Skip to main content

CWE archive

CWE-415 CVEs

Programmatic archive

818 CVEs tagged with CWE-415105 Critical, 519 High, 178 Medium, 16 Low, 0 Unrated.

CVE-2024-50276

Published Nov 19, 2024

In the Linux kernel, the following vulnerability has been resolved: net: vertexcom: mse102x: Fix possible double free of TX skb The scope of the TX skb is wider than just mse102…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10934

Published Nov 15, 2024

In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in…

CVSS 9.2 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-47426

Published Nov 12, 2024

Substance3D - Painter versions 10.1.0 and earlier are affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exp…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50235

Published Nov 9, 2024

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: clear wdev->cqm_config pointer on free When we free wdev->cqm_config when unregistering, we a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50215

Published Nov 9, 2024

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: assign dh_key to NULL after kfree_sensitive ctrl->dh_key might be used across multiple calls to n…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50159

Published Nov 7, 2024

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix the double free in scmi_debugfs_common_setup() Clang static checker(scan-build) throw…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50152

Published Nov 7, 2024

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix possible double free in smb2_set_ea() Clang static checker(scan-build) warning: fs/smb/clien…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47404

Published Nov 5, 2024

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3935

Published Oct 30, 2024

In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming to…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50071

Published Oct 29, 2024

In the Linux kernel, the following vulnerability has been resolved: pinctrl: nuvoton: fix a double free in ma35_pinctrl_dt_node_to_map_func() 'new_map' is allocated using devm_*…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-44098

Published Oct 25, 2024

In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free. This could lead to local escalation of privilege with no a…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50055

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: driver core: bus: Fix double free in driver API bus_register() For bus_register(), any error which happens af…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-49989

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix double free issue during amdgpu module unload Flexible endpoints use DIGs from available…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-49983

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: ext4: drop ppath from ext4_ext_replay_update_ex() to avoid double-free When calling ext4_force_split_extent_a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-49882

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: ext4: fix double brelse() the buffer of the extents path In ext4_ext_try_to_merge_up(), set path[1].p_bh to N…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-49853

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix double free in OPTEE transport Channels can be shared between protocols, avoid freein…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3187

Published Oct 17, 2024

This issue tracks two CWE-416 Use After Free (UAF) and one CWE-415 Double Free vulnerabilities in Goahead versions <= 6.0.0. These are caused by JST values not being nulled when f…

CVSS 5.9 · Medium

CVE-2024-45402

Published Oct 11, 2024

Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsing a spoofed TLS handshake message, picotls (specifically,…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46741

Published Sep 18, 2024

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix double free of 'buf' in error path smatch warning: drivers/misc/fastrpc.c:1926 fastrpc_req…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 251-275 of 818 CVEsPage 11 of 33