Skip to main content

CWE archive

CWE-415 CVEs

Programmatic archive

819 CVEs tagged with CWE-415105 Critical, 520 High, 178 Medium, 16 Low, 0 Unrated.

CVE-2021-4091

Published Feb 18, 2022

A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to…

CVSS 7.5 · High

CVE-2021-22600

Published Jan 26, 2022

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upg…

CVSS 6.6 · Medium
evidence mentions
4
Buzz score
52.6
KEV listed

CVE-2021-40574

Published Jan 13, 2022

The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in load_text.c, which allows attackers to cause a denia…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40573

Published Jan 13, 2022

The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows attackers to cause a denial of service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40572

Published Jan 13, 2022

The binary MP4Box in Gpac 1.0.1 has a double-free bug in the av1dmx_finalize function in reframe_av1.c, which allows attackers to cause a denial of service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40571

Published Jan 13, 2022

The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which allows attackers to cause a denial of service, even code e…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40570

Published Jan 13, 2022

The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avc_compute_poc function in av_parsers.c, which allows attackers to cause a denial of service, even code exe…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40569

Published Jan 13, 2022

The binary MP4Box in Gpac through 1.0.1 has a double-free vulnerability in the iloc_entry_del funciton in box_code_meta.c, which allows attackers to cause a denial of service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37120

Published Jan 3, 2022

There is a Double free vulnerability in Smartphone.Successful exploitation of this vulnerability may cause a kernel crash or privilege escalation.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45288

Published Dec 21, 2021

A Double Free vulnerability exists in filedump.c in GPAC 1.0.1, which could cause a Denail of Service via a crafted file in the MP4Box command.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37072

Published Dec 7, 2021

There is a Incorrect Calculation of Buffer Size vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to memory crash.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43268

Published Nov 24, 2021

An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to reading beyond the end of a buffer, or a double free.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1119

Published Oct 29, 2021

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can double-free a pointer, which may lead to denial of service. This flaw may resu…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21797

Published Oct 18, 2021

An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be sto…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-34769

Published Sep 23, 2021

Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Co…

CVSS 8.6 · High

CVE-2021-34768

Published Sep 23, 2021

Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Co…

CVSS 8.6 · High
Showing 476-500 of 819 CVEsPage 20 of 33