CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
846 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 2 of 17
- CVE-2016-9969HIGHCVSS 7.5EG 7.52019-05-23
In libwebp 0.5.1, there is a double free bug in libwebpmux.
- CVE-2017-1000072CRITICALCVSS 9.8EG 9.82017-07-17
Creolabs Gravity version 1.0 is vulnerable to a Double Free in gravity_value resulting potentially leading to modification of unexpected memory locations
- CVE-2017-1000231CRITICALCVSS 9.8EG 9.82017-11-17
A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.
- CVE-2017-1000232CRITICALCVSS 9.8EG 9.82017-11-17
A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.
- CVE-2017-10914HIGHCVSS 8.1EG 8.12017-07-05
The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA…
- CVE-2017-10950HIGHCVSS 7.0EG 7.02017-08-29
This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Bitdefender Total Security 21.0.24.62. An attacker must first obtain the ability to execute low-privileged code on the target system in orde…
- CVE-2017-11032HIGHCVSS 7.8EG 7.82017-11-16
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a double free can occur when kmalloc fails to allocate memory for pointers resp/req in the service-locator driver function serv…
- CVE-2017-11139CRITICALCVSS 9.8EG 9.82017-07-10
GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.
- CVE-2017-11462CRITICALCVSS 9.8EG 9.82017-09-13
Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.
- CVE-2017-12858CRITICALCVSS 9.8EG 9.82017-08-23
Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown vectors.
- CVE-2017-12925MEDIUMCVSS 6.5EG 6.52017-08-28
Double free vulnerability in DfFromLB in docfile.cxx in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service via a crafted fpx image.
- CVE-2017-13181HIGHCVSS 7.8EG 7.82018-01-12
In the doGetThumb and getThumbnail functions of MtpServer, there is a possible double free due to not NULLing out a freed pointer. This could lead to an local elevation of privilege enabling code execution as a privileged process with no a…
- CVE-2017-14449HIGHCVSS 7.5EG 8.82018-04-24
A double-Free vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a Double-Free situation to occur. An attacker can display a specially crafted image to trigger this vu…
- CVE-2017-14952CRITICALCVSS 9.8EG 9.82017-10-16
Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue.
- CVE-2017-15186MEDIUMCVSS 6.5EG 6.52017-10-24
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
- CVE-2017-15316HIGHCVSS 7.8EG 7.82017-12-22
The GPU driver of Mate 9 Huawei smart phones with software before MHA-AL00B 8.0.0.334(C00) and Mate 9 Pro Huawei smart phones with software before LON-AL00B 8.0.0.334(C00) has a memory double free vulnerability. An attacker tricks a user i…
- CVE-2017-15330MEDIUMCVSS 5.5EG 5.52018-02-15
The Flp Driver in some Huawei smartphones of the software Vicky-AL00AC00B124D, Vicky-AL00AC00B157D, Vicky-AL00AC00B167 has a double free vulnerability. An attacker can trick a user to install a malicious application which has a high privil…
- CVE-2017-15364MEDIUMCVSS 5.5EG 5.52017-10-15
The foreach function in ext/ccsv.c in Ccsv 1.1.0 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact via a crafted file. NOTE: This has been disputed and it is …
- CVE-2017-15826HIGHCVSS 7.8EG 7.82018-03-30
Due to a race condition in MDSS rotator in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-20, a double free vulnerability may potentially exist when two threads free the same perf structures.
- CVE-2017-15843HIGHCVSS 7.0EG 7.02018-06-12
Due to a race condition in a bus driver, a double free in msm_bus_floor_vote_context() can potentially occur in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
- CVE-2017-15856HIGHCVSS 7.0EG 7.02018-07-06
Due to a race condition while processing the power stats debug file to read status, a double free condition can occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security pa…
- CVE-2017-16820CRITICALCVSS 9.8EG 9.82017-11-14
The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other impact).
