CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 16 of 19
- CVE-2021-46700MEDIUMCVSS 6.5EG 6.52022-02-19
In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free.
- CVE-2021-43268MEDIUMCVSS 6.5EG 6.52021-11-24
An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to reading beyond the end of a buffer, or a double free.
- CVE-2021-34734MEDIUMCVSS 6.5EG 6.52021-08-18
A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for the Cisco Video Surveillance 7000 Series IP Cameras firmware could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. Thi…
- CVE-2021-0271MEDIUMCVSS 6.5EG 6.52021-04-22
A Double Free vulnerability in the software forwarding interface daemon (sfid) process of Juniper Networks Junos OS allows an adjacently-connected attacker to cause a Denial of Service (DoS) by sending a crafted ARP packet to the device. C…
- CVE-2020-17498MEDIUMCVSS 6.5EG 6.52020-08-13
In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.
- CVE-2019-20892MEDIUMCVSS 6.5EG 6.52020-06-25
net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect …
- CVE-2020-11017MEDIUMCVSS 6.5EG 6.52020-05-29
In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condition and crash the server. This is fixed in version 2.1.0.
- CVE-2011-1803MEDIUMCVSS 6.5EG 6.52019-11-12
An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Blink M11 and M12 when trying to access a removed smil element.
- CVE-2019-6455MEDIUMCVSS 6.5EG 6.52019-01-16
An issue was discovered in GNU Recutils 1.8. There is a double-free problem in the function rec_mset_elem_destroy() in the file rec-mset.c.
- CVE-2018-20450MEDIUMCVSS 6.5EG 6.52018-12-25
The read_MSAT function in ole.c in libxls 1.4.0 has a double free that allows attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2017-2897.
- CVE-2018-16841MEDIUMCVSS 6.5EG 6.52018-11-28
Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configured to accept smart-card authentication, Samba's KDC will call talloc_free() twice on the same memory if the principal …
- CVE-2018-14524MEDIUMCVSS 6.5EG 6.52018-07-23
dwg_decode_eed in decode.c in GNU LibreDWG before 0.6 leads to a double free (in dwg_free_eed in free.c) because it does not properly manage the obj->eed value after a free occurs.
- CVE-2018-8099MEDIUMCVSS 6.5EG 6.52018-03-14
Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an attacker to cause a denial of service via a crafted repository index file.
- CVE-2017-15186MEDIUMCVSS 6.5EG 6.52017-10-24
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
- CVE-2015-1239MEDIUMCVSS 6.5EG 6.52017-10-18
Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.
- CVE-2017-12925MEDIUMCVSS 6.5EG 6.52017-08-28
Double free vulnerability in DfFromLB in docfile.cxx in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service via a crafted fpx image.
- CVE-2015-1207MEDIUMCVSS 6.5EG 6.52017-06-06
Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
- CVE-2017-9287MEDIUMCVSS 6.5EG 6.52017-05-29
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
- CVE-2026-71338MEDIUMCVSS 6.4EG 6.42026-09-08
Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.
- CVE-2025-68657MEDIUMCVSS 6.4EG 6.42026-01-12
Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hid_host_device_close() can free the same usb_transfer_t twice. The USB event callback and user code share the hid_iface_…
- CVE-2021-37159MEDIUMCVSS 6.4EG 6.42021-07-21
hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free.
- CVE-2026-14604MEDIUMCVSS 6.3EG 6.32026-07-03
A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporter::ExportToBlob of the file code/AssetLib/Ply/PlyLoader.cpp of the component PLY Model Handler. This manipulation cause…
- CVE-2023-28411MEDIUMCVSS 6.3EG 6.32023-05-10
Double free in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.
- CVE-2019-5236MEDIUMCVSS 6.3EG 6.32019-08-08
Huawei smart phones Emily-L29C with versions of 8.1.0.132a(C432), 8.1.0.135(C782), 8.1.0.154(C10), 8.1.0.154(C461), 8.1.0.154(C635), 8.1.0.156(C185), 8.1.0.156(C605), 8.1.0.159(C636) have a double free vulnerability. An attacker can trick …
- CVE-2018-0160MEDIUMCVSS 6.3EG 6.32018-03-28
A vulnerability in Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper management of …
- CVE-2026-20532MEDIUMCVSS 6.2EG 6.22026-10-05
In apu, there is a possible application crash due to double free. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249024; Issue ID:…
- CVE-2026-13713MEDIUMCVSS 6.2EG 6.22026-07-16
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the bundled libsyck, when an anchor name is redefined or removed, syck_hdlr_add_anchor and …
- CVE-2026-31053MEDIUMCVSS 6.2EG 6.22026-04-06
A double free vulnerability exists in librz/bin/format/le/le.c in the function le_load_fixup_record(). When processing malformed or circular LE fixup chains, relocation entries may be freed multiple times during error handling. A specially…
- CVE-2025-65955MEDIUMCVSS 6.1EG 6.12025-12-02
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked wi…
- CVE-2023-21500MEDIUMCVSS 6.0EG 6.02023-05-04
Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.
- CVE-2026-107209MEDIUMCVSS 5.9EG 5.92026-10-07
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause t…
- CVE-2026-18663MEDIUMCVSS 5.9EG 5.92026-08-12
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown the…
- CVE-2026-11894MEDIUMCVSS 5.9EG 5.92026-08-11
The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-ownership contract. That contract requires the driver to consume (unref) the transmit net_buf…
- CVE-2026-11893MEDIUMCVSS 5.9EG 5.92026-08-11
The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetooth/hci/hci_bflb.c, violates the bt_hci_driver_api.send() buffer-ownership contract. That contract (documented at includ…
- CVE-2026-48850MEDIUMCVSS 5.9EG 5.92026-05-25
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
- CVE-2025-8058MEDIUMCVSS 5.9EG 5.92025-07-23
The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random mal…
- CVE-2025-2027MEDIUMCVSS 5.9EG 5.92025-03-28
A double free vulnerability has been identified in the ASUS System Analysis service. This vulnerability can be triggered by sending specially crafted local RPC requests, leading to the service crash and potentially memory manipulation in s…
- CVE-2024-3187MEDIUMCVSS 5.9EG 5.92024-10-17
This issue tracks two CWE-416 Use After Free (UAF) and one CWE-415 Double Free vulnerabilities in Goahead versions <= 6.0.0. These are caused by JST values not being nulled when freed during parsing of JST templates. If the ME_GOAHEAD_JAVA…
- CVE-2023-27537MEDIUMCVSS 5.9EG 5.92023-03-30
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact…
- CVE-2022-31117MEDIUMCVSS 5.9EG 5.92022-07-05
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0 an error occurring while reallocating a buffer for string decoding can cause the buffer to get freed twice. Due to how…
- CVE-2017-6166MEDIUMCVSS 5.9EG 5.92017-11-22
In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management Microkernel (TMM) may crash when processing fragmented packets. This vulnerability affects…
- CVE-2017-7521MEDIUMCVSS 5.9EG 5.92017-06-27
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().
- CVE-2026-46690MEDIUMCVSS 5.8EG 5.82026-05-29
unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race. At time of publication, there are no publicly availa…
- CVE-2026-20026MEDIUMCVSS 5.8EG 5.82026-01-07
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, resu…
- CVE-2026-17050MEDIUMCVSS 5.7EG 5.72026-09-21
The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c). On three failure paths — a fai…
- CVE-2026-34867MEDIUMCVSS 5.6EG 5.62026-04-13
Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-84558MEDIUMCVSS 5.5EG 5.52026-09-14
A double free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27. An app may be able to cause unexpected system termination.
- CVE-2026-45202MEDIUMCVSS 5.5EG 5.52026-08-21
Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption. Scenario caused by memory free paths not maintaining state data of upgraded higher order …
- CVE-2026-17573MEDIUMCVSS 5.5EG 5.52026-07-27
A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.
- CVE-2026-5657MEDIUMCVSS 5.5EG 5.52026-04-30
iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →