Vulnerability index

Browse CVEs

810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Double FreeCWE-415 × clear
Emui HIGH 7.0
CVE-2021-22386

A component of the Huawei smartphone has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevation of Privi…

Mitigation only
Fix from $1,950 2021-08-10
Sys Info CRITICAL 9.8
CVE-2020-36434

An issue was discovered in the sys-info crate before 0.8.0 for Rust. sys_info::disk_info calls can trigger a double free.

Fix: 0.8.0+
Fix from $2,300 2021-08-08
Harmonyos HIGH 7.8
CVE-2021-22425

A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating Privileges.

Mitigation only
Fix from $1,950 2021-08-03
Linux Kernel MEDIUM 6.4
CVE-2021-37159

hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED st…

Fix: after 5.13.4
Fix from $1,600 2021-07-21
Android MEDIUM 5.5
CVE-2021-0601

In encodeFrames of avc_enc_fuzzer.cpp, there is a possible out of bounds write due to a double free. This could lead to local information disclosure …

Mitigation only
Fix from $1,600 2021-07-14
Jt2go MEDIUM 5.5
CVE-2021-34333

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in a…

Fix: 13.2.0+
Fix from $1,600 2021-07-13
Apq8017 Firmware HIGH 7.8
CVE-2021-1888

Memory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto, Snapdragon Compute, Snapdrago…

Mitigation only
Fix from $1,950 2021-07-13
Design Review HIGH 8.1
CVE-2021-27033

A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability in the Autodesk Design Revie…

Mitigation only
Fix from $1,950 2021-07-09
Libredwg HIGH 8.8
CVE-2021-36080

GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_encode_add_object).

Fix: after 0.12.3.4191
Fix from $1,950 2021-07-01
Fluent Bit CRITICAL 9.8
CVE-2021-36088

Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).

Fix: after 1.7.4
Fix from $2,300 2021-07-01
Mruby HIGH 7.8
CVE-2020-36401

mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).

Patch available
Fix from $1,950 2021-07-01
Miniaudio CRITICAL 9.8
CVE-2021-34184

Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in miniaudio.h.

Patch available
Fix from $2,300 2021-06-25
Android HIGH 7.8
CVE-2021-0528

In memory management driver, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no add…

Mitigation only
Fix from $1,950 2021-06-21
Android HIGH 7.8
CVE-2021-0498

In memory management driver, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no add…

Mitigation only
Fix from $1,950 2021-06-11
Linux Kernel MEDIUM 5.5
CVE-2021-3564

A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluet…

No fix yet
Fix from $1,600 2021-06-08
Chrome HIGH 8.8
CVE-2021-30535

Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Fix: 91.0.4472.77+
Fix from $1,950 2021-06-07
Fedora MEDIUM 5.5
CVE-2021-32613

In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.

Fix: after 5.3.0
Fix from $1,600 2021-05-14
Foxit Reader HIGH 7.8
CVE-2021-31449

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is requ…

Fix: after 10.1.3.37598
Fix from $1,950 2021-05-07
Apq8009 Firmware CRITICAL 9.8
CVE-2021-1910

Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IO…

Mitigation only
Fix from $2,300 2021-05-07
Algorithmica HIGH 7.5
CVE-2021-31996

An issue was discovered in the algorithmica crate through 2021-03-07 for Rust. There is a double free in merge_sort::merge().

Fix: after 2021-03-07
Fix from $1,950 2021-05-03
Cloudengine 12800 Firmware HIGH 7.5
CVE-2021-22332

There is a pointer double free vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 and CloudEngine 12800. When a f…

Mitigation only
Fix from $1,950 2021-04-28
Junos MEDIUM 6.5
CVE-2021-0271

A Double Free vulnerability in the software forwarding interface daemon (sfid) process of Juniper Networks Junos OS allows an adjacently-connected at…

Mitigation only
Fix from $1,600 2021-04-22
Ubuntu Linux HIGH 7.8
CVE-2021-3492

Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() corre…

Fix: 18.04 / 20.04+
Fix from $1,950 2021-04-17
Rust CRITICAL 9.8
CVE-2021-31162

In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.

Fix: 1.52.0+
Fix from $2,300 2021-04-14
Android HIGH 7.8
CVE-2021-0437

In setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalation of privilege in a privileged process with no …

Patch available
Fix from $1,950 2021-04-13
Rust CRITICAL 9.8
CVE-2020-36318

In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition.…

Fix: 1.49.0+
Fix from $2,300 2021-04-11
Id Map CRITICAL 9.8
CVE-2021-30455

An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in IdMap::clone_from upon a .clone panic.

Fix: after 2021-02-26
Fix from $2,300 2021-04-07
Id Map CRITICAL 9.8
CVE-2021-30456

An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in get_or_insert upon a panic of a user-provided f f…

Fix: after 2021-02-26
Fix from $2,300 2021-04-07
Id Map CRITICAL 9.8
CVE-2021-30457

An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in remove_set upon a panic in a Drop impl.

Fix: after 2021-02-26
Fix from $2,300 2021-04-07
FreeBSD HIGH 7.8
CVE-2021-29627

In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept filters im…

Fix: 12.2+
Fix from $1,950 2021-04-07