CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 1 of 19
- CVE-2026-33824CRITICALCVSS 9.8EG 9.8⚠ KEV2026-04-14
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
- CVE-2018-4990CRITICALCVSS 8.8EG 9.0⚠ KEV2018-07-09
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the…
- CVE-2014-0502CRITICALCVSS 8.8EG 9.0⚠ KEV2014-02-21
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.162…
- CVE-2020-6820CRITICALCVSS 8.1EG 9.0⚠ KEV2020-04-24
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and F…
- CVE-2020-9859CRITICALCVSS 7.8EG 9.0⚠ KEV2020-06-05
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbi…
- CVE-2025-62215CRITICALCVSS 7.0EG 9.0⚠ KEV2025-11-11
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2021-22600CRITICALCVSS 6.6EG 9.0⚠ KEV2022-01-26
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past …
- CVE-2018-0101CRITICALCVSS 10.0EG 10.02018-01-29
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute cod…
- CVE-2026-89078CRITICALCVSS 9.9EG 9.92026-09-23
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on t…
- CVE-2026-5759CRITICALCVSS 9.8EG 9.82026-10-09
A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.1 allows a remote attacker who can issue Redis replic…
- CVE-2026-84561CRITICALCVSS 9.8EG 9.82026-09-14
A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app …
- CVE-2026-77493CRITICALCVSS 9.8EG 9.82026-09-08
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- CVE-2026-64387CRITICALCVSS 9.8EG 9.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_directory_init()…
- CVE-2026-64386CRITICALCVSS 9.8EG 9.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_info_init() fails b…
- CVE-2026-64385CRITICALCVSS 9.8EG 9.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_ioctl_init() fails bef…
- CVE-2026-64384CRITICALCVSS 9.8EG 9.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails befo…
- CVE-2026-64383CRITICALCVSS 9.8EG 9.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay attempts. If a replayable flush response is received…
- CVE-2026-8925CRITICALCVSS 9.8EG 9.82026-07-03
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
- CVE-2026-52993CRITICALCVSS 9.8EG 9.82026-06-24
In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially reallocate the skb it is validating, freeing the old one. In tipc_buf_append(), it was be…
- CVE-2020-37239CRITICALCVSS 9.8EG 9.82026-05-16
libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_free() twice on the same pointer without…
- CVE-2026-43414CRITICALCVSS 9.8EG 9.82026-05-08
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix fcport double free In qla24xx_els_dcmd_iocb() sp->free is set to qla2x00_els_dcmd_sp_free(). When an error happens, this function is called…
- CVE-2026-43011CRITICALCVSS 9.8EG 9.82026-05-01
In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error). This error propagates back…
- CVE-2026-31609CRITICALCVSS 9.8EG 9.82026-04-24
In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush() smbd_send_batch_flush() already calls smbd_free_send_io(), so we should not call it a…
- CVE-2026-31608CRITICALCVSS 9.8EG 9.82026-04-24
In the Linux kernel, the following vulnerability has been resolved: smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list() smb_direct_flush_send_list() already calls smb_direct_free_sendmsg(), so we …
- CVE-2024-35368CRITICALCVSS 9.8EG 9.82024-11-29
FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.
- CVE-2024-11704CRITICALCVSS 9.8EG 9.82024-11-26
A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulne…
- CVE-2024-10934CRITICALCVSS 9.8EG 9.82024-11-15
In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.
- CVE-2024-27099CRITICALCVSS 9.8EG 9.82024-02-27
The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` failed state, may cause a double free problem. This may cause a RCE. Update submodule with commit 2ca42b6e4e098af2d17e48…
- CVE-2024-23809CRITICALCVSS 9.8EG 9.82024-02-20
A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vdhr file can lead to arbitrary code execution. An attacker c…
- CVE-2024-22097CRITICALCVSS 9.8EG 9.82024-02-20
A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Project libbiosig Master Branch (ab0ee111) and 2.5.0. A specially crafted .vdhr file can lead to arbitrary code execution. An attacker can pro…
- CVE-2023-49937CRITICALCVSS 9.8EG 9.82023-12-14
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a denial of service or possibly execute arbitrary code. The fixed versions are 22.05.11, 23.02.7, and 23.11.1.
- CVE-2023-45666CRITICALCVSS 9.8EG 9.82023-10-21
stb_image is a single file MIT licensed library for processing images. It may look like `stbi__load_gif_main` doesn’t give guarantees about the content of output value `*delays` upon failure. Although it sets `*delays` to zero at the be…
- CVE-2023-35784CRITICALCVSS 9.8EG 9.82023-06-16
A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
- CVE-2021-33304CRITICALCVSS 9.8EG 9.82023-02-15
Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allows attackers to execute arbitrary code.
- CVE-2022-3806CRITICALCVSS 9.8EG 9.82023-01-25
Inconsistent handling of error cases in bluetooth hci may lead to a double free condition of a network buffer.
- CVE-2022-44640CRITICALCVSS 9.8EG 9.82022-12-25
Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC).
- CVE-2022-0699CRITICALCVSS 9.8EG 9.82022-10-17
A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc.
- CVE-2022-39002CRITICALCVSS 9.8EG 9.82022-09-16
Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to be freed twice.
- CVE-2022-20127CRITICALCVSS 9.8EG 9.82022-06-15
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Produ…
- CVE-2022-28738CRITICALCVSS 9.8EG 9.82022-05-09
A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations.
- CVE-2021-23158CRITICALCVSS 9.8EG 9.82022-03-16
A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service.
- CVE-2021-37120CRITICALCVSS 9.8EG 9.82022-01-03
There is a Double free vulnerability in Smartphone.Successful exploitation of this vulnerability may cause a kernel crash or privilege escalation.
- CVE-2021-44732CRITICALCVSS 9.8EG 9.82021-12-20
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
- CVE-2020-36434CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the sys-info crate before 0.8.0 for Rust. sys_info::disk_info calls can trigger a double free.
- CVE-2021-36088CRITICALCVSS 9.8EG 9.82021-07-01
Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).
- CVE-2021-34184CRITICALCVSS 9.8EG 9.82021-06-25
Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in miniaudio.h.
- CVE-2021-31162CRITICALCVSS 9.8EG 9.82021-04-14
In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.
- CVE-2020-36318CRITICALCVSS 9.8EG 9.82021-04-11
In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use-after-free or double free.
- CVE-2021-30457CRITICALCVSS 9.8EG 9.82021-04-07
An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in remove_set upon a panic in a Drop impl.
- CVE-2021-30456CRITICALCVSS 9.8EG 9.82021-04-07
An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in get_or_insert upon a panic of a user-provided f function.
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →