Skip to content
Noroxi

CWE-415 · 839 records

Double Free

CVEs in this class

839 records

  • CVE-2018-4990
    76This week

    Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free

    HighCVSS 8.8KEVWeaponizedEPSS 36%

    adobe · acrobat dcJul 9, 2018

  • CVE-2014-0502
    72This week

    Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and b

    HighCVSS 8.8KEVWeaponizedEPSS 25%

    adobe · flash playerFeb 21, 2014

  • CVE-2026-33824
    69This week

    Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 2%

    microsoft · windows 10 1607Apr 14, 2026

  • CVE-2018-0101
    66This week

    A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an u

    CriticalCVSS 10.0Proof of conceptEPSS 87%

    cisco · adaptive security appliance softwareJan 29, 2018

  • CVE-2003-0545
    65This week

    Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code

    CriticalCVSS 9.8No exploitEPSS 87%

    openssl · opensslNov 17, 2003

  • CVE-2020-9859
    61This week

    A memory consumption issue was addressed with improved memory handling.

    HighCVSS 7.8KEVWeaponizedEPSS 1%

    apple · ipadosJun 5, 2020

  • CVE-2021-22600
    60This week

    Double Free in net/packet/af_packet.c leading to priviledge escalation

    HighCVSS 7.0KEVWeaponizedEPSS 7%

    netapp · 8300 firmwareJan 26, 2022

  • OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.

    MediumCVSS 6.5Proof of conceptEPSS 90%

    openbsd · opensshFeb 3, 2023

  • The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing clust

    CriticalCVSS 9.8No exploitEPSS 38%

    quagga · quaggaFeb 19, 2018

  • Apache HTTP Server: http2: double free and possible RCE on early reset

    HighCVSS 8.8Proof of conceptEPSS 50%

    apache · http serverMay 4, 2026

  • Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attacker

    CriticalCVSS 9.8No exploitEPSS 33%

    gnu · gnutlsMar 24, 2017

  • A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in W

    HighCVSS 8.8Proof of conceptEPSS 45%

    whatsapp · whatsappOct 3, 2019

  • Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbit

    HighCVSS 8.1Proof of conceptEPSS 45%

    openbsd · opensshSep 27, 2006

  • Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and ear

    CriticalCVSS 9.8Proof of conceptEPSS 14%

    adobe · acrobat dcAug 20, 2019

  • Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attac

    CriticalCVSS 9.8No exploitEPSS 12%

    php · phpAug 7, 2016

  • Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Double Free

    CriticalCVSS 9.8No exploitEPSS 11%

    adobe · acrobat dcJul 20, 2018

  • Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitr

    CriticalCVSS 9.8No exploitEPSS 11%

    mit · kerberos 5Jul 18, 2005

  • The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certai

    CriticalCVSS 9.8No exploitEPSS 10%

    zlib · zlibMar 15, 2002

  • Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, a

    CriticalCVSS 9.8No exploitEPSS 10%

    php · phpAug 7, 2016

  • Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5

    CriticalCVSS 9.8No exploitEPSS 10%

    php · phpAug 7, 2016

  • Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Window

    CriticalCVSS 9.3No exploitEPSS 14%

    microsoft · windows 7Mar 12, 2014

  • Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

    CriticalCVSS 9.8No exploitEPSS 7%

    haxx · curlSep 16, 2019

  • In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free.

    CriticalCVSS 9.8No exploitEPSS 7%

    google · androidJun 15, 2022

  • Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to exec

    CriticalCVSS 9.8No exploitEPSS 7%

    mit · kerberos 5Oct 20, 2004

  • Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and ear

    CriticalCVSS 9.8No exploitEPSS 7%

    adobe · acrobat dcMay 22, 2019

All vulnerability classes