Vulnerability index

Browse CVEs

810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Double FreeCWE-415 × clear
Picotcp CRITICAL 9.8
CVE-2021-33304

Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allo…

Patch available
Fix from $2,300 2023-02-15
OpenSSL HIGH 7.5
CVE-2022-4450EPSS 20%

The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload da…

Fix: 1.1.1t / 3.0.8+
Fix from $1,950 2023-02-08
Fedora MEDIUM 6.5
CVE-2023-25136EPSS 90%

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double fre…

Patch available
Fix from $1,600 2023-02-03
Zephyr CRITICAL 9.8
CVE-2022-3806

Inconsistent handling of error cases in bluetooth hci may lead to a double free condition of a network buffer.

Fix: after 3.2.0
Fix from $2,300 2023-01-25
Apq8096au Firmware HIGH 7.8
CVE-2022-25717

Memory corruption in display due to double free while allocating frame buffer memory

Patch available
Fix from $1,950 2023-01-09
Emui HIGH 7.5
CVE-2022-47975

The DUBAI module has a double free vulnerability. Successful exploitation of this vulnerability may affect system availability.

Fix: 2.0+
Fix from $1,950 2023-01-06
Heimdal CRITICAL 9.8
CVE-2022-44640

Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Cen…

Fix: 4.15.3 / 4.16.8+
Fix from $2,300 2022-12-25
Libxml2 HIGH 7.8
CVE-2022-40304EPSS 7%

An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequ…

Fix: 2.10.3+
Fix from $1,950 2022-11-23
Linux Kernel HIGH 7.8
CVE-2022-3238

A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local…

Mitigation only
Fix from $1,950 2022-11-14
Android MEDIUM 6.7
CVE-2022-32614

In audio, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege with System execution privileg…

Mitigation only
Fix from $1,600 2022-11-08
Diplib MEDIUM 6.5
CVE-2021-39432

diplib v3.0.0 is vulnerable to Double Free.

Patch available
Fix from $1,600 2022-11-04
Curl HIGH 8.1
CVE-2022-42915

curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the re…

Fix: 7.86.0 / 12.6.3+
Fix from $1,950 2022-10-29
Iota All In One Security Kit Firmware MEDIUM 6.5
CVE-2022-32574

A double-free vulnerability exists in the web interface /action/ipcamSetParamPost functionality of Abode Systems, Inc. iota All-In-One Security Kit 6…

No fix yet
Fix from $1,600 2022-10-25
Aqt1000 Firmware HIGH 7.8
CVE-2022-25660

Memory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snap…

Mitigation only
Fix from $1,950 2022-10-19
Kailua Firmware HIGH 8.8
CVE-2022-25750

Memory corruption in BTHOST due to double free while music playback and calls over bluetooth headset in Snapdragon Mobile

Patch available
Fix from $1,950 2022-10-19
Linux Kernel MEDIUM 5.5
CVE-2022-3595

A vulnerability was found in Linux Kernel. It has been rated as problematic. Affected by this issue is the function sess_free_buffer of the file fs/c…

Fix: 6.1+
Fix from $1,600 2022-10-18
Shapelib CRITICAL 9.8
CVE-2022-0699

A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of servi…

Fix: after 1.5.0
Fix from $2,300 2022-10-17
Chrome HIGH 7.5
CVE-2019-5797

Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 73.0.3683.75+
Fix from $1,950 2022-09-29
Emui CRITICAL 9.8
CVE-2022-39002

Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to be freed twice.

Mitigation only
Fix from $2,300 2022-09-16
Rizin HIGH 7.8
CVE-2022-36043

Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to a double free in bobj.c:rz_bi…

Fix: after 0.4.0
Fix from $1,950 2022-09-06
Apq8009 Firmware CRITICAL 9.8
CVE-2022-25668

Memory corruption in video driver due to double free while parsing ASF clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdrag…

Mitigation only
Fix from $2,300 2022-09-02
Fedora HIGH 8.8
CVE-2022-39170

libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.

Patch available
Fix from $1,950 2022-09-02
Debian Linux MEDIUM 6.5
CVE-2022-2519

There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1

Patch available
Fix from $1,600 2022-08-31
Radare2 CRITICAL 9.1
CVE-2020-27794

A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modification of unexpected memory locat…

Fix: 4.4.0+
Fix from $2,300 2022-08-19
Json\+\+ CRITICAL 9.8
CVE-2022-23459

Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value class may lead to memory corrupt…

Mitigation only
Fix from $2,300 2022-08-19
Virtual Gpu HIGH 7.8
CVE-2022-31614

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it may double-free some resources. An attacker may explo…

Fix: 11.8 / 13.3+
Fix from $1,950 2022-08-05
Enterprise Linux HIGH 7.5
CVE-2022-2509

A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_p…

Fix: 3.7.7+
Fix from $1,950 2022-08-01
Design Review HIGH 8.8
CVE-2022-27864

A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affected insta…

Patch available
Fix from $1,950 2022-07-29
Simplenetwork HIGH 7.5
CVE-2022-36234

SimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnerability which is exploited via…

No fix yet
Fix from $1,950 2022-07-28
Chrome HIGH 8.8
CVE-2022-2008

Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 102.0.5005.115+
Fix from $1,950 2022-07-28