CWE-415 · 839 records
Double Free
CVEs in this class
839 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
76This week | CVE-2018-4990Weaponized | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free adobe · acrobat dc · CWE-415 | High8.8 | KEV | 36.2% | Jul 9, 2018 |
72This week | CVE-2014-0502Weaponized | Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and badobe · flash player · CWE-415 | High8.8 | KEV | 24.8% | Feb 21, 2014 |
69This week | CVE-2026-33824Weaponized | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-415 | Critical9.8 | KEV | 1.6% | Apr 14, 2026 |
66This week | CVE-2018-0101Proof of concept | A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an ucisco · adaptive security appliance software · CWE-415 | Critical10.0 | — | 86.8% | Jan 29, 2018 |
65This week | CVE-2003-0545No exploit | Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code openssl · openssl · CWE-415 | Critical9.8 | — | 87.5% | Nov 17, 2003 |
61This week | CVE-2020-9859Weaponized | A memory consumption issue was addressed with improved memory handling.apple · ipados · CWE-415 | High7.8 | KEV | 0.8% | Jun 5, 2020 |
60This week | CVE-2021-22600Weaponized | Double Free in net/packet/af_packet.c leading to priviledge escalationnetapp · 8300 firmware · CWE-415 | High7.0 | KEV | 6.5% | Jan 26, 2022 |
53Plan | CVE-2023-25136Proof of concept | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.openbsd · openssh · CWE-415 | Medium6.5 | — | 89.7% | Feb 3, 2023 |
51Plan | CVE-2018-5379No exploit | The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing clustquagga · quagga · CWE-415 | Critical9.8 | — | 38.5% | Feb 19, 2018 |
50Plan | CVE-2026-23918Proof of concept | Apache HTTP Server: http2: double free and possible RCE on early resetapache · http server · CWE-415 | High8.8 | — | 49.7% | May 4, 2026 |
49Plan | CVE-2017-5334No exploit | Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackergnu · gnutls · CWE-415 | Critical9.8 | — | 32.8% | Mar 24, 2017 |
48Plan | CVE-2019-11932Proof of concept | A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in Wwhatsapp · whatsapp · CWE-415 | High8.8 | — | 44.5% | Oct 3, 2019 |
45Plan | CVE-2006-5051Proof of concept | Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitopenbsd · openssh · CWE-415 | High8.1 | — | 45.0% | Sep 27, 2006 |
43Plan | CVE-2019-8044Proof of concept | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earadobe · acrobat dc · CWE-415 | Critical9.8 | — | 14.5% | Aug 20, 2019 |
43Plan | CVE-2016-3132No exploit | Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attacphp · php · CWE-415 | Critical9.8 | — | 11.7% | Aug 7, 2016 |
42Plan | CVE-2018-12782No exploit | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Double Free adobe · acrobat dc · CWE-415 | Critical9.8 | — | 11.0% | Jul 20, 2018 |
42Plan | CVE-2005-1689No exploit | Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrmit · kerberos 5 · CWE-415 | Critical9.8 | — | 11.0% | Jul 18, 2005 |
42Plan | CVE-2002-0059No exploit | The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certaizlib · zlib · CWE-415 | Critical9.8 | — | 9.7% | Mar 15, 2002 |
42Plan | CVE-2016-5772No exploit | Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, aphp · php · CWE-415 | Critical9.8 | — | 9.7% | Aug 7, 2016 |
42Plan | CVE-2016-5768No exploit | Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5php · php · CWE-415 | Critical9.8 | — | 9.6% | Aug 7, 2016 |
41Plan | CVE-2014-0301No exploit | Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windowmicrosoft · windows 7 · CWE-415 | Critical9.3 | — | 14.0% | Mar 12, 2014 |
41Plan | CVE-2019-5481No exploit | Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.haxx · curl · CWE-415 | Critical9.8 | — | 7.5% | Sep 16, 2019 |
41Plan | CVE-2022-20127No exploit | In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free.google · android · CWE-415 | Critical9.8 | — | 7.0% | Jun 15, 2022 |
41Plan | CVE-2004-0772No exploit | Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execmit · kerberos 5 · CWE-415 | Critical9.8 | — | 7.0% | Oct 20, 2004 |
41Plan | CVE-2019-7784No exploit | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earadobe · acrobat dc · CWE-415 | Critical9.8 | — | 6.6% | May 22, 2019 |
- CVE-2018-499076This week
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free
HighCVSS 8.8KEVWeaponizedEPSS 36%adobe · acrobat dcJul 9, 2018
- CVE-2014-050272This week
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and b
HighCVSS 8.8KEVWeaponizedEPSS 25%adobe · flash playerFeb 21, 2014
- CVE-2026-3382469This week
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 2%microsoft · windows 10 1607Apr 14, 2026
- CVE-2018-010166This week
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an u
CriticalCVSS 10.0Proof of conceptEPSS 87%cisco · adaptive security appliance softwareJan 29, 2018
- CVE-2003-054565This week
Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code
CriticalCVSS 9.8No exploitEPSS 87%openssl · opensslNov 17, 2003
- CVE-2020-985961This week
A memory consumption issue was addressed with improved memory handling.
