Vulnerability index

Browse CVEs

810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Double FreeCWE-415 × clear
Apq8017 Firmware HIGH 7.8
CVE-2020-11246

A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Con…

Mitigation only
Fix from $1,950 2021-04-07
Apq8017 Firmware MEDIUM 6.7
CVE-2020-11231

Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in turn can lead to heap corruptio…

Patch available
Fix from $1,600 2021-04-07
Endian Trait HIGH 7.5
CVE-2021-29929

An issue was discovered in the endian_trait crate through 2021-01-04 for Rust. A double drop can occur when a user-provided Endian impl panics.

Fix: after 2021-01-04
Fix from $1,950 2021-04-01
Arenavec HIGH 7.5
CVE-2021-29931

An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A double drop can sometimes occur upon a panic in T::drop().

Fix: after 2021-01-12
Fix from $1,950 2021-04-01
Insert Many HIGH 7.5
CVE-2021-29933

An issue was discovered in the insert_many crate through 2021-01-26 for Rust. Elements may be dropped twice if a .next() method panics.

Fix: after 2021-01-26
Fix from $1,950 2021-04-01
Slice Deque HIGH 7.5
CVE-2021-29938

An issue was discovered in the slice-deque crate through 2021-02-19 for Rust. A double drop can occur in SliceDeque::drain_filter upon a panic in a p…

Fix: after 2021-02-19
Fix from $1,950 2021-04-01
Through CRITICAL 9.8
CVE-2021-29940

An issue was discovered in the through crate through 2021-02-18 for Rust. There is a double free (in through and through_and) upon a panic of the map…

Fix: after 2021-02-18
Fix from $2,300 2021-04-01
Android CRITICAL 9.8
CVE-2021-0397EPSS 6%

In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with n…

Mitigation only
Fix from $2,300 2021-03-10
Android HIGH 7.8
CVE-2021-0392

In main of main.cpp, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with User execution…

Mitigation only
Fix from $1,950 2021-03-10
Fedora HIGH 7.1
CVE-2021-28041

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a…

Fix: 8.5+
Fix from $1,950 2021-03-05
Scratchpad CRITICAL 9.8
CVE-2021-28031

An issue was discovered in the scratchpad crate before 1.3.1 for Rust. The move_elements function can have a double-free upon a panic in a user-provi…

Fix: 1.3.1+
Fix from $2,300 2021-03-05
Stack Dst CRITICAL 9.8
CVE-2021-28034

An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a double free can occur upon a val.clone() …

Fix: 0.6.1+
Fix from $2,300 2021-03-05
Toodee CRITICAL 9.8
CVE-2021-28028

An issue was discovered in the toodee crate before 0.3.0 for Rust. Row insertion can cause a double free upon an iterator panic.

Fix: 0.3.0+
Fix from $2,300 2021-03-05
Enterprise Linux HIGH 7.8
CVE-2021-3403

In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) …

No fix yet
Fix from $1,950 2021-03-04
Fedora MEDIUM 5.5
CVE-2021-3407EPSS 50%

A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.

Mitigation only
Fix from $1,600 2021-02-23
Fedora HIGH 7.8
CVE-2019-19005

A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitmap image. This may occur after…

Patch available
Fix from $1,950 2021-02-11
Qwutils MEDIUM 5.3
CVE-2021-26954

An issue was discovered in the qwutils crate before 0.3.1 for Rust. When a Clone panic occurs, insert_slice_clone can perform a double drop.

Fix: 0.3.1+
Fix from $1,600 2021-02-09
Containers CRITICAL 9.8
CVE-2021-25907

An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} double drop can be performed.

Fix: 0.9.11+
Fix from $2,300 2021-01-26
Fil Ocl HIGH 7.5
CVE-2021-25908

An issue was discovered in the fil-ocl crate through 2021-01-04 for Rust. From<EventList> can lead to a double free.

Fix: after 0.19.4
Fix from $1,950 2021-01-26
Debian Linux HIGH 7.5
CVE-2020-36225

A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of servic…

Fix: 2.4.57 / 11.4+
Fix from $1,950 2021-01-26
Debian Linux HIGH 7.5
CVE-2020-36223

A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service…

Fix: 2.4.57 / 10.14.6+
Fix from $1,950 2021-01-26
Xcb MEDIUM 5.5
CVE-2020-36205

An issue was discovered in the xcb crate through 2020-12-10 for Rust. base::Error does not have soundness. Because of the public ptr field, a use-aft…

Fix: after 2020-12-10
Fix from $1,600 2021-01-26
Pm3003a HIGH 7.8
CVE-2020-11217

A possible double free or invalid memory access in audio driver while reading Speaker Protection parameters in Snapdragon Compute, Snapdragon Connect…

Patch available
Fix from $1,950 2021-01-21
Apq8009 HIGH 7.5
CVE-2020-3685

Pointer variable which is freed is not cleared can result in memory corruption and leads to denial of service in Snapdragon Auto, Snapdragon Compute,…

Mitigation only
Fix from $1,950 2021-01-21
Alpm Rs CRITICAL 9.8
CVE-2020-35885

An issue was discovered in the alpm-rs crate through 2020-08-20 for Rust. StrcCtx performs improper memory deallocation.

Fix: after 2020-08-20
Fix from $2,300 2020-12-31
Ordnung HIGH 7.5
CVE-2020-35891

An issue was discovered in the ordnung crate through 2020-09-03 for Rust. compact::Vec violates memory safety via a remove() double free.

Fix: after 2020-09-03
Fix from $1,950 2020-12-31
Bitvec CRITICAL 9.8
CVE-2020-35862

An issue was discovered in the bitvec crate before 0.17.4 for Rust. BitVec to BitBox conversion leads to a use-after-free or double free.

Fix: 0.17.4+
Fix from $2,300 2020-12-31
Http CRITICAL 9.8
CVE-2019-25009

An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness.

Fix: 0.1.20+
Fix from $2,300 2020-12-31
Binutils MEDIUM 5.5
CVE-2020-16590

A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as demonstrated…

Patch available
Fix from $1,600 2020-12-09
Pulseaudio MEDIUM 6.1
CVE-2020-15710

Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be f…

Mitigation only
Fix from $1,600 2020-11-19