Vulnerability index

Browse CVEs

810 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Double FreeCWE-415 × clear
Softcms HIGH 8.1
CVE-2016-8360

An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. A specially crafted URL request sent to the SoftCMS ASP Webserver can cause a …

Fix: after 1.5
Fix from $1,950 2017-02-13
Libgd CRITICAL 9.8
CVE-2016-6912

Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecifi…

Fix: after 2.2.3
Fix from $2,300 2017-01-26
Giflib CRITICAL 9.8
CVE-2016-3177

Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors.

Patch available
Fix from $2,300 2017-01-23
Linux Kernel HIGH 7.8
CVE-2016-9806

Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of serv…

Fix: 3.12.62 / 3.14.73+
Fix from $1,950 2016-12-28
Linux Kernel HIGH 7.3
CVE-2015-8962

Double free vulnerability in the sg_common_write function in drivers/scsi/sg.c in the Linux kernel before 4.4 allows local users to gain privileges o…

Fix: 3.2.85 / 3.10.107+
Fix from $1,950 2016-11-16
Fedora HIGH 7.8
CVE-2016-5384

fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free att…

Fix: 2.12.1+
Fix from $1,950 2016-08-13
PHP CRITICAL 9.8
CVE-2016-5772EPSS 10%

Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x be…

Fix: 5.5.37 / 5.6.23+
Fix from $2,300 2016-08-07
PHP CRITICAL 9.8
CVE-2016-3132EPSS 12%

Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to e…

Patch available
Fix from $2,300 2016-08-07
PHP CRITICAL 9.8
CVE-2015-8880

Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error.

Mitigation only
Fix from $2,300 2016-05-22
Windows 8.1 HIGH 7.2
CVE-2015-0058

Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local …

Patch available
Fix from $1,950 2015-02-11
Debian Linux HIGH 7.6
CVE-2014-4343EPSS 6%

Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1…

Patch available
Fix from $1,950 2014-08-14
Windows 7 HIGH 7.2
CVE-2014-1767EPSS 13%

Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows …

No fix yet
Fix from $1,950 2014-07-08
Enterprise Linux Desktop HIGH 8.8
CVE-2014-0502 KEVEPSS 24%

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.…

Fix: 4.0.0.1628 / 11.2.202.341+
Fix from $1,950 2014-02-21
Pages HIGH 7.5
CVE-2014-1252

Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of ser…

Fix: after 10.9.1
Fix from $1,950 2014-01-24
Chrome HIGH 7.5
CVE-2011-3892

Double free vulnerability in the Theora decoder in Google Chrome before 15.0.874.120 allows remote attackers to cause a denial of service or possibly…

Fix: 15.0.874.120+
Fix from $1,950 2011-11-11
Chrome MEDIUM 6.8
CVE-2011-2834

Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly …

Fix: 6.0 / 10.7.4+
Fix from $1,600 2011-09-19
Chrome HIGH 7.5
CVE-2011-2821

Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly …

Fix: 6.0 / 10.7.4+
Fix from $1,950 2011-08-29
Windows 2003 Server HIGH 7.3
CVE-2010-3957

Double free vulnerability in the OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, …

Mitigation only
Fix from $1,950 2010-12-16
Chrome HIGH 7.5
CVE-2010-4494EPSS 8%

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attacker…

Fix: 5.0.4 / 8.0.552.215+
Fix from $1,950 2010-12-07
Linux Kernel HIGH 7.2
CVE-2010-3080

Double free vulnerability in the snd_seq_oss_open function in sound/core/seq/oss/seq_oss_init.c in the Linux kernel before 2.6.36-rc4 might allow loc…

Fix: 2.6.36+
Fix from $1,950 2010-09-21
Windows 2003 Server HIGH 8.8
CVE-2009-1544EPSS 21%

Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC mess…

Mitigation only
Fix from $1,950 2009-08-12
Ubuntu Linux HIGH 9.0
CVE-2007-1216EPSS 10%

Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 be…

Fix: 1.6.1+
Fix from $1,950 2007-04-06
Debian Linux HIGH 8.1
CVE-2006-5051EPSS 45%

Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code…

Fix: 10.3.9+
Fix from $1,950 2006-09-27
Debian Linux CRITICAL 9.8
CVE-2005-1689EPSS 11%

Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code …

Fix: 10.4.2+
Fix from $2,300 2005-07-18
Gtk HIGH 7.5
CVE-2005-0891

Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.

Fix: 2.2.4+
Fix from $1,950 2005-05-02
Debian Linux CRITICAL 9.8
CVE-2004-0772EPSS 7%

Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbit…

Fix: after 1.2.8
Fix from $2,300 2004-10-20
Debian Linux HIGH 7.5
CVE-2004-0642EPSS 8%

Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for…

Fix: after 1.3.4
Fix from $1,950 2004-09-28
Internet Explorer HIGH 7.8
CVE-2003-1048EPSS 27%

Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (applicati…

Patch available
Fix from $1,950 2004-07-27
FreeBSD HIGH 7.5
CVE-2003-0015EPSS 24%

Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a ma…

Patch available
Fix from $1,950 2003-02-07
Zlib CRITICAL 9.8
CVE-2002-0059EPSS 10%

The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateEnd to release certain memory …

Fix: after 1.1.3
Fix from $2,300 2002-03-15