CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 4 of 19
- CVE-2024-38087HIGHCVSS 8.8EG 8.82024-07-09
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
- CVE-2024-30013HIGHCVSS 8.8EG 8.82024-07-09
Windows MultiPoint Services Remote Code Execution Vulnerability
- CVE-2024-30097HIGHCVSS 8.8EG 8.82024-06-11
Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
- CVE-2024-35814HIGHCVSS 8.8EG 8.82024-05-17
In the Linux kernel, the following vulnerability has been resolved: swiotlb: Fix double-allocation of slots due to broken alignment handling Commit bbb73a103fbb ("swiotlb: fix a braino in the alignment check fix"), which was a fix for co…
- CVE-2023-41678HIGHCVSS 8.8EG 8.82023-12-13
A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request.
- CVE-2023-45664HIGHCVSS 8.8EG 8.82023-10-21
stb_image is a single file MIT licensed library for processing images. A crafted image file can trigger `stbi__load_gif_main_outofmem` attempt to double-free the out variable. This happens in `stbi__load_gif_main` because when the `layers …
- CVE-2023-39975HIGHCVSS 8.8EG 8.82023-08-16
kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.
- CVE-2022-39170HIGHCVSS 8.8EG 8.82022-09-02
libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
- CVE-2022-27864HIGHCVSS 8.8EG 8.82022-07-29
A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affected installations. User interaction is required to exploit this vulnerability in that the target mu…
- CVE-2022-2008HIGHCVSS 8.8EG 8.82022-07-28
Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-39528HIGHCVSS 8.8EG 8.82021-09-20
An issue was discovered in libredwg through v0.10.1.3751. dwg_free_MATERIAL_private() in dwg.spec has a double free.
- CVE-2021-36080HIGHCVSS 8.8EG 8.82021-07-01
GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_encode_add_object).
- CVE-2021-0473HIGHCVSS 8.8EG 8.82021-06-11
In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitat…
- CVE-2021-30535HIGHCVSS 8.8EG 8.82021-06-07
Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-3492HIGHCVSS 8.8EG 8.82021-04-17
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all.…
- CVE-2019-20397HIGHCVSS 8.8EG 8.82020-01-22
A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminated. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause …
- CVE-2019-20394HIGHCVSS 8.8EG 8.82020-01-22
A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notification statement. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which…
- CVE-2019-20393HIGHCVSS 8.8EG 8.82020-01-22
A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or …
- CVE-2019-20014HIGHCVSS 8.8EG 8.82019-12-27
An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
- CVE-2019-2126HIGHCVSS 8.8EG 8.82019-08-20
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed fo…
- CVE-2019-1144HIGHCVSS 8.8EG 8.82019-08-14
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker…
- CVE-2019-12219HIGHCVSS 8.8EG 8.82019-05-20
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is an invalid free error in the SDL function SDL_SetError_REAL at SDL_error.c.
- CVE-2018-15518HIGHCVSS 8.8EG 8.82018-12-26
QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.
- CVE-2018-1000877HIGHCVSS 8.8EG 8.82018-12-20
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lz…
- CVE-2018-11982HIGHCVSS 8.8EG 8.82018-09-20
In Snapdragon (Mobile, Wear) in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 81…
- CVE-2018-17097HIGHCVSS 8.8EG 8.82018-09-16
The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (double free) or possibly have unspecified other impact, as demonstrated by SoundStretch.
- CVE-2018-1000222HIGHCVSS 8.8EG 8.82018-08-20
Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigger double free. This…
- CVE-2018-1000216HIGHCVSS 8.8EG 8.82018-08-20
Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JS…
- CVE-2018-11416HIGHCVSS 8.8EG 8.82018-05-24
jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
- CVE-2018-3845HIGHCVSS 8.8EG 8.82018-04-26
In Hyland Perceptive Document Filters 11.4.0.2647 - x86/x64 Windows/Linux, a crafted OpenDocument document can lead to a SkCanvas object double free resulting in direct code execution.
- CVE-2018-8804HIGHCVSS 8.8EG 8.82018-03-20
WriteEPTImage in coders/ept.c in ImageMagick 7.0.7-25 Q16 allows remote attackers to cause a denial of service (MagickCore/memory.c double free and application crash) or possibly have unspecified other impact via a crafted file.
- CVE-2017-9078HIGHCVSS 8.8EG 8.82017-05-19
The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled.
- CVE-2016-1516HIGHCVSS 8.8EG 8.82017-04-10
OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.
- CVE-2017-7393HIGHCVSS 8.8EG 8.82017-04-01
In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.
- CVE-2009-1544HIGHCVSS 8.8EG 8.82009-08-12
Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via…
- CVE-2022-25750HIGHCVSS 8.4EG 8.82022-10-19
Memory corruption in BTHOST due to double free while music playback and calls over bluetooth headset in Snapdragon Mobile
- CVE-2024-23141HIGHCVSS 7.8EG 8.82024-06-25
A maliciously crafted MODEL file, when parsed in libodxdll through Autodesk applications, can cause a double free. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
- CVE-2017-14449HIGHCVSS 7.5EG 8.82018-04-24
A double-Free vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a Double-Free situation to occur. An attacker can display a specially crafted image to trigger this vu…
- CVE-2026-19316HIGHCVSS 8.7EG 8.72026-08-27
A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
- CVE-2026-55995HIGHCVSS 8.7EG 8.72026-07-29
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
- CVE-2026-12659HIGHCVSS 8.7EG 8.72026-07-14
A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the…
- CVE-2023-38562HIGHCVSS 8.7EG 8.72024-02-20
A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to memory corruption, potentially resulting in code execution. An…
- CVE-2026-20135HIGHCVSS 8.6EG 8.62026-09-16
A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS)…
- CVE-2025-20134HIGHCVSS 8.6EG 8.62025-08-14
A vulnerability in the certificate processing of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device t…
- CVE-2024-45402HIGHCVSS 8.6EG 8.62024-10-11
Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsing a spoofed TLS handshake message, picotls (specifically, bindings within picotls that call the crypto libraries) may …
- CVE-2024-20498HIGHCVSS 8.6EG 8.62024-10-02
Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an af…
- CVE-2022-20803HIGHCVSS 8.6EG 8.62023-02-17
A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device.The vulnerability is due to in…
- CVE-2021-34769HIGHCVSS 8.6EG 8.62021-09-23
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to…
- CVE-2021-34768HIGHCVSS 8.6EG 8.62021-09-23
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to…
- CVE-2021-1565HIGHCVSS 8.6EG 8.62021-09-23
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to…
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →