VYPR

CWE-415

Double Free

VariantDraftLikelihood: High

Description

The product calls free() twice on the same memory address.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (886)

page 41 of 45
  • CVE-2026-82677LowAug 31, 2026
    risk 0.09cvss 2.4epss 0.01

    A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly…

  • CVE-2026-44348LowMay 14, 2026
    risk 0.09cvss 2.5epss 0.00

    PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFinal fails after buf has already been freed, the Error label frees buf a second…

  • CVE-2003-0015Feb 7, 2003
    risk 0.05cvss —epss 0.24

    Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.

  • CVE-2014-1767Jul 8, 2014
    risk 0.04cvss —epss 0.13

    Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows…

  • CVE-2015-0058Feb 11, 2015
    risk 0.03cvss —epss 0.03

    Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a crafted application, aka "Windows Cursor Object Double Free Vulnerability."

  • CVE-2022-40304HigNov 23, 2022
    risk 0.01cvss 7.8epss 0.06

    An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.

  • CVE-2018-20961CriAug 7, 2019
    risk 0.01cvss 9.8epss 0.06

    In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of service or possibly have unspecified other impact.

  • CVE-2015-0312Jan 28, 2015
    risk 0.01cvss —epss 0.07

    Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.0.296 on Windows and OS X and before 11.2.202.440 on Linux allows attackers to execute arbitrary code via unspecified vectors.

  • CVE-2014-0301Mar 12, 2014
    risk 0.01cvss —epss 0.14

    Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute…

  • CVE-2010-4494Dec 7, 2010
    risk 0.01cvss —epss 0.06

    Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

  • CVE-2007-1216Apr 6, 2007
    risk 0.01cvss —epss 0.10

    Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows remote authenticated users to…

  • CVE-2004-0643Sep 28, 2004
    risk 0.01cvss —epss 0.09

    Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.

  • CVE-2004-0642Sep 28, 2004
    risk 0.01cvss —epss 0.08

    Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.

  • CVE-2026-55132HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.01

    Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-50685HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.

  • CVE-2026-50361HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55004HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

  • CVE-2026-43706MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to…

  • CVE-2025-68657MedJan 12, 2026
    risk 0.00cvss 6.4epss 0.00

    Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hid_host_device_close() can free the same usb_transfer_t twice. The USB event callback and user code share the hid_iface_t state without locking, so both can…

  • CVE-2025-55158HigAug 11, 2025
    risk 0.00cvss 8.8epss 0.00

    Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tuples during Vim9 script import operations, an error during evaluation can trigger a double-free in Vim’s internal typed value (typval_T) management.…