CWE-415 · 839 kayıt
Double Free
Bu sınıftaki CVE’ler
839 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
76Bu hafta | CVE-2018-4990Silahlaştırılmış | Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free adobe · acrobat dc · CWE-415 | Yüksek8,8 | KEV | %36,2 | 9 Tem 2018 |
72Bu hafta | CVE-2014-0502Silahlaştırılmış | Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and badobe · flash player · CWE-415 | Yüksek8,8 | KEV | %24,8 | 21 Şub 2014 |
69Bu hafta | CVE-2026-33824Silahlaştırılmış | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-415 | Kritik9,8 | KEV | %1,6 | 14 Nis 2026 |
66Bu hafta | CVE-2018-0101Kavram kanıtı | A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an ucisco · adaptive security appliance software · CWE-415 | Kritik10,0 | — | %86,8 | 29 Oca 2018 |
65Bu hafta | CVE-2003-0545İstismar yok | Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code openssl · openssl · CWE-415 | Kritik9,8 | — | %87,5 | 17 Kas 2003 |
61Bu hafta | CVE-2020-9859Silahlaştırılmış | A memory consumption issue was addressed with improved memory handling.apple · ipados · CWE-415 | Yüksek7,8 | KEV | %0,8 | 5 Haz 2020 |
60Bu hafta | CVE-2021-22600Silahlaştırılmış | Double Free in net/packet/af_packet.c leading to priviledge escalationnetapp · 8300 firmware · CWE-415 | Yüksek7,0 | KEV | %6,5 | 26 Oca 2022 |
53Planlayın | CVE-2023-25136Kavram kanıtı | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.openbsd · openssh · CWE-415 | Orta6,5 | — | %89,7 | 3 Şub 2023 |
51Planlayın | CVE-2018-5379İstismar yok | The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing clustquagga · quagga · CWE-415 | Kritik9,8 | — | %38,5 | 19 Şub 2018 |
50Planlayın | CVE-2026-23918Kavram kanıtı | Apache HTTP Server: http2: double free and possible RCE on early resetapache · http server · CWE-415 | Yüksek8,8 | — | %49,7 | 4 May 2026 |
49Planlayın | CVE-2017-5334İstismar yok | Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackergnu · gnutls · CWE-415 | Kritik9,8 | — | %32,8 | 24 Mar 2017 |
48Planlayın | CVE-2019-11932Kavram kanıtı | A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in Wwhatsapp · whatsapp · CWE-415 | Yüksek8,8 | — | %44,5 | 3 Eki 2019 |
45Planlayın | CVE-2006-5051Kavram kanıtı | Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitopenbsd · openssh · CWE-415 | Yüksek8,1 | — | %45,0 | 27 Eyl 2006 |
43Planlayın | CVE-2019-8044Kavram kanıtı | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earadobe · acrobat dc · CWE-415 | Kritik9,8 | — | %14,5 | 20 Ağu 2019 |
43Planlayın | CVE-2016-3132İstismar yok | Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attacphp · php · CWE-415 | Kritik9,8 | — | %11,7 | 7 Ağu 2016 |
42Planlayın | CVE-2018-12782İstismar yok | Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Double Free adobe · acrobat dc · CWE-415 | Kritik9,8 | — | %11,0 | 20 Tem 2018 |
42Planlayın | CVE-2005-1689İstismar yok | Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrmit · kerberos 5 · CWE-415 | Kritik9,8 | — | %11,0 | 18 Tem 2005 |
42Planlayın | CVE-2002-0059İstismar yok | The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certaizlib · zlib · CWE-415 | Kritik9,8 | — | %9,7 | 15 Mar 2002 |
42Planlayın | CVE-2016-5772İstismar yok | Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, aphp · php · CWE-415 | Kritik9,8 | — | %9,7 | 7 Ağu 2016 |
42Planlayın | CVE-2016-5768İstismar yok | Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5php · php · CWE-415 | Kritik9,8 | — | %9,6 | 7 Ağu 2016 |
41Planlayın | CVE-2014-0301İstismar yok | Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windowmicrosoft · windows 7 · CWE-415 | Kritik9,3 | — | %14,0 | 12 Mar 2014 |
41Planlayın | CVE-2019-5481İstismar yok | Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.haxx · curl · CWE-415 | Kritik9,8 | — | %7,5 | 16 Eyl 2019 |
41Planlayın | CVE-2022-20127İstismar yok | In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free.google · android · CWE-415 | Kritik9,8 | — | %7,0 | 15 Haz 2022 |
41Planlayın | CVE-2004-0772İstismar yok | Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execmit · kerberos 5 · CWE-415 | Kritik9,8 | — | %7,0 | 20 Eki 2004 |
41Planlayın | CVE-2019-7784İstismar yok | Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earadobe · acrobat dc · CWE-415 | Kritik9,8 | — | %6,6 | 22 May 2019 |
- CVE-2018-499076Bu hafta
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %36adobe · acrobat dc9 Tem 2018
- CVE-2014-050272Bu hafta
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and b
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %25adobe · flash player21 Şub 2014
- CVE-2026-3382469Bu hafta
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %2microsoft · windows 10 160714 Nis 2026
- CVE-2018-010166Bu hafta
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an u
KritikCVSS 10,0Kavram kanıtıEPSS %87cisco · adaptive security appliance software29 Oca 2018
- CVE-2003-054565Bu hafta
Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code
KritikCVSS 9,8İstismar yokEPSS %87openssl · openssl17 Kas 2003
- CVE-2020-985961Bu hafta
A memory consumption issue was addressed with improved memory handling.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %1apple · ipados5 Haz 2020
- CVE-2021-2260060Bu hafta
Double Free in net/packet/af_packet.c leading to priviledge escalation
YüksekCVSS 7,0KEVSilahlaştırılmışEPSS %7netapp · 8300 firmware26 Oca 2022
- CVE-2023-2513653Planlayın
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.
OrtaCVSS 6,5Kavram kanıtıEPSS %90openbsd · openssh3 Şub 2023
- CVE-2018-537951Planlayın
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing clust
KritikCVSS 9,8İstismar yokEPSS %38quagga · quagga19 Şub 2018
- CVE-2026-2391850Planlayın
Apache HTTP Server: http2: double free and possible RCE on early reset
YüksekCVSS 8,8Kavram kanıtıEPSS %50apache · http server4 May 2026
- CVE-2017-533449Planlayın
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attacker
KritikCVSS 9,8İstismar yokEPSS %33gnu · gnutls24 Mar 2017
- CVE-2019-1193248Planlayın
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in W
YüksekCVSS 8,8Kavram kanıtıEPSS %45whatsapp · whatsapp3 Eki 2019
- CVE-2006-505145Planlayın
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbit
YüksekCVSS 8,1Kavram kanıtıEPSS %45openbsd · openssh27 Eyl 2006
- CVE-2019-804443Planlayın
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and ear
KritikCVSS 9,8Kavram kanıtıEPSS %14adobe · acrobat dc20 Ağu 2019
- CVE-2016-313243Planlayın
Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attac
KritikCVSS 9,8İstismar yokEPSS %12php · php7 Ağu 2016
- CVE-2018-1278242Planlayın
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Double Free
KritikCVSS 9,8İstismar yokEPSS %11adobe · acrobat dc20 Tem 2018
- CVE-2005-168942Planlayın
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitr
KritikCVSS 9,8İstismar yokEPSS %11mit · kerberos 518 Tem 2005
- CVE-2002-005942Planlayın
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certai
KritikCVSS 9,8İstismar yokEPSS %10zlib · zlib15 Mar 2002
- CVE-2016-577242Planlayın
Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, a
KritikCVSS 9,8İstismar yokEPSS %10php · php7 Ağu 2016
- CVE-2016-576842Planlayın
Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5
KritikCVSS 9,8İstismar yokEPSS %10php · php7 Ağu 2016
- CVE-2014-030141Planlayın
Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Window
KritikCVSS 9,3İstismar yokEPSS %14microsoft · windows 712 Mar 2014
- CVE-2019-548141Planlayın
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
KritikCVSS 9,8İstismar yokEPSS %7haxx · curl16 Eyl 2019
- CVE-2022-2012741Planlayın
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free.
KritikCVSS 9,8İstismar yokEPSS %7google · android15 Haz 2022
- CVE-2004-077241Planlayın
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to exec
KritikCVSS 9,8İstismar yokEPSS %7mit · kerberos 520 Eki 2004
- CVE-2019-778441Planlayın
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and ear
KritikCVSS 9,8İstismar yokEPSS %7adobe · acrobat dc22 May 2019