CWE-415 · 839 записей
Double Free
CVE этого класса
839 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
76На этой неделе | CVE-2018-4990Готовый эксплойт | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free adobe · acrobat dc · CWE-415 | Высокая8,8 | KEV | 36,2 % | 9 июл. 2018 г. |
72На этой неделе | CVE-2014-0502Готовый эксплойт | Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and badobe · flash player · CWE-415 | Высокая8,8 | KEV | 24,8 % | 21 февр. 2014 г. |
69На этой неделе | CVE-2026-33824Готовый эксплойт | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-415 | Критическая9,8 | KEV | 1,6 % | 14 апр. 2026 г. |
66На этой неделе | CVE-2018-0101Proof of concept | A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an ucisco · adaptive security appliance software · CWE-415 | Критическая10,0 | — | 86,8 % | 29 янв. 2018 г. |
65На этой неделе | CVE-2003-0545Эксплойта нет | Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code openssl · openssl · CWE-415 | Критическая9,8 | — | 87,5 % | 17 нояб. 2003 г. |
61На этой неделе | CVE-2020-9859Готовый эксплойт | A memory consumption issue was addressed with improved memory handling.apple · ipados · CWE-415 | Высокая7,8 | KEV | 0,8 % | 5 июн. 2020 г. |
60На этой неделе | CVE-2021-22600Готовый эксплойт | Double Free in net/packet/af_packet.c leading to priviledge escalationnetapp · 8300 firmware · CWE-415 | Высокая7,0 | KEV | 6,5 % | 26 янв. 2022 г. |
53В плане | CVE-2023-25136Proof of concept | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.openbsd · openssh · CWE-415 | Средняя6,5 | — | 89,7 % | 3 февр. 2023 г. |
51В плане | CVE-2018-5379Эксплойта нет | The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing clustquagga · quagga · CWE-415 | Критическая9,8 | — | 38,5 % | 19 февр. 2018 г. |
50В плане | CVE-2026-23918Proof of concept | Apache HTTP Server: http2: double free and possible RCE on early resetapache · http server · CWE-415 | Высокая8,8 | — | 49,7 % | 4 мая 2026 г. |
49В плане | CVE-2017-5334Эксплойта нет | Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackergnu · gnutls · CWE-415 | Критическая9,8 | — | 32,8 % | 24 мар. 2017 г. |
48В плане | CVE-2019-11932Proof of concept | A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in Wwhatsapp · whatsapp · CWE-415 | Высокая8,8 | — | 44,5 % | 3 окт. 2019 г. |
45В плане | CVE-2006-5051Proof of concept | Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitopenbsd · openssh · CWE-415 | Высокая8,1 | — | 45,0 % | 27 сент. 2006 г. |
43В плане | CVE-2019-8044Proof of concept | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earadobe · acrobat dc · CWE-415 | Критическая9,8 | — | 14,5 % | 20 авг. 2019 г. |
43В плане | CVE-2016-3132Эксплойта нет | Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attacphp · php · CWE-415 | Критическая9,8 | — | 11,7 % | 7 авг. 2016 г. |
42В плане | CVE-2018-12782Эксплойта нет | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Double Free adobe · acrobat dc · CWE-415 | Критическая9,8 | — | 11,0 % | 20 июл. 2018 г. |
42В плане | CVE-2005-1689Эксплойта нет | Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrmit · kerberos 5 · CWE-415 | Критическая9,8 | — | 11,0 % | 18 июл. 2005 г. |
42В плане | CVE-2002-0059Эксплойта нет | The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certaizlib · zlib · CWE-415 | Критическая9,8 | — | 9,7 % | 15 мар. 2002 г. |
42В плане | CVE-2016-5772Эксплойта нет | Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, aphp · php · CWE-415 | Критическая9,8 | — | 9,7 % | 7 авг. 2016 г. |
42В плане | CVE-2016-5768Эксплойта нет | Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5php · php · CWE-415 | Критическая9,8 | — | 9,6 % | 7 авг. 2016 г. |
41В плане | CVE-2014-0301Эксплойта нет | Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windowmicrosoft · windows 7 · CWE-415 | Критическая9,3 | — | 14,0 % | 12 мар. 2014 г. |
41В плане | CVE-2019-5481Эксплойта нет | Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.haxx · curl · CWE-415 | Критическая9,8 | — | 7,5 % | 16 сент. 2019 г. |
41В плане | CVE-2022-20127Эксплойта нет | In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free.google · android · CWE-415 | Критическая9,8 | — | 7,0 % | 15 июн. 2022 г. |
41В плане | CVE-2004-0772Эксплойта нет | Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execmit · kerberos 5 · CWE-415 | Критическая9,8 | — | 7,0 % | 20 окт. 2004 г. |
41В плане | CVE-2019-7784Эксплойта нет | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earadobe · acrobat dc · CWE-415 | Критическая9,8 | — | 6,6 % | 22 мая 2019 г. |
- CVE-2018-499076На этой неделе
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 36 %adobe · acrobat dc9 июл. 2018 г.
