CWE-415

High likelihood

Double Free

Parent: CWE-825 - Expired Pointer Dereference

The product calls free() twice on the same memory address.

823 vulnerabilities with CWE-415
CVE-2023-48013 HIGH
GPAC v2.3-DEV-rev566-g50c2ab06f-master - Use-After-Free via gf_filterpacket_del Function
CVSS 7.8
CVE-2023-43281 MEDIUM
Nothings Stb Image.h <2.28 - Memory Corruption
CVSS 6.5
CVE-2023-45679 HIGH
stb_vorbis.c - Use-After-Free in start_decoder Memory Allocation Failure
CVSS 7.3
CVE-2023-45666 HIGH
stb_image.h - Double Free in stbi__load_gif_main
CVSS 7.3
CVE-2023-45664 HIGH
stb_image.h - Double Free in stbi__load_gif_main_outofmem
CVSS 7.3
CVE-2023-42459 HIGH
Fast DDS <2.12.0-2.6.7 - Memory Corruption
CVSS 8.6
CVE-2023-36420 HIGH
Microsoft ODBC Driver for SQL Server - RCE
CVSS 7.8
CVE-2023-36418 HIGH
Azure RTOS GUIX Studio 6.0-6.2.x - Remote Code Execution via Double Free
CVSS 7.8
CVE-2023-32824 MEDIUM
Android - Double Free in rpmb
CVSS 6.7
CVE-2023-41911 MEDIUM
Samsung Exynos 2200 Firmware - Double Free in GPU
CVSS 4.7
CVE-2023-41374 HIGH
Kostac PLC Programming Software <1.6.11.0 - Code Injection
CVSS 7.8
CVE-2023-41325 HIGH
OP-TEE 3.20.0-3.21.9 - Double Free in RSA Key Allocation
CVSS 7.4
CVE-2023-4389 HIGH
Linux Kernel 5.7-5.10.112 - Use-After-Free in btrfs_get_root_ref
CVSS 7.0
CVE-2023-39975 HIGH
MIT Kerberos 5 1.21-<1.21.2 - Authenticated Double Free in Authorization-Data Handling
CVSS 8.8
CVE-2023-35371 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Double Free
CVSS 7.8
CVE-2023-33952 MEDIUM
Linux kernel - Privilege Escalation
CVSS 6.7
CVE-2023-38434 HIGH
xhttp 72f812d - Double Free in close_connection via Malformed HTTP Request Method
CVSS 7.5
CVE-2023-33161 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Double Free
CVSS 7.8
CVE-2023-21629 MEDIUM
Qualcomm Modem Firmware - Memory Corruption
CVSS 6.8
CVE-2023-37365 MEDIUM
hnswlib 0.7.0 - Double Free in init_index
CVSS 6.5
CVE-2023-1999 MEDIUM
libwebp 0.4.2-1.3.0 - Use-After-Free in ApplyFiltersAndEncode
CVSS 5.3
CVE-2023-3312 HIGH
Linux Kernel 6.2-6.2.15 - Use-After-Free in cpufreq qcom-cpufreq-hw Driver
CVSS 7.5
CVE-2023-35784 CRITICAL
LibreSSL < 3.6.3 and 3.7.x < 3.7.3 - Use-After-Free in SSL_clear
CVSS 9.8
CVE-2023-33137 HIGH
Microsoft Office - Remote Code Execution via Double Free
CVSS 7.8
CVE-2023-29368 HIGH
Windows Filtering Platform - Privilege Escalation
CVSS 7.0
Details
Vulnerabilities 823
Exploit Likelihood High