VYPR

CWE-415

Double Free

VariantDraftLikelihood: High

Description

The product calls free() twice on the same memory address.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (835)

page 41 of 42
  • CVE-2021-40571HigJan 13, 2022
    risk 0.00cvss 7.8epss 0.01

    The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

  • CVE-2021-40570HigJan 13, 2022
    risk 0.00cvss 7.8epss 0.01

    The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avc_compute_poc function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.

  • CVE-2021-40569MedJan 13, 2022
    risk 0.00cvss 5.5epss 0.01

    The binary MP4Box in Gpac through 1.0.1 has a double-free vulnerability in the iloc_entry_del funciton in box_code_meta.c, which allows attackers to cause a denial of service.

  • CVE-2021-40145HigAug 26, 2021
    risk 0.00cvss 7.5epss 0.02

    gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete, and should only be used for development and…

  • CVE-2021-37159MedJul 21, 2021
    risk 0.00cvss 6.4epss 0.00

    hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.

  • CVE-2021-36088CriJul 1, 2021
    risk 0.00cvss 9.8epss 0.02

    Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).

  • CVE-2021-36080HigJul 1, 2021
    risk 0.00cvss 8.8epss 0.01

    GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_encode_add_object).

  • CVE-2021-32613MedMay 14, 2021
    risk 0.00cvss 5.5epss 0.01

    In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.

  • CVE-2020-14354LowMay 13, 2021
    risk 0.00cvss 3.3epss 0.01

    A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. This flaw possibly allows an attacker to crash the service that uses c-ares lib. The highest threat from this vulnerability is to this…

  • CVE-2021-3492HigApr 17, 2021
    risk 0.00cvss 8.8epss 0.02

    Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a…

  • CVE-2021-31162CriApr 14, 2021
    risk 0.00cvss 9.8epss 0.03

    In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.

  • CVE-2021-28041HigMar 5, 2021
    risk 0.00cvss 7.1epss 0.03

    ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

  • CVE-2021-25902HigJan 26, 2021
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the glsl-layout crate before 0.4.0 for Rust. When a panic occurs, map_array can perform a double drop.

  • CVE-2020-11044LowMay 7, 2020
    risk 0.00cvss 2.2epss 0.02

    In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0.

  • CVE-2017-18595HigSep 4, 2019
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in the Linux kernel before 4.14.11. A double free may be caused by the function allocate_trace_buffer in the file kernel/trace/trace.c.

  • CVE-2017-18594HigAug 29, 2019
    risk 0.00cvss 7.5epss 0.03

    nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.

  • CVE-2019-15212MedAug 19, 2019
    risk 0.00cvss 4.6epss 0.01

    An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c driver.

  • CVE-2019-1020014MedJul 29, 2019
    risk 0.00cvss 5.5epss 0.00

    docker-credential-helpers before 0.6.3 has a double free in the List functions.

  • CVE-2018-1000877HigDec 20, 2018
    risk 0.00cvss 8.8epss 0.05

    libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0…

  • CVE-2018-16425MedSep 4, 2018
    risk 0.00cvss 6.6epss 0.01

    A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-hsm.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified…