Vulnerability index

Browse CVEs

810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Double FreeCWE-415 × clear
Fedora CRITICAL 9.8
CVE-2017-11462EPSS 5%

Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of securi…

Patch available
Fix from $2,300 2017-09-13
Debian Linux HIGH 7.5
CVE-2017-6362EPSS 5%

Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors relat…

Patch available
Fix from $1,950 2017-09-07
Pngcrush CRITICAL 9.8
CVE-2015-7700

Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vec…

Fix: after 1.7.86
Fix from $2,300 2017-08-31
Total Security HIGH 7.0
CVE-2017-10950

This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Bitdefender Total Security 21.0.24.62. An attacker…

Mitigation only
Fix from $1,950 2017-08-29
Libfpx MEDIUM 6.5
CVE-2017-12925

Double free vulnerability in DfFromLB in docfile.cxx in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service via a crafted fpx image.

Mitigation only
Fix from $1,600 2017-08-28
Libzip CRITICAL 9.8
CVE-2017-12858

Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown vectors.

Patch available
Fix from $2,300 2017-08-23
Android HIGH 7.0
CVE-2017-8265

In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a video driver which can lead to a double …

Patch available
Fix from $1,950 2017-08-18
Fedora MEDIUM 5.5
CVE-2015-5203

Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via …

Mitigation only
Fix from $1,600 2017-08-02
Gravity CRITICAL 9.8
CVE-2017-1000072

Creolabs Gravity version 1.0 is vulnerable to a Double Free in gravity_value resulting potentially leading to modification of unexpected memory locat…

Patch available
Fix from $2,300 2017-07-17
Debian Linux CRITICAL 9.8
CVE-2017-11139

GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.

Patch available
Fix from $2,300 2017-07-10
Xen HIGH 8.1
CVE-2017-10914

The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service …

Fix: after 4.8.1
Fix from $1,950 2017-07-05
Openvpn MEDIUM 5.9
CVE-2017-7521

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double…

Fix: after 2.3.16
Fix from $1,600 2017-06-27
Android HIGH 7.8
CVE-2017-7373

In all Android releases from CAF using the Linux kernel, a double free vulnerability exists in a display driver.

Patch available
Fix from $1,950 2017-06-13
Chrome MEDIUM 6.5
CVE-2015-1207

Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory co…

Mitigation only
Fix from $1,600 2017-06-06
Android HIGH 7.8
CVE-2015-9007

In TrustZone in all Android releases from CAF using the Linux kernel, a Double Free vulnerability could potentially exist.

Patch available
Fix from $1,950 2017-06-06
Debian Linux MEDIUM 6.5
CVE-2017-9287EPSS 7%

servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can cr…

Fix: after 2.4.44
Fix from $1,600 2017-05-29
Debian Linux HIGH 8.8
CVE-2017-9078EPSS 5%

The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners…

Fix: 2017.75+
Fix from $1,950 2017-05-19
Linux Kernel HIGH 7.8
CVE-2017-8890

The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service…

Fix: 3.2.89 / 3.10.106+
Fix from $1,950 2017-05-10
Debian Linux HIGH 8.8
CVE-2016-1516

OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.

Patch available
Fix from $1,950 2017-04-10
Mac Os X HIGH 7.8
CVE-2017-2425

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "SecurityFoundation" component. A double …

Fix: after 10.12.3
Fix from $1,950 2017-04-02
Tigervnc HIGH 8.8
CVE-2017-7393

In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or po…

Patch available
Fix from $1,950 2017-04-01
Imagemagick MEDIUM 5.5
CVE-2014-9807

The pdb coder in ImageMagick allows remote attackers to cause a denial of service (double free) via unspecified vectors.

Fix: 6.9.4-0+
Fix from $1,600 2017-03-30
Leap CRITICAL 9.8
CVE-2017-5334EPSS 33%

Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have…

Fix: after 3.3.25
Fix from $2,300 2017-03-24
Debian Linux HIGH 7.8
CVE-2017-5506

Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file.

Patch available
Fix from $1,950 2017-03-24
Imagemagick MEDIUM 5.5
CVE-2015-8894

Double free vulnerability in coders/tga.c in ImageMagick 7.0.0 and later allows remote attackers to cause a denial of service (application crash) via…

Patch available
Fix from $1,600 2017-03-15
Linux Kernel HIGH 7.0
CVE-2017-2636

Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double …

Fix: 3.2.87 / 3.10.106+
Fix from $1,950 2017-03-07
Libplist HIGH 7.5
CVE-2017-5836

The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that …

Patch available
Fix from $1,950 2017-03-03
Linux Kernel MEDIUM 5.5
CVE-2017-6353

net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which all…

Fix: after 4.10
Fix from $1,600 2017-03-01
Linux Kernel HIGH 7.8
CVE-2017-6074EPSS 6%

The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the …

Fix: 3.2.86 / 3.10.106+
Fix from $1,950 2017-02-18
Fedora HIGH 7.8
CVE-2016-8693

Double free vulnerability in the mem_close function in jas_stream.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (c…

Fix: after 1.900.5
Fix from $1,950 2017-02-15