← Back
CWE-415

876 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Double Free

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

JSON object

Loading...

CVEs (876)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open...Show more
Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
1Microsoft
6365 Apps
Microsoft 365Office 2019+3 more
Sep 8, 2026
Sep 8, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
8.2 HIGH· v3
N/A· v2
Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
6.4 MEDIUM· v3
N/A· v2
Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Double free in Windows Hello allows an authorized attacker to elevate privileges locally.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
-
-
Sep 8, 2026
Sep 8, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally.
-
-
Sep 9, 2026
Sep 8, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
-
-
Sep 8, 2026
Sep 7, 2026
6.8 MEDIUM· v4
N/A· v3
N/A· v2
A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages