VulnSea

CWE-415

CVEs classified under CWE-415, newest first.

91 CVEsRSS

CVE-2026-17050Medium· 5.7
today

The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c)

The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c). On three failure paths — a fai…

Sunlitzephyrproject · zephyrvia NVD
CVE-2026-20135High· 8.6
5d ago

A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (Do…

A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (Do…

TwilightCisco · Cisco Secure Firewall Threat Defense (FTD) SoftwareEPSS 0.46%via NVD
CVE-2026-84561Critical· 9.8
1w ago

A double free issue was addressed with improved memory management

A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An ap…

Midnightapple · ipadosEPSS 0.65%via NVD
CVE-2026-84558Medium· 5.5
1w ago

A double free issue was addressed with improved memory management

A double free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27. An app may be able to cause unexpected system termination.

Sunlitapple · macosEPSS 0.12%via NVD
CVE-2026-85921High· 8.2
1w ago

Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 11 version 26H1EPSS 0.26%via NVD
CVE-2026-23790Medium· 4.2
1w ago

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffe…

SunlitSamsung · Exynos 1280 firmwareEPSS 0.09%via NVD
CVE-2026-23789High· 7.8
1w ago

An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000

An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC en…

TwilightSamsung · Exynos 850 firmwareEPSS 0.11%via NVD
CVE-2026-57842High· 7.0
1w ago

NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path

NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to exe…

TwilightThe NetBSD Foundation · NetBSDEPSS 0.10%via NVD
CVE-2026-61915Medium· 4.2
1w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two o…

Sunlitcyrus · imapEPSS 0.26%via NVD
CVE-2026-87585High· 8.8
1w ago

Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file

Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.28%via NVD
CVE-2026-79907High· 7.8
1w ago

Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Twilightadobe · acrobatEPSS 0.19%via NVD
CVE-2026-81950High· 7.8
1w ago

Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Twilightmicrosoft · 365_appsEPSS 0.43%via NVD
CVE-2026-80080High· 8.8
1w ago

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Twilightmicrosoft · 365_appsEPSS 0.61%via NVD
CVE-2026-77504High· 8.8
1w ago

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.62%via NVD
CVE-2026-77493Critical· 9.8
1w ago

Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Midnightmicrosoft · windows_10_1607EPSS 0.95%via NVD
CVE-2026-72958High· 8.2
1w ago

Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.

Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_11_24h2EPSS 0.33%via NVD
CVE-2026-71353High· 7.0
1w ago

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via NVD
CVE-2026-71351High· 7.0
1w ago

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.25%via NVD
CVE-2026-71338Medium· 6.4
1w ago

Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.

Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-70567High· 7.0
1w ago

Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_11_24h2EPSS 0.25%via NVD
CVE-2026-70562High· 7.0
1w ago

Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.25%via NVD
CVE-2026-69876High· 8.0
1w ago

Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.

Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.

Twilightmicrosoft · windows_10_1607EPSS 0.58%via NVD
CVE-2026-69725High· 7.8
1w ago

Double free in Windows Hello allows an authorized attacker to elevate privileges locally.

Double free in Windows Hello allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.31%via NVD
CVE-2026-69398High· 7.0
1w ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1809EPSS 0.19%via NVD
CVE-2026-69337High· 7.1
1w ago

Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.

Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.65%via NVD
CVE-2026-69322High· 8.0
1w ago

Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.

Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.

TwilightMicrosoft · Windows 11 version 23H2EPSS 0.70%via NVD
CVE-2026-69309High· 7.0
1w ago

Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.25%via NVD
CVE-2026-69292High· 7.0
1w ago

Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally.

Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via NVD
CVE-2026-55007High· 8.1
1w ago

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

TwilightMicrosoft · Microsoft Exchange Server 2019 Cumulative Update 14EPSS 0.73%via NVD
CVE-2026-82325Medium· 6.8
2w ago

A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages

A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages

SunlitOpenVPN · ovpn-dco-winEPSS 0.10%via NVD
CWE-415 vulnerabilities (CVEs) · VulnSea