Skip to main content

CWE archive

CWE-415 CVEs

Programmatic archive

823 CVEs tagged with CWE-415105 Critical, 523 High, 179 Medium, 16 Low, 0 Unrated.

CVE-2026-55995

Published Jul 29, 2026

A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c053414…

CVSS 8.7 · High
evidence mentions
2

CVE-2026-17573

Published Jul 27, 2026

A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to a…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-66373

Published Jul 25, 2026

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry)…

CVSS 7.5 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-66032

Published Jul 24, 2026

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the h…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-43823

Published Jul 23, 2026

When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64832

Published Jul 22, 2026

FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corrup…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-64621

Published Jul 20, 2026

FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the sel…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-13713

Published Jul 16, 2026

YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the bundled libsyck, when an an…

CVSS 6.2 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-12659

Published Jul 14, 2026

A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets s…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-15667

Published Jul 6, 2026

A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrite of the file src/isomedia/avc_ext.c of the component MP4Bo…

CVSS 1.9 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-14604

Published Jul 3, 2026

A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporter::ExportToBlob of the file code/AssetLib/Ply/PlyLoader.cpp…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-8925

Published Jul 3, 2026

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
39.5
Vendor/product tagsBeta · best-effort

CVE-2026-58381

Published Jul 2, 2026

A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2026-10653

Published Jun 30, 2026

The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and the per-data-block ref_count at the start of each variable/h…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-14164

Published Jun 30, 2026

A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being free…

CVSS 7.5 · High
evidence mentions
6
Buzz score
36.0

CVE-2026-43706

Published Jun 29, 2026

A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5…

CVSS 6.5 · Medium
evidence mentions
8
Buzz score
32.0
Vendor/product tagsBeta · best-effort

CVE-2026-53322

Published Jun 26, 2026

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs before disabling function On device shutdown, make vfio_pci_core_close_device() ca…

CVSS 8.8 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-53294

Published Jun 26, 2026

In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: don't free the reused channel The RX channel can be aliased to the TX channel if it ha…

CVSS 7.8 · High
evidence mentions
9
Buzz score
33.0
Vendor/product tagsBeta · best-effort

CVE-2026-53286

Published Jun 26, 2026

In the Linux kernel, the following vulnerability has been resolved: idpf: fix double free and use-after-free in aux device error paths When auxiliary_device_add() fails in idpf_…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-53233

Published Jun 25, 2026

In the Linux kernel, the following vulnerability has been resolved: netdev: fix double-free in netdev_nl_bind_rx_doit() Sashiko flags that genlmsg_reply() always consumes the sk…

CVSS 7.8 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-53067

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: pci-ep-msi: Fix error unwind and prevent double alloc pci_epf_alloc_doorbell() stores the allo…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 823 CVEsPage 1 of 33