CWE-415
876 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Double Free
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
CVEs (876)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A double drop can sometimes occur upon a panic in T::drop(). |
1Endian Trait Project 1Endian Trait Jun 17, 2026 Apr 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the endian_trait crate through 2021-01-04 for Rust. A double drop can occur when a user-provided Endian impl panics. |
In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not neede...Show more |
In main of main.cpp, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Pro...Show more |
4Fedoraproject NetappOpenbsd+1 more9Cloud Backup Communications Offline Mediation ControllerFedora+6 moreJun 17, 2026 Mar 5, 2021 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-...Show more |
1Stack Dst Project 1Stack Dst Jun 17, 2026 Mar 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a double free can occur upon a val.clone() panic. |
1Scratchpad Project 1Scratchpad Jun 17, 2026 Mar 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the scratchpad crate before 1.3.1 for Rust. The move_elements function can have a double-free upon a panic in a user-provided f function. |
An issue was discovered in the toodee crate before 0.3.0 for Rust. Row insertion can cause a double free upon an iterator panic. |
3Fedoraproject RedhatYtnef Project3Enterprise Linux FedoraYtnefJun 17, 2026 Mar 4, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file. |
3Debian FedoraprojectGnu3Debian Linux FedoraGlibcJun 17, 2026 Feb 24, 2021 N/A· v4 2.5 LOW· v3 1.9 LOW· v2 The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service o...Show more |
3Artifex DebianFedoraproject3Debian Linux FedoraMupdfJun 17, 2026 Feb 23, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences. |
2Autotrace Project Fedoraproject2Autotrace FedoraJun 17, 2026 Feb 11, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitmap image. This may occur after the use-after-free in CVE-2017-9182. |
An issue was discovered in the qwutils crate before 0.3.1 for Rust. When a Clone panic occurs, insert_slice_clone can perform a double drop. |
There is a pointer double free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). There is a lack of muti-thread protection when a function is called. Attackers can exploit this vulnerability by performing malicious oper...Show more |
An issue was discovered in the fil-ocl crate through 2021-01-04 for Rust. From<EventList> can lead to a double free. |
1Containers Project 1Containers Jun 17, 2026 Jan 26, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} double drop can be performed. |
3Apple DebianOpenldap3Debian Linux MacosOpenldapJun 17, 2026 Jan 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service. |
3Apple DebianOpenldap4Debian Linux Mac Os XMacos+1 moreJun 17, 2026 Jan 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read). |
An issue was discovered in the xcb crate through 2020-12-10 for Rust. base::Error does not have soundness. Because of the public ptr field, a use-after-free or double-free can occur. |
1Qualcomm 506Apq8009 Apq8009wApq8017+503 moreJun 17, 2026 Jan 21, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Pointer variable which is freed is not cleared can result in memory corruption and leads to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industria...Show more |