Skip to main content

CWE archive

CWE-415 CVEs

Programmatic archive

818 CVEs tagged with CWE-415105 Critical, 519 High, 178 Medium, 16 Low, 0 Unrated.

CVE-2018-9356

Published Nov 6, 2018

In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. This could lead to remote code execution with no additional execution privileges n…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-18718

Published Oct 29, 2018

An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c because of two successive calls of g…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18297

Published Oct 23, 2018

Double memory free while closing TEE SE API Session management in Snapdragon Mobile in version SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820.

CVSS 7.8 · High

CVE-2018-0469

Published Oct 5, 2018

A vulnerability in the web user interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9513

Published Oct 2, 2018

In copy_process of fork.c, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges neede…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11840

Published Sep 18, 2018

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the WLAN driver command ioctl a temporary buffer used…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11276

Published Sep 18, 2018

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, double free of memory allocation is possible in Kernel when it explicit…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11273

Published Sep 18, 2018

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, 'voice_svc_dev' is allocated as a device-managed resource. If error 'cd…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11270

Published Sep 18, 2018

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, memory allocated with devm_kzalloc is automatically released by the ker…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17097

Published Sep 16, 2018

The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (double free) or possibly have unspecified other impact…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14638

Published Sep 14, 2018

A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpecte…

CVSS 7.5 · High

CVE-2018-16425

Published Sep 4, 2018

A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-hsm.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supp…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16424

Published Sep 4, 2018

A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartc…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16423

Published Sep 4, 2018

A double free when handling responses from a smartcard in sc_file_set_sec_attr in libopensc/sc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smar…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000216

Published Aug 20, 2018

Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be explo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8619

Published Aug 1, 2018

The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-8618

Published Jul 31, 2018

The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplication, on systems using 32 bit `…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 676-700 of 818 CVEsPage 28 of 33