CWE-415
818 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Double Free
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
CVEs (818)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Gnu2Fedora GnutlsJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates...Show more |
An exploitable double free vulnerability exists in the mdnscap binary of the CUJO Smart Firewall. When parsing mDNS packets, a memory space is freed twice if an invalid query name is encountered, leading to arbitrary cod...Show more |
1Intel 1Software Guard Extensions Sdk Jun 17, 2026 Mar 14, 2019 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Double free in Intel(R) SGX SDK for Linux before version 2.2 and Intel(R) SGX SDK for Windows before version 2.1 may allow an authenticated user to potentially enable information disclosure or denial of service via local...Show more |
3Canonical DebianGoogle3Android Debian LinuxUbuntu LinuxJun 17, 2026 Feb 28, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User in...Show more |
3Canonical DebianLibgd3Debian Linux LibgdUbuntu LinuxJun 17, 2026 Jan 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected. |
An issue was discovered in GNU Recutils 1.8. There is a double-free problem in the function rec_mset_elem_destroy() in the file rec-mset.c. |
3Debian OpensuseQt3Debian Linux LeapQtNov 21, 2024 Dec 26, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document. |
The read_MSAT function in ole.c in libxls 1.4.0 has a double free that allows attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2017-2897. |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Dec 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes...Show more |
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, if there is an unlikely memory alloc failure for the secure pool in boot, it can result in wrong pointer access c...Show more |
In MasteringMetadata::Parse of mkvparser.cc there is a possible double free due to an insecure default value. This could lead to remote code execution with no additional execution privileges needed. User interaction is n...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxNov 21, 2024 Nov 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configured to accept smart-card authentication, Samba's KDC will call talloc_free() twice on the same memor...Show more |
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, memory allocated is automatically released by the kernel if the 'probe' function fails with an error code. |
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, freeing device memory in driver probe failure will result in double free issue in power module. |
2Canonical Google2Android Ubuntu LinuxJun 17, 2026 Nov 6, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In driver_override_store and driver_override_show of bus.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interact...Show more |
In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for...Show more |
3Canonical GnuRedhat3Enterprise Linux GettextUbuntu LinuxNov 21, 2024 Oct 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt. |
2Debian Gnome2Debian Linux GthumbNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c because of two successive calls of g_free, each of which frees the same buffe...Show more |
1Qualcomm 7Sd 425 Firmware Sd 430 FirmwareSd 450 Firmware+4 moreNov 21, 2024 Oct 23, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Double memory free while closing TEE SE API Session management in Snapdragon Mobile in version SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820. |
1Adobe 2Acrobat Dc Acrobat Reader DcNov 21, 2024 Oct 12, 2018 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a double free vulnerability. Successful exploitation could lead to arbitrary code execution. |