Vulnerability index

Browse CVEs

810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Double FreeCWE-415 × clear
Android HIGH 7.8
CVE-2018-3560

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a Double Free vulnerability exists in…

Mitigation only
Fix from $1,950 2018-03-16
Debian Linux MEDIUM 6.5
CVE-2018-8099

Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an attacker …

Fix: 0.26.2+
Fix from $1,600 2018-03-14
Cimg HIGH 7.8
CVE-2018-7589

An issue was discovered in CImg v.220. A double free in load_bmp in CImg.h occurs when loading a crafted bmp image.

No fix yet
Fix from $1,950 2018-03-01
Libcdio CRITICAL 9.8
CVE-2017-18201

An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.

Fix: 2.0.0+
Fix from $2,300 2018-02-26
Linux Kernel HIGH 7.8
CVE-2018-7480

The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local users to cause a denial of service (double free) or …

Fix: 4.1.51 / 4.4.123+
Fix from $1,950 2018-02-25
Libmad CRITICAL 9.8
CVE-2018-7263

The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service (SIGABRT because …

Fix: after 0.15.1b
Fix from $2,300 2018-02-20
Debian Linux CRITICAL 9.8
CVE-2018-5379EPSS 38%

The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list a…

Fix: after 1.2.2
Fix from $2,300 2018-02-19
Vicky Al00a Firmware MEDIUM 5.5
CVE-2017-15330

The Flp Driver in some Huawei smartphones of the software Vicky-AL00AC00B124D, Vicky-AL00AC00B157D, Vicky-AL00AC00B167 has a double free vulnerabilit…

Mitigation only
Fix from $1,600 2018-02-15
Patch HIGH 7.5
CVE-2018-6952EPSS 8%

A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.

Fix: after 2.7.6
Fix from $1,950 2018-02-13
Linux Kernel CRITICAL 9.8
CVE-2017-18174

In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a dou…

Fix: 4.7+
Fix from $2,300 2018-02-11
Gifsicle HIGH 7.8
CVE-2017-18120

A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified …

Patch available
Fix from $1,950 2018-02-02
Adaptive Security Appliance Software CRITICAL 10.0
CVE-2018-0101EPSS 87%

A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenti…

Fix: 9.1.7.23 / 9.2.4.27+
Fix from $2,300 2018-01-29
Nx Os HIGH 7.4
CVE-2018-0102

A vulnerability in the Pong tool of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, r…

Mitigation only
Fix from $1,950 2018-01-18
Android HIGH 7.8
CVE-2017-13181

In the doGetThumb and getThumbnail functions of MtpServer, there is a possible double free due to not NULLing out a freed pointer. This could lead to…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.8
CVE-2017-9705

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, concurrent rx notifications and read(…

Patch available
Fix from $1,950 2018-01-10
Mate 9 Firmware HIGH 7.8
CVE-2017-15316

The GPU driver of Mate 9 Huawei smart phones with software before MHA-AL00B 8.0.0.334(C00) and Mate 9 Pro Huawei smart phones with software before LO…

Mitigation only
Fix from $1,950 2017-12-22
P10 Plus Firmware HIGH 7.8
CVE-2017-8141

The Touch Panel (TP) driver in P10 Plus smart phones with software versions earlier than VKY-AL00C00B153 has a memory double free vulnerability. An a…

Mitigation only
Fix from $1,950 2017-11-22
P9 Plus Firmware HIGH 7.8
CVE-2017-8140

The soundtrigger driver in P9 Plus smart phones with software versions earlier than VIE-AL10BC00B353 has a memory double free vulnerability. An attac…

Mitigation only
Fix from $1,950 2017-11-22
Big Ip Afm MEDIUM 5.9
CVE-2017-6166

In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management …

Fix: after 12.1.1
Fix from $1,600 2017-11-22
Ldns CRITICAL 9.8
CVE-2017-1000231

A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.

Patch available
Fix from $2,300 2017-11-17
Ldns CRITICAL 9.8
CVE-2017-1000232

A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.

No fix yet
Fix from $2,300 2017-11-17
Android HIGH 7.8
CVE-2017-11032

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a double free can occur when kmalloc …

Patch available
Fix from $1,950 2017-11-16
Collectd CRITICAL 9.8
CVE-2017-16820

The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which co…

Fix: 5.6.3+
Fix from $2,300 2017-11-14
Ffmpeg MEDIUM 6.5
CVE-2017-15186

Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.

Fix: after 3.3.4
Fix from $1,600 2017-10-24
Debian Linux HIGH 7.5
CVE-2015-5177EPSS 6%

Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service…

Patch available
Fix from $1,950 2017-10-22
Debian Linux MEDIUM 6.5
CVE-2015-1239

Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to ca…

Fix: 2.1.1+
Fix from $1,600 2017-10-18
International Components For Unicode CRITICAL 9.8
CVE-2017-14952EPSS 5%

Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary co…

Fix: after 59.1
Fix from $2,300 2017-10-16
Ccsv MEDIUM 5.5
CVE-2017-15364

The foreach function in ext/ccsv.c in Ccsv 1.1.0 allows remote attackers to cause a denial of service (double free and application crash) or possibly…

Patch available
Fix from $1,600 2017-10-15
Android HIGH 7.8
CVE-2017-9686

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a possible double free/use a…

Mitigation only
Fix from $1,950 2017-10-10
Android HIGH 7.8
CVE-2017-9687

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, two concurrent threads/processes can …

Mitigation only
Fix from $1,950 2017-10-10