Skip to main content

CWE archive

CWE-415 CVEs

Programmatic archive

821 CVEs tagged with CWE-415105 Critical, 522 High, 178 Medium, 16 Low, 0 Unrated.

CVE-2021-47082

Published Mar 4, 2024

In the Linux kernel, the following vulnerability has been resolved: tun: avoid double free in tun_free_netdev Avoid double free in tun_free_netdev() by moving the dev->tstats an…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-46979

Published Feb 28, 2024

In the Linux kernel, the following vulnerability has been resolved: iio: core: fix ioctl handlers removal Currently ioctl handlers are removed twice. For the first time during i…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36785

Published Feb 28, 2024

In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27099

Published Feb 27, 2024

The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` failed state, may cause a double free problem. This may caus…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-46938

Published Feb 27, 2024

In the Linux kernel, the following vulnerability has been resolved: dm rq: fix double free of blk_mq_tag_set in dev remove after table load fails When loading a device-mapper ta…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52439

Published Feb 20, 2024

In the Linux kernel, the following vulnerability has been resolved: uio: Fix use-after-free in uio_open core-1 core-2 -------------------------------------------------------…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38562

Published Feb 20, 2024

A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead to me…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1032

Published Jan 8, 2024

The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2588

Published Jan 8, 2024

It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2023-52284

Published Dec 31, 2023

Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49937

Published Dec 14, 2023

An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a denial of service or possibly execute arbitrary code. The f…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-41678

Published Dec 13, 2023

A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40103

Published Dec 4, 2023

In multiple locations, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege with no additional execution privileges nee…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48013

Published Nov 15, 2023

GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a double free via the gf_filterpacket_del function at /gpac/src/filter_core/filter.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43281

Published Oct 25, 2023

Double Free vulnerability in Nothings Stb Image.h v.2.28 allows a remote attacker to cause a denial of service via a crafted file to the stbi_load_gif_main function.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45679

Published Oct 21, 2023

stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in `start_decoder`. In that case the functio…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45666

Published Oct 21, 2023

stb_image is a single file MIT licensed library for processing images. It may look like `stbi__load_gif_main` doesn’t give guarantees about the content of output value `*delays`…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45664

Published Oct 21, 2023

stb_image is a single file MIT licensed library for processing images. A crafted image file can trigger `stbi__load_gif_main_outofmem` attempt to double-free the out variable. Thi…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-42459

Published Oct 16, 2023

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). In affected versions specific DATA submessages can be sent t…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort
Showing 351-375 of 821 CVEsPage 15 of 33