Skip to main content

CWE archive

CWE-415 CVEs

Programmatic archive

821 CVEs tagged with CWE-415105 Critical, 522 High, 178 Medium, 16 Low, 0 Unrated.

CVE-2022-3238

Published Nov 14, 2022

A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42915

Published Oct 29, 2022

curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNE…

CVSS 8.1 · High

CVE-2022-3595

Published Oct 18, 2022

A vulnerability was found in Linux Kernel. It has been rated as problematic. Affected by this issue is the function sess_free_buffer of the file fs/cifs/sess.c of the component CI…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-0699

Published Oct 17, 2022

A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-5797

Published Sep 29, 2022

Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36043

Published Sep 6, 2022

Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to a double free in bobj.c:rz_bin_reloc_storage_free() when fr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27794

Published Aug 19, 2022

A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modification of unexpected memory locations and potentially causing a…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-23459

Published Aug 19, 2022

Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value class may lead to memory corruption via a double free or via a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31614

Published Aug 5, 2022

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it may double-free some resources. An attacker may exploit this vulnerability with oth…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27864

Published Jul 29, 2022

A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affected installations. User interaction is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36234

Published Jul 28, 2022

SimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnerability which is exploited via crafted TCP packets.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2008

Published Jul 28, 2022

Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-2327

Published Jul 22, 2022

io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some ope…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 426-450 of 821 CVEsPage 18 of 33