CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 14 of 19
- CVE-2026-58381HIGHCVSS 7.3EG 7.32026-07-02
A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading…
- CVE-2021-1910HIGHCVSS 7.3EG 7.32021-05-07
Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wear…
- CVE-2015-8962HIGHCVSS 7.3EG 7.32016-11-16
Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (memory corruption and system crash) by detaching a device dur…
- CVE-2010-3957HIGHCVSS 7.3EG 7.32010-12-16
Double free vulnerability in the OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges…
- CVE-2024-27127HIGHCVSS 7.2EG 7.22024-05-21
A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute arbitrary code via a network. We have already fixed the vulnerabi…
- CVE-2023-27320HIGHCVSS 7.2EG 7.22023-02-28
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
- CVE-2015-0058HIGHCVSS v2 7.2EG 7.22015-02-11
Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a crafted application, aka "Windows Cursor Object Double Free…
- CVE-2014-1767HIGHCVSS v2 7.2EG 7.22014-07-08
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wind…
- CVE-2010-3080HIGHCVSS v2 7.2EG 7.22010-09-21
Double free vulnerability in the snd_seq_oss_open function in sound/core/seq/oss/seq_oss_init.c in the Linux kernel before 2.6.36-rc4 might allow local users to cause a denial of service or possibly have unspecified other impact via an uns…
- CVE-2026-61915HIGHCVSS 7.1EG 7.12026-09-09
An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or …
- CVE-2026-69337HIGHCVSS 7.1EG 7.12026-09-08
Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.
- CVE-2024-36030HIGHCVSS 7.1EG 7.12024-05-30
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix the double free in rvu_npc_freemem() Clang static checker(scan-build) warning: drivers/net/ethernet/marvell/octeontx2/af/rvu_npc.c:line 2184, column …
- CVE-2023-4389HIGHCVSS 7.1EG 7.12023-08-16
A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may…
- CVE-2021-1119HIGHCVSS 7.1EG 7.12021-10-29
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can double-free a pointer, which may lead to denial of service. This flaw may result in a write-what-where condition, allowing an attacker to …
- CVE-2021-28041HIGHCVSS 7.1EG 7.12021-03-05
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
- CVE-2020-5988HIGHCVSS 7.1EG 7.12020-10-02
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which allocated memory can be freed twice, which may lead to information disclosure or denial of service. This affects vGPU version 8.x (prior to 8.5), version 10.x…
- CVE-2019-0122HIGHCVSS 7.1EG 7.12019-03-14
Double free in Intel(R) SGX SDK for Linux before version 2.2 and Intel(R) SGX SDK for Windows before version 2.1 may allow an authenticated user to potentially enable information disclosure or denial of service via local access.
- CVE-2026-57842HIGHCVSS 7.0EG 7.02026-09-11
NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execu…
- CVE-2026-69309HIGHCVSS 7.0EG 7.02026-09-08
Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
- CVE-2026-70567HIGHCVSS 7.0EG 7.02026-09-08
Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69398HIGHCVSS 7.0EG 7.02026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-71351HIGHCVSS 7.0EG 7.02026-09-08
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-71353HIGHCVSS 7.0EG 7.02026-09-08
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-70562HIGHCVSS 7.0EG 7.02026-09-08
Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69292HIGHCVSS 7.0EG 7.02026-09-08
Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-65780HIGHCVSS 7.0EG 7.02026-08-11
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
- CVE-2026-62766HIGHCVSS 7.0EG 7.02026-08-11
Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
- CVE-2026-61366HIGHCVSS 7.0EG 7.02026-08-11
Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
- CVE-2026-64222HIGHCVSS 7.0EG 7.02026-07-24
In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack on AQ init failure otx2_pool_aq_init() frees pool->stack when mailbox sync or retry allocation fails, but leaves the point…
- CVE-2026-46164HIGHCVSS 7.0EG 7.02026-05-28
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free in create_space_info_sub_group() error path When kobject_init_and_add() fails, the call chain is: create_space_info_sub_group() -> btrfs_sysfs_ad…
- CVE-2026-34341HIGHCVSS 7.0EG 7.02026-05-12
Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
- CVE-2026-32219HIGHCVSS 7.0EG 7.02026-04-14
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-26166HIGHCVSS 7.0EG 7.02026-04-14
Double free in Windows Shell allows an authorized attacker to elevate privileges locally.
- CVE-2026-20863HIGHCVSS 7.0EG 7.02026-01-13
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
- CVE-2025-20801HIGHCVSS 7.0EG 7.02026-01-06
In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Pat…
- CVE-2025-62469HIGHCVSS 7.0EG 7.02025-12-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- CVE-2025-62219HIGHCVSS 7.0EG 7.02025-11-11
Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.
- CVE-2025-59289HIGHCVSS 7.0EG 7.02025-10-14
Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-23282HIGHCVSS 7.0EG 7.02025-10-10
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, dat…
- CVE-2025-47975HIGHCVSS 7.0EG 7.02025-07-08
Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-37915HIGHCVSS 7.0EG 7.02025-05-20
In the Linux kernel, the following vulnerability has been resolved: net_sched: drr: Fix double list add in class with netem as child qdisc As described in Gerrard's report [1], there are use cases where a netem child qdisc will make the …
- CVE-2025-26640HIGHCVSS 7.0EG 7.02025-04-08
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
- CVE-2024-49095HIGHCVSS 7.0EG 7.02024-12-12
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
- CVE-2024-38157HIGHCVSS 7.0EG 7.02024-08-13
Azure IoT SDK Remote Code Execution Vulnerability
- CVE-2024-21445HIGHCVSS 7.0EG 7.02024-03-12
Windows USB Print Driver Elevation of Privilege Vulnerability
- CVE-2023-29368HIGHCVSS 7.0EG 7.02023-06-14
Windows Filtering Platform Elevation of Privilege Vulnerability
- CVE-2022-31614HIGHCVSS 7.0EG 7.02022-08-05
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it may double-free some resources. An attacker may exploit this vulnerability with other vulnerabilities to cause denial of service, code executio…
- CVE-2021-22386HIGHCVSS 7.0EG 7.02021-08-10
A component of the Huawei smartphone has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevation of Privileges.
- CVE-2017-15856HIGHCVSS 7.0EG 7.02018-07-06
Due to a race condition while processing the power stats debug file to read status, a double free condition can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security pa…
- CVE-2017-15843HIGHCVSS 7.0EG 7.02018-06-12
Due to a race condition in a bus driver, a double free in msm_bus_floor_vote_context() can potentially occur in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →