Skip to main content

CWE archive

CWE-415 CVEs

Programmatic archive

821 CVEs tagged with CWE-415105 Critical, 522 High, 178 Medium, 16 Low, 0 Unrated.

CVE-2023-21500

Published May 4, 2023

Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29469

Published Apr 24, 2023

An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4744

Published Mar 30, 2023

A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGIST…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27537

Published Mar 30, 2023

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing acro…

CVSS 5.9 · Medium

CVE-2023-25801

Published Mar 25, 2023

TensorFlow is an open source machine learning platform. Prior to versions 2.12.0 and 2.11.1, `nn_ops.fractional_avg_pool_v2` and `nn_ops.fractional_max_pool_v2` require the first…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-21030

Published Mar 24, 2023

In Confirmation of keystore_cli_v2.cpp, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege in an unprivileged process…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1449

Published Mar 17, 2023

A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function gf_av1_reset_state of the file media_…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26545

Published Feb 25, 2023

In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renam…

CVSS 4.7 · Medium

CVE-2022-20803

Published Feb 17, 2023

A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unauthenticated, remote attacker to cause a denial of service co…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40683

Published Feb 16, 2023

A double free in Fortinet FortiWeb version 7.0.0 through 7.0.3 may allows attacker to execute unauthorized code or commands via specially crafted commands

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-33304

Published Feb 15, 2023

Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allows attackers to execute arbitr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-25136

Published Feb 3, 2023

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unau…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2022-3806

Published Jan 25, 2023

Inconsistent handling of error cases in bluetooth hci may lead to a double free condition of a network buffer.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-44640

Published Dec 25, 2022

Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 401-425 of 821 CVEsPage 17 of 33