Vulnerability index

Browse CVEs

810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Double FreeCWE-415 × clear
Linux Kernel HIGH 7.8
CVE-2022-2327

io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when…

Patch available
Fix from $1,950 2022-07-22
Hicos Natural Person Credential Component Client MEDIUM 6.8
CVE-2022-32962

HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability…

Mitigation only
Fix from $1,600 2022-07-20
Ultrajson MEDIUM 5.9
CVE-2022-31117

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0 an error occurring while rea…

Fix: 5.4.0+
Fix from $1,600 2022-07-05
Dcmtk HIGH 7.5
CVE-2021-41688

DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still used in other locations. Sending…

Fix: after 3.6.6
Fix from $1,950 2022-06-28
Linux Kernel MEDIUM 5.5
CVE-2022-34494

rpmsg_virtio_add_ctrl_dev in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.

Fix: 5.18.4+
Fix from $1,600 2022-06-26
Linux Kernel MEDIUM 5.5
CVE-2022-34495

rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.

Fix: 5.18.4+
Fix from $1,600 2022-06-26
Libredwg HIGH 7.8
CVE-2022-33033

LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.

No fix yet
Fix from $1,950 2022-06-23
Debian Linux HIGH 7.5
CVE-2022-31291

An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.

Patch available
Fix from $1,950 2022-06-16
Android HIGH 7.8
CVE-2021-39806

In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privile…

Mitigation only
Fix from $1,950 2022-06-15
Android CRITICAL 9.8
CVE-2022-20127EPSS 7%

In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no add…

Mitigation only
Fix from $2,300 2022-06-15
Apq8009w Firmware CRITICAL 9.8
CVE-2022-22086

Memory corruption in video due to double free while parsing 3gp clip with invalid meta data atoms in Snapdragon Auto, Snapdragon Compute, Snapdragon …

Mitigation only
Fix from $2,300 2022-06-14
Sa8540p Firmware HIGH 7.8
CVE-2022-22103

Memory corruption in multimedia driver due to double free while processing data from user in Snapdragon Auto

Mitigation only
Fix from $1,950 2022-06-14
Android MEDIUM 6.7
CVE-2022-21758

In ccu, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges…

Mitigation only
Fix from $1,600 2022-06-06
Fedora HIGH 7.8
CVE-2021-42613

A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact vi…

No fix yet
Fix from $1,950 2022-05-24
Jt2go HIGH 7.8
CVE-2022-29032

A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visual…

Fix: 13.3.0.3 / 14.0.0.1+
Fix from $1,950 2022-05-20
Ruby CRITICAL 9.8
CVE-2022-28738

A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untruste…

Fix: 3.0.4 / 3.1.2+
Fix from $2,300 2022-05-09
Miui HIGH 7.5
CVE-2020-14123

There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, …

Mitigation only
Fix from $1,950 2022-04-22
Fedora MEDIUM 5.3
CVE-2021-42778

A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.

Fix: 0.22.0+
Fix from $1,600 2022-04-18
Linux Kernel HIGH 7.8
CVE-2022-29156

drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release.

Fix: 5.10.103 / 5.15.26+
Fix from $1,950 2022-04-13
Tcpreplay HIGH 7.8
CVE-2022-27416

Tcpreplay v4.4.1 was discovered to contain a double-free via __interceptor_free.

Patch available
Fix from $1,950 2022-04-12
Navisworks HIGH 7.8
CVE-2022-25796

A Double Free vulnerability allows remote malicious actors to execute arbitrary code on DWF file in Autodesk Navisworks 2022 within affected installa…

Fix: 2022.2+
Fix from $1,950 2022-04-11
Linux Kernel MEDIUM 5.5
CVE-2022-28388

usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.

Fix: after 5.17.1
Fix from $1,600 2022-04-03
Linux Kernel MEDIUM 5.5
CVE-2022-28389

mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.

Fix: after 5.17.1
Fix from $1,600 2022-04-03
Linux Kernel HIGH 7.8
CVE-2022-28390

ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.

Fix: after 5.17.1
Fix from $1,950 2022-04-03
Bridge HIGH 7.8
CVE-2021-42533

Adobe Bridge version 11.1.1 (and earlier) is affected by a double free vulnerability when parsing a crafted DCM file, which could result in arbitrary…

Fix: after 11.1.1
Fix from $1,950 2022-03-16
Android MEDIUM 6.7
CVE-2021-39725

In gasket_free_coherent_memory_all of gasket_page_table.c, there is a possible memory corruption due to a double free. This could lead to local escal…

Mitigation only
Fix from $1,600 2022-03-16
Htmldoc CRITICAL 9.8
CVE-2021-23158

A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an …

Patch available
Fix from $2,300 2022-03-16
Libsixel MEDIUM 6.5
CVE-2021-46700

In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free.

No fix yet
Fix from $1,600 2022-02-19
Microstation HIGH 7.8
CVE-2021-46621

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User inter…

Fix: 10.16.02+
Fix from $1,950 2022-02-18
Microstation HIGH 7.8
CVE-2021-46625

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is requir…

Fix: 10.16.02+
Fix from $1,950 2022-02-18