CWE-415

High likelihood

Double Free

Parent: CWE-825 - Expired Pointer Dereference

The product calls free() twice on the same memory address.

823 vulnerabilities with CWE-415
CVE-2026-23098 HIGH
Linux Kernel - Use-After-Free in nr_route_frame
CVSS 8.8
CVE-2026-23068 HIGH
Linux Kernel 4.17-6.1.161, 6.2-6.6.121, 6.7-6.12.67, 6.13-6.18.7 - Use-After-Free in SPI Controller Error Path
CVSS 7.8
CVE-2026-20415 MEDIUM
Android MediaTek MT6897/MT6989 - Denial of Service via Improper Locking in imgsys
CVSS 5.5
CVE-2026-21918 HIGH
Juniper Junos < 22.4R3-S7; 23.2 < 23.2R2-S3; 23.4 < 23.4R2-S4; 24.2 < 24.2R2 - DoS via TCP Session
CVSS 7.5
CVE-2026-20867 HIGH
Windows Management Services - Privilege Escalation
CVSS 7.8
CVE-2026-20863 HIGH
Microsoft Windows Win32K - Double Free in ICOMP
CVSS 7.0
CVE-2026-20861 HIGH
Windows Management Services - Privilege Escalation
CVSS 7.8
CVE-2026-20832 HIGH
Windows RPC IDL - Privilege Escalation
CVSS 7.8
CVE-2026-20026 MEDIUM
Cisco Secure Firewall Threat Defense (FTD) Software - Denial of Service via DCE/RPC Request Handling
CVSS 5.8
CVE-2025-15667 LOW
GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free
CVSS 3.3
CVE-2025-69650 HIGH
GNU Binutils < 2.46 - Denial of Service via Malformed ELF Relocation Data
CVSS 7.5
CVE-2025-71238 HIGH
Linux Kernel 5.7-5.10.250 - Use-After-Free in qla2xxx SCSI Driver bsg_done()
CVSS 7.8
CVE-2025-61145 MEDIUM
libtiff < 4.7.1 - Double Free in tiffcrop.c
CVSS 5.0
CVE-2025-12343 LOW
FFmpeg 6.1-8.1 - Double Free in TensorFlow Backend Error Handling
CVSS 3.3
CVE-2025-57785 MEDIUM
Hiawatha Webserver 11.7 - Unauthenticated Double Free in XSLT show_index
CVSS 6.5
CVE-2025-13844 MEDIUM
EcoStruxure Power Build - Rapsody < 2.8.8 - Double Free via Malicious SSD File Import
CVSS 5.3
CVE-2025-68968 HIGH
Multi-mode Input Module - Memory Corruption
CVSS 7.8
CVE-2025-68657 MEDIUM
Espressif USB Host HID Driver < 1.1.0 - Double Free in hid_host_device_close
CVSS 6.4
CVE-2025-47396 HIGH
Qualcomm FastConnect and Snapdragon Firmware - Use-After-Free in Secure Application Launch
CVSS 7.8
CVE-2025-47356 HIGH
Qualcomm Cologne Firmware - Memory Corruption via Concurrent Thread Access
CVSS 7.8
CVE-2025-20801 HIGH
Android - Local Privilege Escalation via Race Condition in seninf
CVSS 7.0
CVE-2025-20786 MEDIUM
Google Android - Use After Free
CVSS 6.7
CVE-2025-20781 HIGH
Google Android - Use After Free
CVSS 7.8
CVE-2025-36919 HIGH
Android - Use-After-Free in aoc_channel_dev.c aocc_read
CVSS 7.8
CVE-2025-62469 HIGH
Windows 11 24H2/25H2 and Windows Server 2025 - Local Privilege Escalation via Race Condition in Brokering File System
CVSS 7.0
Details
Vulnerabilities 823
Exploit Likelihood High