CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 2 of 19
- CVE-2021-30455CRITICALCVSS 9.8EG 9.82021-04-07
An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in IdMap::clone_from upon a .clone panic.
- CVE-2021-29940CRITICALCVSS 9.8EG 9.82021-04-01
An issue was discovered in the through crate through 2021-02-18 for Rust. There is a double free (in through and through_and) upon a panic of the map function.
- CVE-2021-0397CRITICALCVSS 9.8EG 9.82021-03-10
In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.…
- CVE-2021-28034CRITICALCVSS 9.8EG 9.82021-03-05
An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a double free can occur upon a val.clone() panic.
- CVE-2021-28031CRITICALCVSS 9.8EG 9.82021-03-05
An issue was discovered in the scratchpad crate before 1.3.1 for Rust. The move_elements function can have a double-free upon a panic in a user-provided f function.
- CVE-2021-28028CRITICALCVSS 9.8EG 9.82021-03-05
An issue was discovered in the toodee crate before 0.3.0 for Rust. Row insertion can cause a double free upon an iterator panic.
- CVE-2021-25907CRITICALCVSS 9.8EG 9.82021-01-26
An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} double drop can be performed.
- CVE-2020-35885CRITICALCVSS 9.8EG 9.82020-12-31
An issue was discovered in the alpm-rs crate through 2020-08-20 for Rust. StrcCtx performs improper memory deallocation.
- CVE-2020-35862CRITICALCVSS 9.8EG 9.82020-12-31
An issue was discovered in the bitvec crate before 0.17.4 for Rust. BitVec to BitBox conversion leads to a use-after-free or double free.
- CVE-2019-25009CRITICALCVSS 9.8EG 9.82020-12-31
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness.
- CVE-2020-24698CRITICALCVSS 9.8EG 9.82020-10-02
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker might be able to cause a double-free, leading to a crash or possibly arbitrary code execution. …
- CVE-2020-24978CRITICALCVSS 9.8EG 9.82020-09-04
In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.
- CVE-2020-1647CRITICALCVSS 9.8EG 9.82020-07-17
On Juniper Networks SRX Series with ICAP (Internet Content Adaptation Protocol) redirect service enabled, a double free vulnerability can lead to a Denial of Service (DoS) or Remote Code Execution (RCE) due to processing of a specific HTTP…
- CVE-2020-6072CRITICALCVSS 9.8EG 9.82020-03-24
An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the rr_decode function's return value is not checked, leading to a doubl…
- CVE-2020-8432CRITICALCVSS 9.8EG 9.82020-01-29
In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an attacker to execute arbitrary code. NOTE: this vulnerablity…
- CVE-2007-4773CRITICALCVSS 9.8EG 9.82020-01-15
Systrace before 1.6.0 has insufficient escape policy enforcement.
- CVE-2019-11049CRITICALCVSS 9.8EG 9.82019-12-23
In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can resul…
- CVE-2019-19725CRITICALCVSS 9.8EG 9.82019-12-11
sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
- CVE-2019-10565CRITICALCVSS 9.8EG 9.82019-11-06
Double free issue can happen when sensor power settings is freed by some thread while another thread try to access. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon I…
- CVE-2019-17545CRITICALCVSS 9.8EG 9.82019-10-14
GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
- CVE-2019-16880CRITICALCVSS 9.8EG 9.82019-09-25
An issue was discovered in the linea crate through 0.9.4 for Rust. There is double free in the Matrix::zip_elements method.
- CVE-2019-5481CRITICALCVSS 9.8EG 9.82019-09-16
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
- CVE-2018-20996CRITICALCVSS 9.8EG 9.82019-08-26
An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling.
- CVE-2019-15551CRITICALCVSS 9.8EG 9.82019-08-26
An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts with the current capacity.
- CVE-2018-20991CRITICALCVSS 9.8EG 9.82019-08-26
An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors, leading to a double free.
- CVE-2019-15504CRITICALCVSS 9.8EG 9.82019-08-23
drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir).
- CVE-2019-8044CRITICALCVSS 9.8EG 9.82019-08-20
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a double free vulnerability. …
- CVE-2019-15151CRITICALCVSS 9.8EG 9.82019-08-18
AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.
- CVE-2018-20961CRITICALCVSS 9.8EG 9.82019-08-07
In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of service or possibly have unspecified other …
- CVE-2019-12874CRITICALCVSS 9.8EG 9.82019-06-18
An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a double free.
- CVE-2019-7080CRITICALCVSS 9.8EG 9.82019-05-24
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a double free vulnerability. Successful exploitation could lead to arbitrary …
- CVE-2019-7784CRITICALCVSS 9.8EG 9.82019-05-22
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a double free vulnerability. …
- CVE-2018-3985CRITICALCVSS 9.8EG 9.82019-03-21
An exploitable double free vulnerability exists in the mdnscap binary of the CUJO Smart Firewall. When parsing mDNS packets, a memory space is freed twice if an invalid query name is encountered, leading to arbitrary code execution in the …
- CVE-2019-6978CRITICALCVSS 9.8EG 9.82019-01-28
The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.
- CVE-2018-9356CRITICALCVSS 9.8EG 9.82018-11-06
In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Prod…
- CVE-2018-18751CRITICALCVSS 9.8EG 9.82018-10-29
An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt.
- CVE-2018-17825CRITICALCVSS 9.8EG 9.82018-10-01
An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuopl class in emuopl.cpp because of a destructor's two OPLDestroy calls, each of which frees TL_TABLE, SIN_TABLE, AMS_TABLE, and VIB_TABLE.
- CVE-2018-16402CRITICALCVSS 9.8EG 9.82018-09-03
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
- CVE-2018-12782CRITICALCVSS 9.8EG 9.82018-07-20
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the…
- CVE-2018-14054CRITICALCVSS 9.8EG 9.82018-07-13
A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0. A dangling pointer is freed again in the destructor once an exception is triggered.
- CVE-2015-9165CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 650/52, SD 808, and S…
- CVE-2018-3593CRITICALCVSS 9.8EG 9.82018-04-11
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617…
- CVE-2017-18201CRITICALCVSS 9.8EG 9.82018-02-26
An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.
- CVE-2018-7263CRITICALCVSS 9.8EG 9.82018-02-20
The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service (SIGABRT because of double free or corruption) or possibly have unspecified other impact via a crafted file…
- CVE-2017-18174CRITICALCVSS 9.8EG 9.82018-02-11
In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free.
- CVE-2017-1000232CRITICALCVSS 9.8EG 9.82017-11-17
A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.
- CVE-2017-1000231CRITICALCVSS 9.8EG 9.82017-11-17
A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.
- CVE-2017-16820CRITICALCVSS 9.8EG 9.82017-11-14
The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other impact).
- CVE-2017-14952CRITICALCVSS 9.8EG 9.82017-10-16
Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue.
- CVE-2017-11462CRITICALCVSS 9.8EG 9.82017-09-13
Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →