A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attack
Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec use
A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modificati
Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corr
A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PD
libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
Memory corruption in BTHOST due to double free while music playback and calls over bluetooth headset in Snapdragon Mobil
Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value cla
curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it set
The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avc_compute_poc function in av_parsers.c, which a
The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which
The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line funct
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7
Adobe Bridge version 11.1.1 (and earlier) is affected by a double free vulnerability when parsing a crafted DCM file, wh
ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.
A Double Free vulnerability allows remote malicious actors to execute arbitrary code on DWF file in Autodesk Navisworks
Tcpreplay v4.4.1 was discovered to contain a double-free via __interceptor_free.
drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_rele
A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions <
A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly hav
Memory corruption in multimedia driver due to double free while processing data from user in Snapdragon Auto
In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double free. This could lead t
LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.
Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to
Memory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Sn
A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneou
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, p
There is a Double free vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may
On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is configured on a virtual
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker co
There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is cop
An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packe
DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still use
io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent
SimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnera
A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap c
Memory corruption in video due to double free while parsing 3gp clip with invalid meta data atoms in Snapdragon Auto, Sn
Memory corruption in video driver due to double free while parsing ASF clip in Snapdragon Auto, Snapdragon Compute, Snap
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it may double-free some res
HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker c
In gasket_free_coherent_memory_all of gasket_page_table.c, there is a possible memory corruption due to a double free. T
In ccu, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege wit
In audio, there is a possible memory corruption due to a logic error. This could lead to local escalation of privilege w
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscal
In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double
There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1
A double-free vulnerability exists in the web interface /action/ipcamSetParamPost functionality of Abode Systems, Inc. i
diplib v3.0.0 is vulnerable to Double Free.
Frequently Asked Questions
What is CWE-415?
CWE-415 (CWE-415) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-415?
There are 982 CVE records associated with CWE-415 in our database. Of these, 103 are critical severity, 519 are high severity, and 168 are medium severity.
How can I protect against CWE-415 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-415 using AI-powered security agents.
Detect CWE-415 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-415 vulnerabilities across your infrastructure.
Get Started