Vulnerability index

Browse CVEs

810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Double FreeCWE-415 × clear
Opensc MEDIUM 6.6
CVE-2018-16425

A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-hsm.c in OpenSC before 0.19.0-rc1 could be …

Fix: after 0.18.0
Fix from $1,600 2018-09-04
Opensc MEDIUM 6.6
CVE-2018-16423

A double free when handling responses from a smartcard in sc_file_set_sec_attr in libopensc/sc.c in OpenSC before 0.19.0-rc1 could be used by attacke…

Fix: after 0.18.0
Fix from $1,600 2018-09-04
Debian Linux CRITICAL 9.8
CVE-2018-16402

libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecif…

No fix yet
Fix from $2,300 2018-09-03
Debian Linux HIGH 7.8
CVE-2018-10902

It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_…

Patch available
Fix from $1,950 2018-08-21
Ubuntu Linux HIGH 8.8
CVE-2018-1000222

Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This atta…

Mitigation only
Fix from $1,950 2018-08-20
Cjson HIGH 8.8
CVE-2018-1000216

Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. …

Fix: 1.7.3+
Fix from $1,950 2018-08-20
Curl CRITICAL 9.8
CVE-2016-8619

The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.

Fix: 7.51.0+
Fix from $2,300 2018-08-01
Curl CRITICAL 9.8
CVE-2016-8618

The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplicat…

Fix: 7.51.0+
Fix from $2,300 2018-07-31
Libredwg MEDIUM 6.5
CVE-2018-14524

dwg_decode_eed in decode.c in GNU LibreDWG before 0.6 leads to a double free (in dwg_free_eed in free.c) because it does not properly manage the obj-…

Fix: 0.6+
Fix from $1,600 2018-07-23
Acrobat Dc CRITICAL 9.8
CVE-2018-12782EPSS 11%

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Double Free vulnerabi…

Fix: after 18.011.20040
Fix from $2,300 2018-07-20
Mp4v2 CRITICAL 9.8
CVE-2018-14054

A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0. A dangling pointer is freed again in the destructor once an ex…

No fix yet
Fix from $2,300 2018-07-13
Acrobat Dc HIGH 8.8
CVE-2018-4990 KEVEPSS 37%

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerabi…

Fix: after 18.011.20038
Fix from $1,950 2018-07-09
Android HIGH 7.0
CVE-2017-15856

Due to a race condition while processing the power stats debug file to read status, a double free condition can occur in Android releases from CAF us…

Patch available
Fix from $1,950 2018-07-06
Libfsntfs MEDIUM 5.5
CVE-2018-11730

The libfsntfs_security_descriptor_values_free function in libfsntfs_security_descriptor_values.c in libfsntfs through 2018-04-20 allows remote attack…

Fix: after 20180420
Fix from $1,600 2018-06-19
Android HIGH 7.0
CVE-2017-15843

Due to a race condition in a bus driver, a double free in msm_bus_floor_vote_context() can potentially occur in all Android releases from CAF (Androi…

Patch available
Fix from $1,950 2018-06-12
Jpegoptim HIGH 8.8
CVE-2018-11416

jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of servic…

Mitigation only
Fix from $1,950 2018-05-24
Upx HIGH 7.8
CVE-2018-11243

PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware…

No fix yet
Fix from $1,950 2018-05-18
Openvpn HIGH 7.8
CVE-2018-9336

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sendin…

Fix: 2.4.6+
Fix from $1,950 2018-05-01
Perceptive Document Filters HIGH 8.8
CVE-2018-3845

In Hyland Perceptive Document Filters 11.4.0.2647 - x86/x64 Windows/Linux, a crafted OpenDocument document can lead to a SkCanvas object double free …

Mitigation only
Fix from $1,950 2018-04-26
Perceptive Document Filters HIGH 7.8
CVE-2018-3855

In Hyland Perceptive Document Filters 11.4.0.2647 - x86/x64 Windows/Linux, a crafted OpenDocument document can lead to a SkCanvas object double free …

No fix yet
Fix from $1,950 2018-04-26
Webaccess Hmi Designer HIGH 7.8
CVE-2018-8835

Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote…

Fix: after 2.1.7.32
Fix from $1,950 2018-04-25
Debian Linux HIGH 8.8
CVE-2017-14449

A double-Free vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a Double-Fre…

Mitigation only
Fix from $1,950 2018-04-24
Berkeley Al20 Firmware MEDIUM 5.5
CVE-2018-7899

The Mali Driver of Huawei Berkeley-AL20 and Berkeley-BD smart phones with software Berkeley-AL20 8.0.0.105(C00), 8.0.0.111(C00), 8.0.0.112D(C00), 8.0…

Mitigation only
Fix from $1,600 2018-04-19
Mdm9206 Firmware CRITICAL 9.8
CVE-2015-9165

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MSM8909W, S…

Mitigation only
Fix from $2,300 2018-04-18
Mdm9206 Firmware CRITICAL 9.8
CVE-2018-3593

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650…

Mitigation only
Fix from $2,300 2018-04-11
Android HIGH 7.8
CVE-2017-15826

Due to a race condition in MDSS rotator in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-20, a double free vulnerability may po…

Patch available
Fix from $1,950 2018-03-30
Ios Xe MEDIUM 6.3
CVE-2018-0160

A vulnerability in Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to caus…

Mitigation only
Fix from $1,600 2018-03-28
Cx Supervisor MEDIUM 5.3
CVE-2018-7523

In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a double free vulnerability.

Fix: after 3.30
Fix from $1,600 2018-03-21
Mate 9 Pro Firmware HIGH 7.8
CVE-2017-17320

Huawei Mate 9 Pro smartphones with software of LON-AL00BC00B139D, LON-AL00BC00B229, LON-L29DC721B188 have a memory double free vulnerability. The sys…

Mitigation only
Fix from $1,950 2018-03-20
Ubuntu Linux HIGH 8.8
CVE-2018-8804

WriteEPTImage in coders/ept.c in ImageMagick 7.0.7-25 Q16 allows remote attackers to cause a denial of service (MagickCore/memory.c double free and a…

Mitigation only
Fix from $1,950 2018-03-20