- CVE-2017-17320HIGHCVSS 7.8EG 7.82018-03-20
Huawei Mate 9 Pro smartphones with software of LON-AL00BC00B139D, LON-AL00BC00B229, LON-L29DC721B188 have a memory double free vulnerability. The system does not manage the memory properly, that frees on the same memory address twice. An a…
- CVE-2017-18120HIGHCVSS 7.8EG 7.82018-02-02
A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, because last_name is mishandled, a different …
- CVE-2017-18174CRITICALCVSS 9.8EG 9.82018-02-11
In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free.
- CVE-2017-18201CRITICALCVSS 9.8EG 9.82018-02-26
An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.
- CVE-2017-18297HIGHCVSS 7.8EG 7.82018-10-23
Double memory free while closing TEE SE API Session management in Snapdragon Mobile in version SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820.
- CVE-2017-18594HIGHCVSS 7.5EG 7.52019-08-29
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.
- CVE-2017-18595HIGHCVSS 7.8EG 7.82019-09-04
An issue was discovered in the Linux kernel before 4.14.11. A double free may be caused by the function allocate_trace_buffer in the file kernel/trace/trace.c.
- CVE-2017-2425HIGHCVSS 7.8EG 7.82017-04-02
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "SecurityFoundation" component. A double free vulnerability allows remote attackers to execute arbitrary code via a crafted certifi…
- CVE-2017-2636HIGHCVSS 7.0EG 7.82017-03-07
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
- CVE-2017-5334CRITICALCVSS 9.8EG 9.82017-03-24
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a…
- CVE-2017-5506HIGHCVSS 7.8EG 7.82017-03-24
Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file.
- CVE-2017-5836HIGHCVSS 7.5EG 7.52017-03-03
The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is treated as a PLIST_KEY and then triggers an invalid free.
- CVE-2017-6074HIGHCVSS 7.8EG 7.82017-02-18
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of serv…
- CVE-2017-6166MEDIUMCVSS 5.9EG 5.92017-11-22
In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management Microkernel (TMM) may crash when processing fragmented packets. This vulnerability affects…
- CVE-2017-6353MEDIUMCVSS 5.5EG 5.52017-03-01
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multit…
- CVE-2017-6362HIGHCVSS 7.5EG 7.52017-09-07
Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.
- CVE-2017-7373HIGHCVSS 7.8EG 7.82017-06-13
In all Android releases from CAF using the Linux kernel, a double free vulnerability exists in a display driver.
- CVE-2017-7393HIGHCVSS 8.8EG 8.82017-04-01
In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.
- CVE-2017-7521MEDIUMCVSS 5.9EG 5.92017-06-27
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().
- CVE-2017-8140HIGHCVSS 7.8EG 7.82017-11-22
The soundtrigger driver in P9 Plus smart phones with software versions earlier than VIE-AL10BC00B353 has a memory double free vulnerability. An attacker tricks a user into installing a malicious application, and the application can start m…
- CVE-2017-8141HIGHCVSS 7.8EG 7.82017-11-22
The Touch Panel (TP) driver in P10 Plus smart phones with software versions earlier than VKY-AL00C00B153 has a memory double free vulnerability. An attacker with the root privilege of the Android system tricks a user into installing a mali…
- CVE-2017-8265HIGHCVSS 7.0EG 7.02017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a video driver which can lead to a double free.
- CVE-2017-8890HIGHCVSS 7.8EG 7.82017-05-10
The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept s…
- CVE-2017-9078HIGHCVSS 8.8EG 8.82017-05-19
The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled.
- CVE-2017-9287MEDIUMCVSS 6.5EG 6.52017-05-29
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
- CVE-2017-9686HIGHCVSS 7.8EG 7.82017-10-10
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a possible double free/use after free in the SPS driver when debugfs logging is used.
- CVE-2017-9687HIGHCVSS 7.8EG 7.82017-10-10
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, two concurrent threads/processes can write the value of "0" to the debugfs file that controls ipa ipc log which will lead to th…
- CVE-2017-9705HIGHCVSS 7.8EG 7.82018-01-10
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, concurrent rx notifications and read() operations in the G-Link PKT driver can result in a double free condition due to missing…
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →