Vulnerability index

Browse CVEs

810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Double FreeCWE-415 × clear
Debian Linux CRITICAL 9.8
CVE-2020-6072

An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels …

No fix yet
Fix from $2,300 2020-03-24
Pfc200 Firmware HIGH 7.8
CVE-2019-5184

An exploitable double free vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. A specially crafted XML cache file…

No fix yet
Fix from $1,950 2020-03-23
Apq8053 Firmware HIGH 7.8
CVE-2018-11838

Possible double free issue in WLAN due to lack of checking memory free condition. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electro…

Patch available
Fix from $1,950 2020-03-05
Quick \'n Easy Web Server HIGH 7.5
CVE-2019-19943

The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or dom…

Fix: after 3.3.8
Fix from $1,950 2020-02-28
Nip6800 Firmware HIGH 7.5
CVE-2020-1829

Huawei NIP6800 versions V500R001C30 and V500R001C60SPC500; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, and V500R…

Mitigation only
Fix from $1,950 2020-02-17
Apq8009 Firmware HIGH 7.8
CVE-2019-14055

Possibility of use-after-free and double free because of not marking buffer as NULL after freeing can lead to dangling pointer access in Snapdragon A…

Patch available
Fix from $1,950 2020-02-07
U Boot CRITICAL 9.8
CVE-2020-8432

In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-wha…

Fix: after 2020.01
Fix from $2,300 2020-01-29
Debian Linux MEDIUM 5.5
CVE-2020-8003

A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service by triggering texture al…

Fix: after 0.8.1
Fix from $1,600 2020-01-27
Libyang HIGH 8.8
CVE-2019-20393

A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used. Applications that use libyang to pars…

Patch available
Fix from $1,950 2020-01-22
Libyang HIGH 8.8
CVE-2019-20394

A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notification statement. Applications …

Patch available
Fix from $1,950 2020-01-22
Libyang HIGH 8.8
CVE-2019-20397

A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminated. Applications that use liby…

Patch available
Fix from $1,950 2020-01-22
Systrace CRITICAL 9.8
CVE-2007-4773

Systrace before 1.6.0 has insufficient escape policy enforcement.

Fix: 1.6.0+
Fix from $2,300 2020-01-15
Android HIGH 7.8
CVE-2019-9468

In export_key_der of export_key.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with …

Fix: 10.0+
Fix from $1,950 2020-01-06
Libredwg HIGH 8.8
CVE-2019-20014

An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.

Fix: 0.9.3+
Fix from $1,950 2019-12-27
PHP CRITICAL 9.8
CVE-2019-11049

In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4…

Fix: 5.19.0+
Fix from $2,300 2019-12-23
Mac Os X HIGH 7.8
CVE-2019-8635

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to exe…

Fix: 10.14.5+
Fix from $1,950 2019-12-18
Apq8009 Firmware HIGH 7.8
CVE-2019-10517

Memory is being freed up twice when two concurrent threads are executing in parallel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT,…

Mitigation only
Fix from $1,950 2019-12-18
Apq8009 Firmware HIGH 7.8
CVE-2019-10536

Potential double free scenario if driver receives another DIAG_EVENT_LOG_SUPPORTED event from firmware as the pointer is not set to NULL on first cal…

Patch available
Fix from $1,950 2019-12-18
Debian Linux CRITICAL 9.8
CVE-2019-19725

sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.

Fix: after 12.2.0
Fix from $2,300 2019-12-11
Apq8053 Firmware HIGH 7.8
CVE-2019-2266

Possible double free issue in kernel while handling the camera sensor and its sub modules power sequence in Snapdragon Auto, Snapdragon Consumer IOT,…

Patch available
Fix from $1,950 2019-11-21
Emily Al00a Firmware HIGH 7.8
CVE-2019-5282

Bastet module of some Huawei smartphones with Versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Versions earlier than Emily-TL00B 9.0.0.182(C…

Mitigation only
Fix from $1,950 2019-11-13
Blink MEDIUM 6.5
CVE-2011-1803

An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Blink M11 and M12 when trying t…

Mitigation only
Fix from $1,600 2019-11-12
Blink HIGH 7.5
CVE-2011-2335

A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function.

Mitigation only
Fix from $1,950 2019-11-12
Psutil HIGH 7.5
CVE-2019-18874

psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts…

Fix: after 5.6.5
Fix from $1,950 2019-11-12
Apq8053 Firmware CRITICAL 9.8
CVE-2019-10565

Double free issue can happen when sensor power settings is freed by some thread while another thread try to access. in Snapdragon Auto, Snapdragon Co…

Mitigation only
Fix from $2,300 2019-11-06
Debian Linux CRITICAL 9.8
CVE-2019-17545

GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.

Fix: after 3.0.1
Fix from $2,300 2019-10-14
Whatsapp HIGH 8.8
CVE-2019-11932EPSS 45%

A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp f…

Fix: 1.2.18 / 2.19.244+
Fix from $1,950 2019-10-03
Linea CRITICAL 9.8
CVE-2019-16880

An issue was discovered in the linea crate through 0.9.4 for Rust. There is double free in the Matrix::zip_elements method.

Fix: after 0.9.4
Fix from $2,300 2019-09-25
Curl CRITICAL 9.8
CVE-2019-5481EPSS 7%

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

Fix: after 7.65.3
Fix from $2,300 2019-09-16
Android HIGH 7.8
CVE-2019-2115

In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corruption due to a double free. Thi…

Patch available
Fix from $1,950 2019-09-05