CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 13 of 19
- CVE-2022-36234HIGHCVSS 7.5EG 7.52022-07-28
SimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnerability which is exploited via crafted TCP packets.
- CVE-2021-41688HIGHCVSS 7.5EG 7.52022-06-28
DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still used in other locations. Sending specific requests to the dcmqrdb program will incur a double free. An attacker can use it…
- CVE-2022-31291HIGHCVSS 7.5EG 7.52022-06-16
An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.
- CVE-2020-14123HIGHCVSS 7.5EG 7.52022-04-22
There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operatio…
- CVE-2021-4091HIGHCVSS 7.5EG 7.52022-02-18
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.
- CVE-2022-23012HIGHCVSS 7.5EG 7.52022-01-25
On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions …
- CVE-2021-40038HIGHCVSS 7.5EG 7.52022-01-10
There is a Double free vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.
- CVE-2021-37072HIGHCVSS 7.5EG 7.52021-12-07
There is a Incorrect Calculation of Buffer Size vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to memory crash.
- CVE-2021-40873HIGHCVSS 7.5EG 7.52021-11-10
An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server proc…
- CVE-2021-40145HIGHCVSS 7.5EG 7.52021-08-26
gdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2 image format is a proprietary image format of libgd. It has to be regarded as being obsolete, and sho…
- CVE-2021-31996HIGHCVSS 7.5EG 7.52021-05-03
An issue was discovered in the algorithmica crate through 2021-03-07 for Rust. There is a double free in merge_sort::merge().
- CVE-2021-22332HIGHCVSS 7.5EG 7.52021-04-28
There is a pointer double free vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 and CloudEngine 12800. When a function is called, the same memory pointer is copied to two functional modules. Attackers …
- CVE-2021-29938HIGHCVSS 7.5EG 7.52021-04-01
An issue was discovered in the slice-deque crate through 2021-02-19 for Rust. A double drop can occur in SliceDeque::drain_filter upon a panic in a predicate function.
- CVE-2021-29933HIGHCVSS 7.5EG 7.52021-04-01
An issue was discovered in the insert_many crate through 2021-01-26 for Rust. Elements may be dropped twice if a .next() method panics.
- CVE-2021-29931HIGHCVSS 7.5EG 7.52021-04-01
An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A double drop can sometimes occur upon a panic in T::drop().
- CVE-2021-29929HIGHCVSS 7.5EG 7.52021-04-01
An issue was discovered in the endian_trait crate through 2021-01-04 for Rust. A double drop can occur when a user-provided Endian impl panics.
- CVE-2021-25908HIGHCVSS 7.5EG 7.52021-01-26
An issue was discovered in the fil-ocl crate through 2021-01-04 for Rust. From<EventList> can lead to a double free.
- CVE-2020-36225HIGHCVSS 7.5EG 7.52021-01-26
A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service.
- CVE-2020-36223HIGHCVSS 7.5EG 7.52021-01-26
A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read).
- CVE-2020-3685HIGHCVSS 7.5EG 7.52021-01-21
Pointer variable which is freed is not cleared can result in memory corruption and leads to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon I…
- CVE-2020-35891HIGHCVSS 7.5EG 7.52020-12-31
An issue was discovered in the ordnung crate through 2020-09-03 for Rust. compact::Vec violates memory safety via a remove() double free.
- CVE-2020-1686HIGHCVSS 7.5EG 7.52020-10-16
On Juniper Networks Junos OS devices, receipt of a malformed IPv6 packet may cause the system to crash and restart (vmcore). This issue can be trigged by a malformed IPv6 packet destined to the Routing Engine. An attacker can repeatedly se…
- CVE-2020-9844HIGHCVSS 7.5EG 7.52020-06-09
A double free issue was addressed with improved memory management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
- CVE-2020-3179HIGHCVSS 7.5EG 7.52020-05-06
A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an aff…
- CVE-2019-19943HIGHCVSS 7.5EG 7.52020-02-28
The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double fre…
- CVE-2020-1829HIGHCVSS 7.5EG 7.52020-02-17
Huawei NIP6800 versions V500R001C30 and V500R001C60SPC500; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, and V500R001C60SPC500 have a vulnerability that the IPSec module handles a message improperly. Atta…
- CVE-2011-2335HIGHCVSS 7.5EG 7.52019-11-12
A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function.
- CVE-2019-18874HIGHCVSS 7.5EG 7.52019-11-12
psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object.
- CVE-2017-18594HIGHCVSS 7.5EG 7.52019-08-29
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.
- CVE-2016-9969HIGHCVSS 7.5EG 7.52019-05-23
In libwebp 0.5.1, there is a double free bug in libwebpmux.
- CVE-2018-14638HIGHCVSS 7.5EG 7.52018-09-14
A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service.
- CVE-2018-6952HIGHCVSS 7.5EG 7.52018-02-13
A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.
- CVE-2015-5177HIGHCVSS 7.5EG 7.52017-10-22
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.
- CVE-2017-6362HIGHCVSS 7.5EG 7.52017-09-07
Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.
- CVE-2017-5836HIGHCVSS 7.5EG 7.52017-03-03
The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is treated as a PLIST_KEY and then triggers an invalid free.
- CVE-2005-0891HIGHCVSS 7.5EG 7.52005-05-02
Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.
- CVE-2021-34981HIGHCVSS 6.7EG 7.52024-05-07
Linux Kernel Bluetooth CMTP Module Double Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to exe…
- CVE-2024-3935HIGHCVSS 6.5EG 7.52024-10-30
In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that makes use of topic remapping, then if th…
- CVE-2014-1252HIGHCVSS v2 7.5EG 7.52014-01-24
Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.
- CVE-2011-3892HIGHCVSS v2 7.5EG 7.52011-11-11
Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
- CVE-2011-2821HIGHCVSS v2 7.5EG 7.52011-08-29
Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
- CVE-2010-4494HIGHCVSS v2 7.5EG 7.52010-12-07
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors relat…
- CVE-2004-0642HIGHCVSS v2 7.5EG 7.52004-09-28
Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary c…
- CVE-2003-0015HIGHCVSS v2 7.5EG 7.52003-02-07
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-pro…
- CVE-2025-49690HIGHCVSS 7.4EG 7.42025-07-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.
- CVE-2025-21183HIGHCVSS 7.4EG 7.42025-02-11
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
- CVE-2025-21182HIGHCVSS 7.4EG 7.42025-02-11
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
- CVE-2024-44098HIGHCVSS 7.4EG 7.42024-10-25
In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n…
- CVE-2018-0102HIGHCVSS 7.4EG 7.42018-01-18
A vulnerability in the Pong tool of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the affe…
- CVE-2026-64621HIGHCVSS 7.3EG 7.32026-07-20
FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorId…
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →