CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 18 of 19
- CVE-2015-5203MEDIUMCVSS 5.5EG 5.52017-08-02
Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
- CVE-2014-9807MEDIUMCVSS 5.5EG 5.52017-03-30
The pdb coder in ImageMagick allows remote attackers to cause a denial of service (double free) via unspecified vectors.
- CVE-2015-8894MEDIUMCVSS 5.5EG 5.52017-03-15
Double free vulnerability in coders/tga.c in ImageMagick 7.0.0 and later allows remote attackers to cause a denial of service (application crash) via a crafted tga file.
- CVE-2017-6353MEDIUMCVSS 5.5EG 5.52017-03-01
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multit…
- CVE-2024-42123MEDIUMCVSS 4.4EG 5.52024-07-30
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix double free err_addr pointer warnings In amdgpu_umc_bad_page_polling_timeout, the amdgpu_umc_handle_bad_pages will be run many times so that double free …
- CVE-2022-3595MEDIUMCVSS 3.5EG 5.52022-10-18
A vulnerability was found in Linux Kernel. It has been rated as problematic. Affected by this issue is the function sess_free_buffer of the file fs/cifs/sess.c of the component CIFS Handler. The manipulation leads to double free. It is rec…
- CVE-2026-104113MEDIUMCVSS 5.4EG 5.42026-10-09
A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/…
- CVE-2026-5186MEDIUMCVSS 5.3EG 5.32026-03-31
A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb_image.h of the component Multi-frame GIF File Handler. This manipulation causes double free. The attack requires local…
- CVE-2026-33995MEDIUMCVSS 5.3EG 5.32026-03-30
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a double-free vulnerability in kerberos_AcceptSecurityContext() and kerberos_InitializeSecurityContextA() (WinPR, winpr/libwinpr/sspi/Kerberos/kerber…
- CVE-2025-13844MEDIUMCVSS 5.3EG 5.32026-01-15
CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.
- CVE-2025-8585MEDIUMCVSS 5.3EG 5.32025-08-05
A vulnerability, which was classified as critical, has been found in libav up to 12.3. Affected by this issue is the function main of the file /avtools/avconv.c of the component DSS File Demuxer. The manipulation leads to double free. Atta…
- CVE-2025-31241MEDIUMCVSS 5.3EG 5.32025-05-12
A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6, tvOS 18.5, visionOS 2.5, watchOS 11.5. A remo…
- CVE-2024-35835MEDIUMCVSS 5.3EG 5.32024-05-17
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix a double-free in arfs_create_groups When `in` allocated by kvzalloc fails, arfs_create_groups will free ft->g and return an error. However, arfs_create_ta…
- CVE-2022-2588MEDIUMCVSS 5.3EG 5.32024-01-08
It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.
- CVE-2023-1999MEDIUMCVSS 5.3EG 5.32023-06-20
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memor…
- CVE-2021-42778MEDIUMCVSS 5.3EG 5.32022-04-18
A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
- CVE-2021-26954MEDIUMCVSS 5.3EG 5.32021-02-09
An issue was discovered in the qwutils crate before 0.3.1 for Rust. When a Clone panic occurs, insert_slice_clone can perform a double drop.
- CVE-2020-15710MEDIUMCVSS 5.3EG 5.32020-11-19
Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail condition in src/modules/bluetooth/module-bluez5-device.c and src/m…
- CVE-2018-7523MEDIUMCVSS 5.3EG 5.32018-03-21
In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a double free vulnerability.
- CVE-2026-6654MEDIUMCVSS 5.1EG 5.12026-04-20
Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.
- CVE-2026-23868MEDIUMCVSS 5.1EG 5.12026-03-10
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.
- CVE-2026-35188MEDIUMCVSS 5.0EG 5.02026-06-09
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free in the client's certificate verification path. Impact summary: Successful expl…
- CVE-2025-61145MEDIUMCVSS 5.0EG 5.02026-02-23
libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
- CVE-2024-53698MEDIUMCVSS 4.9EG 4.92025-03-07
A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify memory. We have already fixed the …
- CVE-2008-2944MEDIUMCVSS v2 4.9EG 4.92008-06-30
Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Enterprise Linux (RHEL) 5 and Fedora Core 6 (FC6) allows local users to cause a denial of service (oops), as demonstrated by a crash when runn…
- CVE-2026-108104MEDIUMCVSS 4.8EG 4.82026-10-09
Xerial snappy-java from 1.1.7.4 before 1.1.10.10 contains a double release vulnerability in SnappyFramedInputStream that returns pooled buffers twice when replacement allocation fails. Attackers can supply framed data with a large declared…
- CVE-2026-32848MEDIUMCVSS 4.7EG 4.72026-05-18
NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the sam…
- CVE-2025-20765MEDIUMCVSS 4.7EG 4.72025-12-02
In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: …
- CVE-2023-53586MEDIUMCVSS 4.7EG 4.72025-10-04
In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix multiple LUN_RESET handling This fixes a bug where an initiator thinks a LUN_RESET has cleaned up running commands when it hasn't. The bug was added in…
- CVE-2025-21825MEDIUMCVSS 4.7EG 4.72025-03-06
In the Linux kernel, the following vulnerability has been resolved: bpf: Cancel the running bpf_timer through kworker for PREEMPT_RT During the update procedure, when overwrite element in a pre-allocated htab, the freeing of old_element …
- CVE-2023-52384MEDIUMCVSS 4.7EG 4.72024-05-14
Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-52383MEDIUMCVSS 4.7EG 4.72024-05-14
Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-1032MEDIUMCVSS 4.7EG 4.72024-01-08
The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15c7691e9b13cbe9bf6c6…
- CVE-2019-15212MEDIUMCVSS 4.6EG 4.62019-08-19
An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c driver.
- CVE-2004-0643MEDIUMCVSS v2 4.6EG 4.62004-09-28
Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.
- CVE-2024-41957MEDIUMCVSS 4.5EG 4.52024-08-01
Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that …
- CVE-2023-7256MEDIUMCVSS 4.4EG 4.42024-08-31
In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() …
- CVE-2024-26846MEDIUMCVSS 4.4EG 4.42024-04-17
In the Linux kernel, the following vulnerability has been resolved: nvme-fc: do not wait in vain when unloading module The module exit path has race between deleting all controllers and freeing 'left over IDs'. To prevent double free a s…
- CVE-2021-25477MEDIUMCVSS 4.4EG 4.42021-10-06
An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote denial of service.
- CVE-2026-23790MEDIUMCVSS 4.2EG 4.22026-09-14
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer …
- CVE-2024-41965MEDIUMCVSS 4.2EG 4.22024-08-01
Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim m…
- CVE-2024-26652MEDIUMCVSS 4.1EG 4.12024-03-27
In the Linux kernel, the following vulnerability has been resolved: net: pds_core: Fix possible double free in error handling path When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), Callback function pdsc…
- CVE-2025-15667LOWCVSS 3.3EG 3.32026-07-06
A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrite of the file src/isomedia/avc_ext.c of the component MP4Box. This manipulation of the argument nalu_out_bs causes doub…
- CVE-2026-45324LOWCVSS 3.3EG 3.32026-05-29
Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cmd_search.c:byte_pattern_search() due wrong pointer ownership declared. This vulnerability is fixed by commit 045fff363b…
- CVE-2025-13566LOWCVSS 3.3EG 3.32025-11-23
A security vulnerability has been detected in jarun nnn up to 5.1. The impacted element is the function show_content_in_floating_window/run_cmd_as_plugin of the file nnn/src/nnn.c. The manipulation leads to double free. An attack has to be…
- CVE-2025-2925LOWCVSS 3.3EG 3.32025-03-28
A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerability affects the function H5MM_realloc of the file src/H5MM.c. The manipulation of the argument mem leads to double free. The attack needs to …
- CVE-2020-14354LOWCVSS 3.3EG 3.32021-05-13
A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. This flaw possibly allows an attacker to crash the service that uses c-ares lib. The highest threat …
- CVE-2021-22303LOWCVSS 3.3EG 3.32021-02-06
There is a pointer double free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). There is a lack of muti-thread protection when a function is called. Attackers can exploit this vulnerability by performing malicious operation to cause poin…
- CVE-2020-1862LOWCVSS 3.3EG 3.32020-03-20
There is a double free vulnerability in some Huawei products. A local attacker with low privilege may perform some operations to exploit the vulnerability. Due to doubly freeing memory, successful exploit may cause some service abnormal. A…
- CVE-2026-44348LOWCVSS 2.5EG 2.52026-05-14
PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFinal fails after buf has already been free…
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →