: do not wait in vain when unloading module The module exit path has race between deleting all controllers and freeing 'left over IDs'. To prevent double free a synchronization between nvme_delete_ctrl…

  • CVE-2021-25477MedOct 6, 2021
    risk 0.29cvss 4.4epss 0.01

    An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote denial of service.

  • CVE-2015-8894MedMar 15, 2017
    risk 0.29cvss 5.5epss 0.01

    Double free vulnerability in coders/tga.c in ImageMagick 7.0.0 and later allows remote attackers to cause a denial of service (application crash) via a crafted tga file.

  • CVE-2026-55653MedJun 23, 2026
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes…

  • CVE-2021-26954MedFeb 9, 2021
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in the qwutils crate before 0.3.1 for Rust. When a Clone panic occurs, insert_slice_clone can perform a double drop.