Vulnerability index

Browse CVEs

809 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Double FreeCWE-415 × clear
MEDIUM 5.9 CVE-2026-18663 A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control… No fix yet Fix from $4,0002026-08-12 HIGH 7.0 CVE-2026-65780 Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.9106 / 10.0.26200.9106+ Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-62889 Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-62766 Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.9106 / 10.0.26100.33222+ Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-61366 Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 MEDIUM 5.9 CVE-2026-11894 The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-own… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.9 CVE-2026-11893 The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetooth/hci/hci_bflb.c, violates t… No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-20338 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. … No fix yet Fix from $1,9502026-08-07 HIGH 7.8 CVE-2026-43622 llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using m… No fix yet Fix from $1,9502026-08-06 HIGH 8.7 CVE-2026-55995 A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 5… No fix yet Fix from $1,9502026-07-29 MEDIUM 5.5 CVE-2026-17573 A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack … Hdf5 Fix unknown Fix from $1,6002026-07-27 HIGH 7.5 CVE-2026-66373 Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where… No fix yet Fix from $1,9502026-07-25 HIGH 8.8 CVE-2026-66032 libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicio… Libssh2 after 1.11.1 Fix from $1,9502026-07-24 HIGH 7.8 CVE-2026-64242 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: net2280: Fix double free in probe error path usb_initialize_gadget… Linux Kernel 5.10.259 / 5.15.210+ Fix from $1,9502026-07-24 HIGH 7.8 CVE-2026-64224 In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix double free in rvu_rep_rsrc_init() rvu_rep_rsrc_init() alloca… Linux Kernel 6.18.34 / 7.0.11+ Fix from $1,9502026-07-24 HIGH 7.0 CVE-2026-64222 In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack on AQ init failure otx2_pool_aq_… Linux Kernel 5.10.259 / 5.15.210+ Fix from $1,9502026-07-24 HIGH 7.5 CVE-2026-43823 When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deini… No fix yet Fix from $1,9502026-07-23 HIGH 8.8 CVE-2026-64832 FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows atta… Ffmpeg after 8.1.2 Fix from $1,9502026-07-22 HIGH 7.3 CVE-2026-64621 FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/commo… Freerdp 3.28.0+ Fix from $1,9502026-07-20 HIGH 8.4 CVE-2026-64118 In the Linux kernel, the following vulnerability has been resolved: qed: fix double free in qed_cxt_tables_alloc() If one of the later PF or VF CID… Linux Kernel 5.10.259 / 5.15.210+ Fix from $1,9502026-07-19 MEDIUM 6.2 CVE-2026-13713 YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In t… No fix yet Fix from $1,6002026-07-16 HIGH 7.8 CVE-2026-55132 Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps 16.0.19725.20434+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-50685 Double free in Windows DHCP Server allows an authorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-50361 Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.8875 / 10.0.26100.33158+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-55004 Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.7 CVE-2026-12659 A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when pr… Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.3 CVE-2026-14604 A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporter::ExportToBlob of the file c… No fix yet Fix from $1,6002026-07-03 CRITICAL 9.8 CVE-2026-8925 The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making… Curl 8.21.0+ Fix from $2,3002026-07-03 MEDIUM 6.1 CVE-2026-58381 A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially craf… Mitigation only Fix from $1,6002026-07-02 HIGH 8.1 CVE-2026-10653 The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and the per-data-block ref_count a… Zephyr after 4.4.1 Fix from $1,9502026-06-30