CWE-415
818 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Double Free
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
CVEs (818)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Jun 8, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This...Show more |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 May 14, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS. |
2C Ares Fedoraproject2C Ares FedoraJun 17, 2026 May 13, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. This flaw possibly allows an attacker to crash the service that uses c-ares lib....Show more |
1Foxitsoftware 2Foxit Reader PhantompdfJun 17, 2026 May 7, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is required to exploit this vulnerability in that the target must visit a mali...Show more |
1Qualcomm 373Apq8009 Firmware Apq8009w FirmwareApq8017 Firmware+370 moreJun 17, 2026 May 7, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Mus...Show more |
1Algorithmica Project 1Algorithmica Jun 17, 2026 May 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the algorithmica crate through 2021-03-07 for Rust. There is a double free in merge_sort::merge(). |
1Huawei 4Cloudengine 12800 Firmware Cloudengine 5800 FirmwareCloudengine 6800 Firmware+1 moreJun 17, 2026 Apr 28, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a pointer double free vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 and CloudEngine 12800. When a function is called, the same memory pointer is copied to two functional...Show more |
A Double Free vulnerability in the software forwarding interface daemon (sfid) process of Juniper Networks Junos OS allows an adjacently-connected attacker to cause a Denial of Service (DoS) by sending a crafted ARP pack...Show more |
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not...Show more |
2Fedoraproject Rust Lang2Fedora RustJun 17, 2026 Apr 14, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics. |
In setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalation of privilege in a privileged process with no additional execution privileges needed. User interaction is not needed...Show more |
In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use-after-free or double free. |
An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in remove_set upon a panic in a Drop impl. |
An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in get_or_insert upon a panic of a user-provided f function. |
An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in IdMap::clone_from upon a .clone panic. |
In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept filters implementing the accf_create callback incorrectly freed a process supplie...Show more |
1Qualcomm 317Apq8017 Firmware Apq8037 FirmwareApq8053 Firmware+314 moreJun 17, 2026 Apr 7, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdrag...Show more |
1Qualcomm 215Apq8017 Firmware Apq8053 FirmwareAqt1000 Firmware+212 moreJun 17, 2026 Apr 7, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in turn can lead to heap corruption in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer I...Show more |
An issue was discovered in the through crate through 2021-02-18 for Rust. There is a double free (in through and through_and) upon a panic of the map function. |