VYPR

CWE-415

Double Free

VariantDraftLikelihood: High

Description

The product calls free() twice on the same memory address.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (886)

page 8 of 45
  • CVE-2019-17545CriOct 14, 2019
    risk 0.57cvss 9.8epss 0.03

    GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.

  • CVE-2019-11932HigOct 3, 2019
    risk 0.57cvss 8.8epss 0.45

    A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause…

  • CVE-2019-5481CriSep 16, 2019
    risk 0.57cvss 9.8epss 0.07

    Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

  • CVE-2019-15551CriAug 26, 2019
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts with the current capacity.

  • CVE-2019-15151CriAug 18, 2019
    risk 0.57cvss 9.8epss 0.02

    AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.

  • CVE-2019-12219HigMay 20, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an invalid free error in the SDL function SDL_SetError_REAL at SDL_error.c.

  • CVE-2019-6978CriJan 28, 2019
    risk 0.57cvss 9.8epss 0.04

    The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.

  • CVE-2018-11982HigSep 20, 2018
    risk 0.57cvss 8.8epss 0.00

    In Snapdragon (Mobile, Wear) in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SD 820, SD 835,…

  • CVE-2018-17097HigSep 16, 2018
    risk 0.57cvss 8.8epss 0.03

    The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (double free) or possibly have unspecified other impact, as demonstrated by SoundStretch.

  • CVE-2018-1000216HigAug 20, 2018
    risk 0.57cvss 8.8epss 0.01

    Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, depending on how cJSON library…

  • CVE-2018-14054CriJul 13, 2018
    risk 0.57cvss 9.8epss 0.03

    A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0. A dangling pointer is freed again in the destructor once an exception is triggered.

  • CVE-2018-11416HigMay 24, 2018
    risk 0.57cvss 8.8epss 0.02

    jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

  • CVE-2018-3845HigApr 26, 2018
    risk 0.57cvss 8.8epss 0.03

    In Hyland Perceptive Document Filters 11.4.0.2647 - x86/x64 Windows/Linux, a crafted OpenDocument document can lead to a SkCanvas object double free resulting in direct code execution.

  • CVE-2017-7393HigApr 1, 2017
    risk 0.57cvss 8.8epss 0.02

    In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.

  • CVE-2026-20135HigSep 16, 2026
    risk 0.56cvss 8.6epss 0.00

    A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due…

  • CVE-2025-20134HigAug 14, 2025
    risk 0.56cvss 8.6epss 0.00

    A vulnerability in the certificate processing of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a…

  • CVE-2024-20498HigOct 2, 2024
    risk 0.56cvss 8.6epss 0.01

    Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. These vulnerabilities…

  • CVE-2022-20803HigFeb 17, 2023
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.The vulnerability is due to incorrect use of the realloc function that…

  • CVE-2021-34769HigSep 23, 2021
    risk 0.56cvss 8.6epss 0.01

    Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS)…

  • CVE-2021-34768HigSep 23, 2021
    risk 0.56cvss 8.6epss 0.01

    Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS)…