VulnSea

CWE-415

CVEs classified under CWE-415, newest first.

105 CVEsRSS

CVE-2026-10653Medium· 6.4
2mo ago

The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and the per-data-block ref_count at the start of each variable/heap data allocation -- with plain non-atomic C operators (…

The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and the per-data-block ref_count at the start of each variable/heap data allocation -- with plain non-atomic C operators (…

▾ Sunlitzephyrproject · zephyrEPSS 0.42%via NVD
CVE-2026-53322High· 8.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs before disabling function On device shutdown, make vfio_pci_core_close_device() call vfio_pci_dma_buf_cleanup() before the function is disab…

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs before disabling function On device shutdown, make vfio_pci_core_close_device() call vfio_pci_dma_buf_cleanup() before the function is disab…

▾ Twilightlinux · linux_kernelEPSS 0.36%via NVD
CVE-2026-53009High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it…

In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or ice_tx_csum() fail, the error path in ice_xmit_frame_ring() frees the skb, but the 'first' tx_buf still points to it…

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CVE-2026-55653Medium· 4.3
3mo ago

A flaw was found in OpenSSH

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group va…

▾ Sunlitopenbsd · opensshEPSS 0.51%via NVD
CVE-2026-11576High· 7.5
3mo ago

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file …

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file …

▾ Twilighteclipse · threadx_netx_duoEPSS 0.46%via NVD
CVE-2026-44422High· 7.5
4mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without tracking the pointed object's expected NDR …

▾ Twilightfreerdp · freerdpEPSS 0.66%via NVD
CVE-2026-46189High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path Sashiko points out that pvrdma_uar_free() is already called within pvrdma_dealloc_ucontext(), so…

In the Linux kernel, the following vulnerability has been resolved: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path Sashiko points out that pvrdma_uar_free() is already called within pvrdma_dealloc_ucontext(), so…

▾ Twilightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-45852High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix double free in rxe_srq_from_init In rxe_srq_from_init(), the queue pointer 'q' is assigned to 'srq->rq.queue' before copying the SRQ number to user space…

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix double free in rxe_srq_from_init In rxe_srq_from_init(), the queue pointer 'q' is assigned to 'srq->rq.queue' before copying the SRQ number to user space…

▾ Twilightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2026-43414Critical· 9.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix fcport double free In qla24xx_els_dcmd_iocb() sp->free is set to qla2x00_els_dcmd_sp_free(). When an error happens, this function is call…

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix fcport double free In qla24xx_els_dcmd_iocb() sp->free is set to qla2x00_els_dcmd_sp_free(). When an error happens, this function is call…

▾ Midnightlinux · linux_kernelEPSS 0.55%via NVD
CVE-2026-33811High· 7.5
4mo ago

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

▾ Twilightgolang · goEPSS 0.88%via NVD
CVE-2026-26166High· 7.0
5mo ago

Windows Shell Elevation of Privilege Vulnerability

Double free in Windows Shell allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 22H3EPSS 0.26%via CVEORG
CVE-2026-26179High· 7.8PoC
5mo ago

Windows Kernel Elevation of Privilege Vulnerability

Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 11 version 22H3EPSS 0.33%via CVEORG
CVE-2026-32219High· 7.0
5mo ago

Microsoft Brokering File System Elevation of Privilege Vulnerability

Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.20%via CVEORG
CVE-2026-26163High· 7.8
5mo ago

Windows Kernel Elevation of Privilege Vulnerability

Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-32069High· 7.8
5mo ago

Windows Projected File System Elevation of Privilege Vulnerability

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-32074High· 7.8
5mo ago

Windows Projected File System Elevation of Privilege Vulnerability

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-33824Critical· 9.8CISA KEVPoC
5mo ago

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

▾ Hadalmicrosoft · windows_10_1607EPSS 1.6%via NVD
CVE-2025-13844Medium· 5.3
8mo ago

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.

▾ Sunlitschneider-electric · ecostruxure_power_build_-_rapsodyEPSS 0.16%via NVD
CVE-2026-20867High· 7.8
8mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.30%via NVD
CVE-2026-20863High· 7.0
8mo ago

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_23h2EPSS 0.40%via NVD
CVE-2026-20861High· 7.8
8mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.30%via NVD
CVE-2026-20832High· 7.8
8mo ago

Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability

Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability

▾ Twilightmicrosoft · windows_10_1607EPSS 0.48%via NVD
CVE-2025-65955Medium· 4.9
9mo ago

ImageMagick is free and open-source software used for editing and manipulating digital images

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked wi…

▾ Sunlitimagemagick · imagemagickEPSS 0.16%via NVD
CVE-2022-50303High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix double release compute pasid If kfd_process_device_init_vm returns failure after vm is converted to compute vm and vm->pasid set to compute pasid, KFD …

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix double release compute pasid If kfd_process_device_init_vm returns failure after vm is converted to compute vm and vm->pasid set to compute pasid, KFD …

▾ Twilightlinux · linux_kernelEPSS 0.16%via NVD
CVE-2025-32988Medium· 6.5
1y ago

A flaw was found in GnuTLS

A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malforme…

▾ Sunlitgnu · gnutlsEPSS 1.3%via NVD
CVE-2025-38206High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: exfat: fix double free in delayed_free The double free could happen in the following path. exfat_create_upcase_table() exfat_create_upcase_table() : return er…

In the Linux kernel, the following vulnerability has been resolved: exfat: fix double free in delayed_free The double free could happen in the following path. exfat_create_upcase_table() exfat_create_upcase_table() : return er…

▾ Twilightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2025-5351Medium· 6.5
1y ago

A flaw was found in the key export functionality of libssh

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not clear…

▾ Sunlitlibssh · libsshEPSS 0.57%via NVD
CVE-2025-4574Medium· 6.5
1y ago

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

▾ SunlitEPSS 0.54%via NVD
CVE-2025-21825High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Cancel the running bpf_timer through kworker for PREEMPT_RT During the update procedure, when overwrite element in a pre-allocated htab, the freeing of old_elemen…

In the Linux kernel, the following vulnerability has been resolved: bpf: Cancel the running bpf_timer through kworker for PREEMPT_RT During the update procedure, when overwrite element in a pre-allocated htab, the freeing of old_elemen…

▾ Twilightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2022-49519High· 8.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: ath10k: skip ath10k_halt during suspend for driver state RESTARTING Double free crash is observed when FW recovery(caused by wmi timeout/crash) is followed by immediat…

In the Linux kernel, the following vulnerability has been resolved: ath10k: skip ath10k_halt during suspend for driver state RESTARTING Double free crash is observed when FW recovery(caused by wmi timeout/crash) is followed by immediat…

▾ Twilightlinux · linux_kernelEPSS 0.35%via NVD
CWE-415 vulnerabilities (CVEs) — page 3 · VulnSea