VYPR

CWE-415

Double Free

VariantDraftLikelihood: High

Description

The product calls free() twice on the same memory address.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (886)

page 9 of 45
  • CVE-2021-1565HigSep 23, 2021
    risk 0.56cvss 8.6epss 0.01

    Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS)…

  • CVE-2025-39790HigSep 11, 2025
    risk 0.55cvss 8.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Detect events pointing to unexpected TREs When a remote device sends a completion event to the host, it contains a pointer to the consumed TRE. The host uses this pointer to process all of the…

  • CVE-2024-56704HigDec 28, 2024
    risk 0.55cvss 8.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: 9p/xen: fix release of IRQ Kernel logs indicate an IRQ was double-freed. Pass correct device ID during IRQ release. [Dominique: remove confusing variable reset to 0]

  • CVE-2024-47404HigNov 5, 2024
    risk 0.55cvss 8.4epss 0.00

    in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.

  • CVE-2024-21461HigJul 1, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while performing finish HMAC operation when context is freed by keymaster.

  • CVE-2024-36973HigJun 17, 2024
    risk 0.55cvss 8.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe() When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), callback function…

  • CVE-2022-40522HigJun 6, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Linux Networking due to double free while handling a hyp-assign.

  • CVE-2022-40507HigJun 6, 2023
    risk 0.55cvss 8.4epss 0.01

    Memory corruption due to double free in Core while mapping HLOS address to the list.

  • CVE-2022-33307HigJun 6, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed.

  • CVE-2022-25750HigOct 19, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in BTHOST due to double free while music playback and calls over bluetooth headset in Snapdragon Mobile

  • CVE-2021-1934HigSep 9, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible memory corruption due to improper check when application loader object is explicitly destructed while application is unloading in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT

  • CVE-2021-1888HigJul 13, 2021
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2020-11246HigApr 7, 2021
    risk 0.55cvss 8.4epss 0.00

    A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2023-33137HigJun 14, 2023
    risk 0.54cvss 7.8epss 0.03

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2020-11900HigJun 17, 2020
    risk 0.54cvss 8.2epss 0.13

    The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free.

  • CVE-2019-1999HigFeb 28, 2019
    risk 0.54cvss 7.8epss 0.01

    In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android.…

  • CVE-2017-6074HigFeb 18, 2017
    risk 0.54cvss 7.8epss 0.06

    The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application…

  • CVE-2026-85921HigSep 14, 2026
    risk 0.53cvss 8.2epss 0.00

    Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

  • CVE-2026-72958HigSep 8, 2026
    risk 0.53cvss 8.2epss 0.00

    Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55007HigSep 8, 2026
    risk 0.53cvss 8.1epss 0.01

    Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.