HighCVSS 7.8KEVWeaponizedEPSS 1%apple · ipadosJun 5, 2020
- CVE-2021-2260060This week
Double Free in net/packet/af_packet.c leading to priviledge escalation
HighCVSS 7.0KEVWeaponizedEPSS 7%netapp · 8300 firmwareJan 26, 2022
- CVE-2023-2513653Plan
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.
MediumCVSS 6.5Proof of conceptEPSS 90%openbsd · opensshFeb 3, 2023
- CVE-2018-537951Plan
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing clust
CriticalCVSS 9.8No exploitEPSS 38%quagga · quaggaFeb 19, 2018
- CVE-2026-2391850Plan
Apache HTTP Server: http2: double free and possible RCE on early reset
HighCVSS 8.8Proof of conceptEPSS 50%apache · http serverMay 4, 2026
- CVE-2017-533449Plan
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attacker
CriticalCVSS 9.8No exploitEPSS 33%gnu · gnutlsMar 24, 2017
- CVE-2019-1193248Plan
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in W
HighCVSS 8.8Proof of conceptEPSS 45%whatsapp · whatsappOct 3, 2019
- CVE-2006-505145Plan
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbit
HighCVSS 8.1Proof of conceptEPSS 45%openbsd · opensshSep 27, 2006
- CVE-2019-804443Plan
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and ear
CriticalCVSS 9.8Proof of conceptEPSS 14%adobe · acrobat dcAug 20, 2019
- CVE-2016-313243Plan
Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attac
CriticalCVSS 9.8No exploitEPSS 12%php · phpAug 7, 2016
- CVE-2018-1278242Plan
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Double Free
CriticalCVSS 9.8No exploitEPSS 11%adobe · acrobat dcJul 20, 2018
- CVE-2005-168942Plan
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitr
CriticalCVSS 9.8No exploitEPSS 11%mit · kerberos 5Jul 18, 2005
- CVE-2002-005942Plan
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certai
CriticalCVSS 9.8No exploitEPSS 10%zlib · zlibMar 15, 2002
- CVE-2016-577242Plan
Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, a
CriticalCVSS 9.8No exploitEPSS 10%php · phpAug 7, 2016
- CVE-2016-576842Plan
Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5
CriticalCVSS 9.8No exploitEPSS 10%php · phpAug 7, 2016
- CVE-2014-030141Plan
Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Window
CriticalCVSS 9.3No exploitEPSS 14%microsoft · windows 7Mar 12, 2014
- CVE-2019-548141Plan
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
CriticalCVSS 9.8No exploitEPSS 7%haxx · curlSep 16, 2019
- CVE-2022-2012741Plan
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free.
CriticalCVSS 9.8No exploitEPSS 7%google · androidJun 15, 2022
- CVE-2004-077241Plan
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to exec
CriticalCVSS 9.8No exploitEPSS 7%mit · kerberos 5Oct 20, 2004
- CVE-2019-778441Plan
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and ear
CriticalCVSS 9.8No exploitEPSS 7%adobe · acrobat dcMay 22, 2019