CWE-415

High likelihood

Double Free

Parent: CWE-825 - Expired Pointer Dereference

The product calls free() twice on the same memory address.

823 vulnerabilities with CWE-415
CVE-2024-57980 HIGH
Linux Kernel - Use-After-Free in UVC Video Status Cleanup
CVSS 7.8
CVE-2024-39564 HIGH
Juniper Junos OS 22.4 - Denial of Service via Malformed BGP Path Attribute Update
CVSS 7.5
CVE-2024-56775 HIGH
Linux Kernel < 6.12.4 - Use-After-Free in DRM AMD Display Plane State Handling
CVSS 7.8
CVE-2024-56766 HIGH
Linux Kernel - Use-After-Free in atmel_pmecc_create_user()
CVSS 7.8
CVE-2024-35365 HIGH
FFmpeg n6.1.1 - Double Free in new_stream_audio Function
CVSS 8.8
CVE-2024-56708 HIGH
Linux Kernel 5.11-6.12.1 - Use-After-Free in EDAC igen6 Module Unload
CVSS 7.8
CVE-2024-56704 HIGH
Linux Kernel 4.12-6.12.2 - Use-After-Free in 9p/xen IRQ Release
CVSS 7.8
CVE-2024-56699 HIGH
Linux Kernel 6.9-6.12.1, 6.11.11 - Use-After-Free in s390/pci Hotplug Slot Release
CVSS 7.8
CVE-2024-53213 HIGH
Linux Kernel 5.17-6.1.119, 6.2-6.6.63, 6.7-6.11.10, 6.12.0-6.12.1 - Use-After-Free in lan78xx_probe
CVSS 7.8
CVE-2024-53191 HIGH
Linux Kernel 6.3-6.6.63, 6.7-6.11.10, 6.12-6.12.1 - Double Free in ath12k WiFi Driver
CVSS 7.8
CVE-2024-49095 HIGH
Windows PrintWorkflowUserSvc - Elevation of Privilege via Race Condition
CVSS 7.0
CVE-2024-53133 HIGH
Linux Kernel < 6.11.10 - Use-After-Free in DRM AMD Display DML Context Handling
CVSS 7.8
CVE-2024-12107 HIGH
uD3TN - Denial of Service via Double-Free in BPv7 Endpoint Identifier
CVSS 7.5
CVE-2024-35368 CRITICAL
FFmpeg n7.0 - Double Free in rkmpp_retrieve_frame
CVSS 9.8
CVE-2024-11704 CRITICAL
Firefox < 133 and ESR < 128.7 - Use-After-Free in sec_pkcs7_decoder_start_decrypt
CVSS 9.8
CVE-2024-50276 HIGH
Linux Kernel 5.17-6.1.117, 6.2-6.6.61, 6.7-6.11.8 - Double Free in mse102x_tx_frame_spi
CVSS 7.8
CVE-2024-10934 CRITICAL
OpenBSD < 7.4 - Double Free in NFS Client and Server Implementation
CVSS 9.8
CVE-2024-47426 HIGH
Adobe Substance 3D Painter <=10.1.0 - Double Free Code Execution
CVSS 7.8
CVE-2024-49014 HIGH
SQL Server 2016, 2017, 2019 - Remote Code Execution via Double Free
CVSS 8.8
CVE-2024-43640 HIGH
Windows 10/11, Server 2022 Elevation of Privilege via Kernel-Mode Driver Double Free
CVSS 7.8
CVE-2024-43447 HIGH
Windows Server 2022 < 10.0.20348.2849 - Remote Code Execution via SMBv3 Server Double Free
CVSS 8.1
CVE-2024-50235 HIGH
Linux Kernel 6.1.57-6.1.115 - Use-After-Free in WiFi cfg80211 CQM Configuration
CVSS 7.8
CVE-2024-50215 HIGH
Linux Kernel 6.0-6.1.115, 6.2-6.6.59, 6.7-6.11.6 - Use-After-Free in NVMe Target Authentication
CVSS 7.8
CVE-2024-50159 HIGH
Linux Kernel 6.3-6.6.59 6.7-6.11.6 - Use-After-Free in SCSI DebugFS Setup
CVSS 7.8
CVE-2024-50152 MEDIUM
Linux Kernel - Use-After-Free in SMB2 Extended Attribute Handling
CVSS 5.5
Details
Vulnerabilities 823
Exploit Likelihood High