← Back
CWE-415

818 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Double Free

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

JSON object

Loading...

CVEs (818)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Linux
Redhat
4Enterprise Linux
Enterprise Linux For Real TimeEnterprise Linux For Real Time For Nfv+1 more
Jun 17, 2026
Jul 24, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further...Show more
A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. This issue occurs due to the lack of validating the existence of an object prior to performing further free operations on the object, which may allow a local privileged user to escalate privileges and execute code in the context of the kernel.Show less
1Xhttp Project
1Xhttp
Jun 17, 2026
Jul 18, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method.
1Microsoft
3365 Apps
OfficeOffice Long Term Servicing Channel
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Excel Remote Code Execution Vulnerability
1Qualcomm
207205 Firmware
215 Firmware315 5g Firmware+204 more
Jun 17, 2026
Jul 4, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
1Hnswlib Project
1Hnswlib
Jun 17, 2026
Jun 30, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Hnswlib 0.7.0 has a double free in init_index when the M argument is a large integer.
1Webmproject
1Libwebp
Jun 17, 2026
Jun 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because...Show more
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.Show less
1Linux
1Linux Kernel
Jun 17, 2026
Jun 19, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during device unbind will lead to double release problem leading to denial of service.
1Openbsd
2Libressl
Openbsd
Jun 17, 2026
Jun 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
1Microsoft
2Office
Office Online Server
Jun 17, 2026
Jun 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Excel Remote Code Execution Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Jun 14, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Windows Filtering Platform Elevation of Privilege Vulnerability
1Microsoft
5Windows 10 21h2
Windows 10 22h2Windows 11 21h2+2 more
Jun 17, 2026
Jun 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Geolocation Service Remote Code Execution Vulnerability
1Qualcomm
54Csr8811 Firmware
Ipq6000 FirmwareIpq6005 Firmware+51 more
Jun 17, 2026
Jun 6, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Linux Networking due to double free while handling a hyp-assign.
1Qualcomm
242315 5g Iot Modem Firmware
9205 Lte Modem Firmware9206 Lte Modem Firmware+239 more
Jun 17, 2026
Jun 6, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption due to double free in Core while mapping HLOS address to the list.
1Qualcomm
110Aqt1000 Firmware
Qam8255p FirmwareQam8295p Firmware+107 more
Jun 17, 2026
Jun 6, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed.
1Qualcomm
71Aqt1000 Firmware
Csrb31024 FirmwareQam8255p Firmware+68 more
Jun 17, 2026
Jun 6, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Linux android due to double free while calling unregister provider after register call.
1Google
1Android
Jun 17, 2026
May 15, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In adreno_set_param of adreno_gpu.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not ne...Show more
In adreno_set_param of adreno_gpu.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-265016072References: Upstream kernelShow less
1Intel
10Server System D50tnp1mhcpac Firmware
Server System D50tnp1mhcrac FirmwareServer System D50tnp1mhcrlc Firmware+7 more
Jun 17, 2026
May 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Double free in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
May 9, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
1Samsung
1Android
Jun 17, 2026
May 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.
2Debian
Xmlsoft
2Debian Linux
Libxml2
Jun 17, 2026
Apr 24, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory error...Show more
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various logic and memory errors, such as a double free. This behavior occurs because there is an attempt to use the first byte of an empty string, and any value is possible (not solely the '\0' value).Show less