CWE-415

High likelihood

Double Free

Parent: CWE-825 - Expired Pointer Dereference

The product calls free() twice on the same memory address.

823 vulnerabilities with CWE-415
CVE-2025-65955 MEDIUM
ImageMagick <7.1.2-9 & 6.9.13-34 - Memory Corruption
CVSS 4.9
CVE-2025-13566 LOW
jarun nnn <= 5.1 - Use-After-Free in show_content_in_floating_window/run_cmd_as_plugin
CVSS 3.3
CVE-2025-62219 HIGH
Windows 10 1607-22H2 and Windows 11 23H2-25H2 - Authenticated Privilege Escalation via Double Free
CVSS 7.0
CVE-2025-62215 HIGH KEV
Windows Kernel - Use-After-Free via Race Condition
CVSS 7.0
CVE-2025-59505 HIGH
Windows Smart Card - Authenticated Double Free
CVSS 7.8
CVE-2025-43282 MEDIUM
iPadOS < 17.7.9 - Use-After-Free
CVSS 5.5
CVE-2025-61990 HIGH
F5 BIG-IP 15.1.0-15.1.10.8 - Denial of Service via TMM Double Free
CVSS 7.5
CVE-2025-59289 HIGH
Windows 10/11, Server 2022/2025 - Authenticated Double Free in Bluetooth Service
CVSS 7.0
CVE-2025-23282 HIGH
NVIDIA Display Driver - Privilege Escalation
CVSS 7.0
CVE-2025-39914 MEDIUM
Linux Kernel - Use-After-Free in Trace PID List Handling
CVSS 5.5
CVE-2025-47316 HIGH
Qualcomm AQT1000 and FastConnect Firmware - Use-After-Free via Timestamp Store Race Condition
CVSS 7.8
CVE-2025-39870 HIGH
Linux Kernel - Use-After-Free in idxd_setup_wqs()
CVSS 7.8
CVE-2025-51006 HIGH
tcpreplay - Denial of Service via Double Free in dlt_linuxsll2_cleanup
CVSS 7.8
CVE-2025-55118 HIGH
Control-M/Agent <9.0.20,9.0.21,9.0.22 - Memory Corruption
CVSS 8.9
CVE-2025-39790 HIGH
Linux Kernel 5.7-5.15.190 5.16-6.1.149 6.2-6.6.103 6.7-6.12.44 6.13-6.16.4 - Use-After-Free in MHI Host Event Processing
CVSS 8.4
CVE-2025-38731 HIGH
Linux Kernel 6.15-6.16.3 - Use-After-Free in Xe VM Bind IOCTL
CVSS 7.8
CVE-2025-38699 HIGH
Linux Kernel - Use-After-Free in SCSI BFA Driver
CVSS 7.8
CVE-2025-38682 HIGH
Linux Kernel 6.16-6.16.2 - Use-After-Free in i2c_unregister_device
CVSS 7.8
CVE-2025-38593 HIGH
Linux Kernel 5.17-6.15.10 - Use-After-Free in Bluetooth Discovery Filter Clear
CVSS 7.8
CVE-2025-38582 HIGH
Linux Kernel - Use-After-Free in RDMA/hns rsv_qp Destruction
CVSS 7.8
CVE-2025-53948 HIGH
Sante PACS Server < 4.2.3 - Unauthenticated Denial of Service via Crafted HL7 Message
CVSS 7.5
CVE-2025-20134 HIGH
Cisco Adaptive Security Appliance (ASA) Software - Denial of Service via Crafted DNS Packets
CVSS 8.6
CVE-2025-50169 HIGH
Windows SMB - Race Condition Remote Code Execution
CVSS 7.5
CVE-2025-55158 HIGH
vim 9.1.1231-9.1.1406 - Double Free in Vim9 Script Import Typed Value Handling
CVSS 8.8
CVE-2025-23322 HIGH
NVIDIA Triton Inference Server < 25.06 - Denial of Service via Stream Cancellation Double Free
CVSS 7.5
Details
Vulnerabilities 823
Exploit Likelihood High