- CVE-2014-050272На этой неделе
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and b
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 25 %adobe · flash player21 февр. 2014 г.
- CVE-2026-3382469На этой неделе
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 2 %microsoft · windows 10 160714 апр. 2026 г.
- CVE-2018-010166На этой неделе
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an u
КритическаяCVSS 10,0Proof of conceptEPSS 87 %cisco · adaptive security appliance software29 янв. 2018 г.
- CVE-2003-054565На этой неделе
Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code
КритическаяCVSS 9,8Эксплойта нетEPSS 87 %openssl · openssl17 нояб. 2003 г.
- CVE-2020-985961На этой неделе
A memory consumption issue was addressed with improved memory handling.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 1 %apple · ipados5 июн. 2020 г.
- CVE-2021-2260060На этой неделе
Double Free in net/packet/af_packet.c leading to priviledge escalation
ВысокаяCVSS 7,0KEVГотовый эксплойтEPSS 7 %netapp · 8300 firmware26 янв. 2022 г.
- CVE-2023-2513653В плане
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.
СредняяCVSS 6,5Proof of conceptEPSS 90 %openbsd · openssh3 февр. 2023 г.
- CVE-2018-537951В плане
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing clust
КритическаяCVSS 9,8Эксплойта нетEPSS 38 %quagga · quagga19 февр. 2018 г.
- CVE-2026-2391850В плане
Apache HTTP Server: http2: double free and possible RCE on early reset
ВысокаяCVSS 8,8Proof of conceptEPSS 50 %apache · http server4 мая 2026 г.
- CVE-2017-533449В плане
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attacker
КритическаяCVSS 9,8Эксплойта нетEPSS 33 %gnu · gnutls24 мар. 2017 г.
- CVE-2019-1193248В плане
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in W
ВысокаяCVSS 8,8Proof of conceptEPSS 45 %whatsapp · whatsapp3 окт. 2019 г.
- CVE-2006-505145В плане
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbit
ВысокаяCVSS 8,1Proof of conceptEPSS 45 %openbsd · openssh27 сент. 2006 г.
- CVE-2019-804443В плане
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and ear
КритическаяCVSS 9,8Proof of conceptEPSS 14 %adobe · acrobat dc20 авг. 2019 г.
- CVE-2016-313243В плане
Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attac
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %php · php7 авг. 2016 г.
- CVE-2018-1278242В плане
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Double Free
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %adobe · acrobat dc20 июл. 2018 г.
- CVE-2005-168942В плане
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitr
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %mit · kerberos 518 июл. 2005 г.
- CVE-2002-005942В плане
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certai
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %zlib · zlib15 мар. 2002 г.
- CVE-2016-577242В плане
Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, a
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %php · php7 авг. 2016 г.
- CVE-2016-576842В плане
Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %php · php7 авг. 2016 г.
- CVE-2014-030141В плане
Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Window
КритическаяCVSS 9,3Эксплойта нетEPSS 14 %microsoft · windows 712 мар. 2014 г.
- CVE-2019-548141В плане
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %haxx · curl16 сент. 2019 г.
- CVE-2022-2012741В плане
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %google · android15 июн. 2022 г.
- CVE-2004-077241В плане
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to exec
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %mit · kerberos 520 окт. 2004 г.
- CVE-2019-778441В плане
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and ear
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %adobe · acrobat dc22 мая 2019 г.