CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 3 of 19
- CVE-2015-7700CRITICALCVSS 9.8EG 9.82017-08-31
Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.
- CVE-2017-12858CRITICALCVSS 9.8EG 9.82017-08-23
Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown vectors.
- CVE-2017-1000072CRITICALCVSS 9.8EG 9.82017-07-17
Creolabs Gravity version 1.0 is vulnerable to a Double Free in gravity_value resulting potentially leading to modification of unexpected memory locations
- CVE-2017-11139CRITICALCVSS 9.8EG 9.82017-07-10
GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.
- CVE-2017-5334CRITICALCVSS 9.8EG 9.82017-03-24
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a…
- CVE-2016-6912CRITICALCVSS 9.8EG 9.82017-01-26
Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.
- CVE-2016-3177CRITICALCVSS 9.8EG 9.82017-01-23
Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors.
- CVE-2016-5772CRITICALCVSS 9.8EG 9.82016-08-07
Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or pos…
- CVE-2016-5768CRITICALCVSS 9.8EG 9.82016-08-07
Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to execute arbitrary code or cause…
- CVE-2016-3132CRITICALCVSS 9.8EG 9.82016-08-07
Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to execute arbitrary code via a crafted index.
- CVE-2015-8880CRITICALCVSS 9.8EG 9.82016-05-22
Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error.
- CVE-2004-0772CRITICALCVSS 9.8EG 9.82004-10-20
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.
- CVE-2003-0545CRITICALCVSS 9.8EG 9.82003-11-17
Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.
- CVE-2002-0059CRITICALCVSS 9.8EG 9.82002-03-15
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory more than once (a "double free"), which may allow local and remote attackers to execute ar…
- CVE-2022-42915CRITICALCVSS 8.1EG 9.82022-10-29
curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the pr…
- CVE-2022-23459CRITICALCVSS 8.1EG 9.82022-08-19
Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value class may lead to memory corruption via a double free or via a use after free. The value class has a default assignment op…
- CVE-2018-5379CRITICALCVSS 7.5EG 9.82018-02-19
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potential…
- CVE-2022-40515CRITICALCVSS 7.3EG 9.82023-03-10
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
- CVE-2022-25668CRITICALCVSS 7.3EG 9.82022-09-02
Memory corruption in video driver due to double free while parsing ASF clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, S…
- CVE-2022-22086CRITICALCVSS 7.3EG 9.82022-06-14
Memory corruption in video due to double free while parsing 3gp clip with invalid meta data atoms in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapd…
- CVE-2023-25136CRITICALCVSS 6.5EG 9.82023-02-03
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to…
- CVE-2016-8619CRITICALCVSS 5.3EG 9.82018-08-01
The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.
- CVE-2016-8618CRITICALCVSS 5.3EG 9.82018-07-31
The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplication, on systems using 32 bit `size_t` variables.
- CVE-2022-33231CRITICALCVSS 9.3EG 9.32023-04-13
Memory corruption due to double free in core while initializing the encryption key.
- CVE-2015-0312HIGHCVSS v2 9.3EG 9.32015-01-28
Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.0.296 on Windows and OS X and before 11.2.202.440 on Linux allows attackers to execute arbitrary code via unspecified vectors.
- CVE-2014-0301HIGHCVSS v2 9.3EG 9.32014-03-12
Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold a…
- CVE-2020-27794CRITICALCVSS 9.1EG 9.12022-08-19
A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modification of unexpected memory locations and potentially causing a crash.
- CVE-2021-22945CRITICALCVSS 9.1EG 9.12021-09-23
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.
- CVE-2007-1216HIGHCVSS v2 9.0EG 9.02007-04-06
Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC librar…
- CVE-2025-55118HIGHCVSS 8.9EG 8.92025-09-16
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting …
- CVE-2026-23918HIGHCVSS 8.8EG 8.92026-05-04
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
- CVE-2019-11932HIGHCVSS 8.8EG 8.92019-10-03
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote atta…
- CVE-2026-91018HIGHCVSS 8.8EG 8.82026-09-22
lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.
- CVE-2026-87585HIGHCVSS 8.8EG 8.82026-09-09
Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
- CVE-2026-80080HIGHCVSS 8.8EG 8.82026-09-08
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-77504HIGHCVSS 8.8EG 8.82026-09-08
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-64382HIGHCVSS 8.8EG 8.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_open_init() fails befor…
- CVE-2026-66032HIGHCVSS 8.8EG 8.82026-07-24
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. Whe…
- CVE-2026-64832HIGHCVSS 8.8EG 8.82026-07-22
FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surf…
- CVE-2026-53322HIGHCVSS 8.8EG 8.82026-06-26
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs before disabling function On device shutdown, make vfio_pci_core_close_device() call vfio_pci_dma_buf_cleanup() before the function is disable…
- CVE-2026-12043HIGHCVSS 8.8EG 8.82026-06-12
Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to a…
- CVE-2026-44422HIGHCVSS 8.8EG 8.82026-05-29
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR ty…
- CVE-2026-43249HIGHCVSS 8.8EG 8.82026-05-06
In the Linux kernel, the following vulnerability has been resolved: 9p/xen: protect xen_9pfs_front_free against concurrent calls The xenwatch thread can race with other back-end change notifications and call xen_9pfs_front_free() twice, …
- CVE-2025-55158HIGHCVSS 8.8EG 8.82025-08-11
Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tuples during Vim9 script import operations, an error during evaluation can trigger a double-free in Vim’s internal typ…
- CVE-2025-49688HIGHCVSS 8.8EG 8.82025-07-08
Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- CVE-2025-23102HIGHCVSS 8.8EG 8.82025-06-03
An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380, 1480 and 2400. A Double Free in the mobile processor leads to privilege escalation.
- CVE-2025-21201HIGHCVSS 8.8EG 8.82025-02-11
Windows Telephony Server Remote Code Execution Vulnerability
- CVE-2025-21291HIGHCVSS 8.8EG 8.82025-01-14
Windows Direct Show Remote Code Execution Vulnerability
- CVE-2024-35365HIGHCVSS 8.8EG 8.82025-01-03
FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically within the new_stream_audio function.
- CVE-2024-49014HIGHCVSS 8.8EG 8.82024-11-12
SQL Server Native Client Remote Code Execution Vulnerability
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →