CWE-415
781 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Double Free
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
CVEs (781)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 47Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+44 moreNov 21, 2024 Dec 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Potential double free scenario if driver receives another DIAG_EVENT_LOG_SUPPORTED event from firmware as the pointer is not set to NULL on first call in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electroni...Show more |
1Qualcomm 33Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+30 moreNov 21, 2024 Dec 18, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Memory is being freed up twice when two concurrent threads are executing in parallel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdrag...Show more |
3Canonical DebianSysstat Project3Debian Linux SysstatUbuntu LinuxNov 21, 2024 Dec 11, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c. |
1Qualcomm 16Apq8053 Firmware Ipq4019 FirmwareIpq8064 Firmware+13 moreNov 21, 2024 Nov 21, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Possible double free issue in kernel while handling the camera sensor and its sub modules power sequence in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdrag...Show more |
1Huawei 7Emily Al00a Firmware Emily L09c FirmwareEmily L29c Firmware+4 moreNov 21, 2024 Nov 13, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Bastet module of some Huawei smartphones with Versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Versions earlier than Emily-TL00B 9.0.0.182(C01E82R1P21), Versions earlier than Emily-L09C 9.0.0.203(C432E7R1P11), V...Show more |
An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Blink M11 and M12 when trying to access a removed smil element. |
A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function. |
psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object. |
1Qualcomm 13Apq8053 Firmware Mdm9206 FirmwareMdm9207c Firmware+10 moreNov 21, 2024 Nov 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Double free issue can happen when sensor power settings is freed by some thread while another thread try to access. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consume...Show more |
5Debian FedoraprojectOpensuse+2 more6Backports Sle Debian LinuxFedora+3 moreNov 21, 2024 Oct 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded. |
2Android Gif Drawable Project Whatsapp2Android Gif Drawable WhatsappNov 21, 2024 Oct 3, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications,...Show more |
An issue was discovered in the linea crate through 0.9.4 for Rust. There is double free in the Matrix::zip_elements method. |
6Debian FedoraprojectHaxx+3 more12Cloud Backup Communications Operations MonitorCommunications Session Border Controller+9 moreApr 16, 2026 Sep 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3. |
In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution pri...Show more |
An issue was discovered in the Linux kernel before 4.14.11. A double free may be caused by the function allocate_trace_buffer in the file kernel/trace/trace.c. |
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse. |
1Crossbeam Project 1Crossbeam Nov 21, 2024 Aug 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling. |
An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts with the current capacity. |
An issue was discovered in the smallvec crate before 0.6.3 for Rust. The Iterator implementation mishandles destructors, leading to a double free. |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Aug 23, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through 5.2.9 has a Double Free via crafted USB device traffic (which may be remote via usbip or usbredir). |