CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 15 of 19
- CVE-2017-10950HIGHCVSS 7.0EG 7.02017-08-29
This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Bitdefender Total Security 21.0.24.62. An attacker must first obtain the ability to execute low-privileged code on the target system in orde…
- CVE-2017-8265HIGHCVSS 7.0EG 7.02017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a video driver which can lead to a double free.
- CVE-2026-11388MEDIUMCVSS 6.9EG 6.92026-09-22
Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.1.0 before 7.3.1.6.
- CVE-2026-82325MEDIUMCVSS 6.8EG 6.82026-09-07
A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages
- CVE-2026-56109MEDIUMCVSS 6.8EG 6.82026-06-22
The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When p…
- CVE-2023-21629MEDIUMCVSS 6.8EG 6.82023-07-04
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
- CVE-2022-32962MEDIUMCVSS 6.8EG 6.82022-07-20
HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate servi…
- CVE-2019-20792MEDIUMCVSS 6.8EG 6.82020-04-29
OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.
- CVE-2018-0469MEDIUMCVSS 6.8EG 6.82018-10-05
A vulnerability in the web user interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a double-free-in-memory handling by the affected software…
- CVE-2021-3407MEDIUMCVSS 5.5EG 6.82021-02-23
A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
- CVE-2011-2834MEDIUMCVSS v2 6.8EG 6.82011-09-19
Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
- CVE-2026-20510MEDIUMCVSS 6.7EG 6.72026-09-07
In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for explo…
- CVE-2026-32170MEDIUMCVSS 6.7EG 6.72026-05-12
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
- CVE-2026-21530MEDIUMCVSS 6.7EG 6.72026-05-12
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
- CVE-2025-20786MEDIUMCVSS 6.7EG 6.72026-01-06
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patc…
- CVE-2025-20775MEDIUMCVSS 6.7EG 6.72025-12-02
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patc…
- CVE-2025-20773MEDIUMCVSS 6.7EG 6.72025-12-02
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patc…
- CVE-2025-20772MEDIUMCVSS 6.7EG 6.72025-12-02
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patc…
- CVE-2024-23379MEDIUMCVSS 6.7EG 6.72024-10-07
Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
- CVE-2023-28583MEDIUMCVSS 6.7EG 6.72024-01-02
Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 address.
- CVE-2023-32824MEDIUMCVSS 6.7EG 6.72023-10-02
In rpmb , there is a possible double free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07912966; Issue ID:…
- CVE-2023-41325MEDIUMCVSS 6.7EG 6.72023-09-15
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20 and prior to version 3.22, `shdr_verify_signature` c…
- CVE-2023-33952MEDIUMCVSS 6.7EG 6.72023-07-24
A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on…
- CVE-2022-33227MEDIUMCVSS 6.7EG 6.72023-06-06
Memory corruption in Linux android due to double free while calling unregister provider after register call.
- CVE-2022-32614MEDIUMCVSS 6.7EG 6.72022-11-08
In audio, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07310571; Issue …
- CVE-2022-21758MEDIUMCVSS 6.7EG 6.72022-06-06
In ccu, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06439600; Issue ID…
- CVE-2021-39725MEDIUMCVSS 6.7EG 6.72022-03-16
In gasket_free_coherent_memory_all of gasket_page_table.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed…
- CVE-2020-11231MEDIUMCVSS 6.7EG 6.72021-04-07
Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in turn can lead to heap corruption in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Indu…
- CVE-2020-0483MEDIUMCVSS 6.7EG 6.72020-12-15
In DrmManagerService::~DrmManagerService() of DrmManagerService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction …
- CVE-2020-25637MEDIUMCVSS 6.7EG 6.72020-10-06
A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Speci…
- CVE-2023-45584MEDIUMCVSS 6.6EG 6.62025-08-12
A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 thro…
- CVE-2023-44247MEDIUMCVSS 6.6EG 6.62024-05-14
A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.
- CVE-2018-16425MEDIUMCVSS 6.6EG 6.62018-09-04
A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-hsm.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (applicat…
- CVE-2018-16424MEDIUMCVSS 6.6EG 6.62018-09-04
A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or pos…
- CVE-2018-16423MEDIUMCVSS 6.6EG 6.62018-09-04
A double free when handling responses from a smartcard in sc_file_set_sec_attr in libopensc/sc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or p…
- CVE-2026-63652MEDIUMCVSS 6.5EG 6.52026-08-19
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the…
- CVE-2026-43706MEDIUMCVSS 6.5EG 6.52026-06-29
A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing malic…
- CVE-2026-55653MEDIUMCVSS 6.5EG 6.52026-06-23
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group vali…
- CVE-2025-57785MEDIUMCVSS 6.5EG 6.52026-01-26
A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to corrupt data which may lead to arbitrary code execution.
- CVE-2025-5351MEDIUMCVSS 6.5EG 6.52025-07-04
A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared…
- CVE-2025-23096MEDIUMCVSS 6.5EG 6.52025-06-04
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile processor leads to privilege escalation.
- CVE-2025-23095MEDIUMCVSS 6.5EG 6.52025-06-04
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile processor leads to privilege escalation.
- CVE-2025-4574MEDIUMCVSS 6.5EG 6.52025-05-13
In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.
- CVE-2025-31235MEDIUMCVSS 6.5EG 6.52025-05-12
A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able to cause unexpected system termination.
- CVE-2023-43281MEDIUMCVSS 6.5EG 6.52023-10-25
Double Free vulnerability in Nothings Stb Image.h v.2.28 allows a remote attacker to cause a denial of service via a crafted file to the stbi_load_gif_main function.
- CVE-2023-37365MEDIUMCVSS 6.5EG 6.52023-06-30
Hnswlib 0.7.0 has a double free in init_index when the M argument is a large integer.
- CVE-2023-29469MEDIUMCVSS 6.5EG 6.52023-04-24
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double…
- CVE-2021-39432MEDIUMCVSS 6.5EG 6.52022-11-04
diplib v3.0.0 is vulnerable to Double Free.
- CVE-2022-32574MEDIUMCVSS 6.5EG 6.52022-10-25
A double-free vulnerability exists in the web interface /action/ipcamSetParamPost functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to memory corruption. An attacker …
- CVE-2022-2519MEDIUMCVSS 6.5EG 6.52022-08-31
There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →