CWE-415

High likelihood

Double Free

Parent: CWE-825 - Expired Pointer Dereference

The product calls free() twice on the same memory address.

786 vulnerabilities with CWE-415
CVE-2023-4389 HIGH
Linux Kernel 5.7-5.10.112 - Use-After-Free in btrfs_get_root_ref
CVSS 7.0
CVE-2023-39975 HIGH
MIT Kerberos 5 1.21-<1.21.2 - Authenticated Double Free in Authorization-Data Handling
CVSS 8.8
CVE-2023-35371 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Double Free
CVSS 7.8
CVE-2023-33952 MEDIUM
Linux kernel - Privilege Escalation
CVSS 6.7
CVE-2023-38434 HIGH
xhttp 72f812d - Double Free in close_connection via Malformed HTTP Request Method
CVSS 7.5
CVE-2023-33161 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Double Free
CVSS 7.8
CVE-2023-21629 MEDIUM
Qualcomm Modem Firmware - Memory Corruption
CVSS 6.8
CVE-2023-37365 MEDIUM
hnswlib 0.7.0 - Double Free in init_index
CVSS 6.5
CVE-2023-1999 MEDIUM
libwebp 0.4.2-1.3.0 - Use-After-Free in ApplyFiltersAndEncode
CVSS 5.3
CVE-2023-3312 HIGH
Linux Kernel 6.2-6.2.15 - Use-After-Free in cpufreq qcom-cpufreq-hw Driver
CVSS 7.5
CVE-2023-35784 CRITICAL
LibreSSL < 3.6.3 and 3.7.x < 3.7.3 - Use-After-Free in SSL_clear
CVSS 9.8
CVE-2023-33137 HIGH
Microsoft Office - Remote Code Execution via Double Free
CVSS 7.8
CVE-2023-29368 HIGH
Windows Filtering Platform - Privilege Escalation
CVSS 7.0
CVE-2023-29366 HIGH
Microsoft Windows Geolocation Service - Remote Code Execution
CVSS 7.8
CVE-2023-21106 HIGH
Android - Double Free in adreno_set_param
CVSS 7.8
CVE-2023-28411 MEDIUM
Intel Server System D50TNP1MHCRLC Firmware < 2.90 - Information Disclosure via Double Free
CVSS 6.3
CVE-2023-24903 HIGH
Microsoft Windows SSTP - Remote Code Execution
CVSS 8.1
CVE-2023-21500 MEDIUM
Samsung Android - Double Free in mPOS TUI Trustlet setPinPadImages
CVSS 6.0
CVE-2023-29469 MEDIUM
libxml2 < 2.10.4 - Double Free via Empty Dict String Hashing
CVSS 6.5
CVE-2023-28296 HIGH
Visual Studio 2017 15.0-15.9.53, 2019 16.0-16.11.25, 2022 17.0-17.0.20, 17.2.0-17.2.14 - Remote Code Execution
CVSS 7.8
CVE-2023-28464 HIGH
Linux kernel <6.2.9 - Use After Free
CVSS 7.8
CVE-2023-27537 MEDIUM
libcurl < 8.0.0 - Double Free via HSTS Data Sharing
CVSS 5.9
CVE-2023-25801 HIGH
TensorFlow < 2.12.0 - Use-After-Free in Fractional Pooling Ops
CVSS 8.0
CVE-2023-21030 HIGH
Android 13 - Double Free in keystore_cli_v2.cpp
CVSS 7.8
CVE-2023-1449 MEDIUM
GPAC 2.3-DEV-rev35-gbbca86917-master - Double Free
CVSS 5.3
Details
Vulnerabilities 786
Exploit Likelihood High