CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,847 CVEs tracked 53,242 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,918 Nuclei templates 37,802 vendors 42,493 researchers
718 results Clear all
CVE-2017-6074 7.8 HIGH 6 PoCs Analysis EPSS 0.20
Linux Kernel < 3.2.86 - Double Free
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
CWE-415 Feb 18, 2017
CVE-2016-8693 7.8 HIGH 1 Writeup EPSS 0.01
JasPer <1.900.10 - Use After Free
Double free vulnerability in the mem_close function in jas_stream.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image to the imginfo command.
CWE-415 Feb 15, 2017
CVE-2016-8360 8.1 HIGH EPSS 0.01
Moxa SoftCMS <1.6 - RCE
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. A specially crafted URL request sent to the SoftCMS ASP Webserver can cause a double free condition on the server allowing an attacker to modify memory locations and possibly cause a denial of service or the execution of arbitrary code.
CWE-415 Feb 13, 2017
CVE-2016-6912 9.8 CRITICAL EPSS 0.01
Libgd < 2.2.3 - Double Free
Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.
CWE-415 Jan 26, 2017
CVE-2016-3177 9.8 CRITICAL EPSS 0.00
Giflib - Use After Free
Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors.
CWE-415 Jan 23, 2017
CVE-2016-9806 7.8 HIGH 1 Writeup EPSS 0.00
Linux Kernel < 3.12.62 - Race Condition
Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes sendmsg system calls, leading to a free operation associated with a new dump that started earlier than anticipated.
CWE-415 Dec 28, 2016
CVE-2015-8962 7.3 HIGH EPSS 0.00
Linux Kernel < 3.2.85 - Double Free
Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (memory corruption and system crash) by detaching a device during an SG_IO ioctl call.
CWE-415 Nov 16, 2016
CVE-2016-5384 7.8 HIGH EPSS 0.00
Fedora < 2.12.1 - Double Free
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
CWE-415 Aug 13, 2016
CVE-2016-5772 9.8 CRITICAL EPSS 0.16
PHP <5.5.37, <5.6.23, <7.0.8 - Use After Free
Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted XML data that is mishandled in a wddx_deserialize call.
CWE-415 Aug 07, 2016
CVE-2016-5768 9.8 CRITICAL EPSS 0.21
PHP <5.5.37, 5.6.x <5.6.23, 7.x <7.0.8 - RCE
Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by leveraging a callback exception.
CWE-415 Aug 07, 2016
CVE-2016-3132 9.8 CRITICAL EPSS 0.11
Php - Double Free
Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to execute arbitrary code via a crafted index.
CWE-415 Aug 07, 2016
CVE-2015-8880 9.8 CRITICAL EPSS 0.02
Php - Double Free
Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error.
CWE-415 May 22, 2016
CVE-2015-0058 1 PoC Analysis EPSS 0.08
Microsoft Windows 8.1 - Double Free
Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a crafted application, aka "Windows Cursor Object Double Free Vulnerability."
CWE-415 Feb 11, 2015
CVE-2015-0312 EPSS 0.05
Adobe Flash Player < 11.2.202.438 - Double Free
Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.0.296 on Windows and OS X and before 11.2.202.440 on Linux allows attackers to execute arbitrary code via unspecified vectors.
CWE-415 Jan 28, 2015
CVE-2014-4343 EPSS 0.07
MIT Kerberos 5 <1.12.2 - Use After Free
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via network traffic that appears to come from an intended acceptor, but specifies a security mechanism different from the one proposed by the initiator.
CWE-415 Aug 14, 2014
CVE-2014-1767 4 PoCs Analysis EPSS 0.56
Microsoft Windows - Privilege Escalation
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
CWE-415 Jul 08, 2014
CVE-2014-0301 EPSS 0.21
Microsoft Windows - Memory Corruption
Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via a crafted JPEG image, aka "DirectShow Memory Corruption Vulnerability."
CWE-415 Mar 12, 2014
CVE-2014-0502 8.8 HIGH KEV EPSS 0.89
Adobe Flash Player <11.7.700.269-12.0.0.70 - RCE
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.
CWE-415 Feb 21, 2014
CVE-2014-1252 EPSS 0.04
Apple Pages < 10.9.1 - Double Free
Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.
CWE-415 Jan 24, 2014
CVE-2011-3892 EPSS 0.02
Google Chrome <15.0.874.120 - Use After Free
Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted stream.
CWE-415 Nov 11, 2011