UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0
A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c,
The binary MP4Box in Gpac through 1.0.1 has a double-free vulnerability in the iloc_entry_del funciton in box_code_meta.
The binary MP4Box in Gpac 1.0.1 has a double-free bug in the av1dmx_finalize function in reframe_av1.c, which allows att
The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows atta
usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.
mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.
rpmsg_virtio_add_ctrl_dev in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.
rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.
A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
A vulnerability was found in Linux Kernel. It has been rated as problematic. Affected by this issue is the function sess
An issue was discovered in the containers crate before 0.9.11 for Rust. When a panic occurs, a util::{mutate,mutate2} do
An issue was discovered in the toodee crate before 0.3.0 for Rust. Row insertion can cause a double free upon an iterato
An issue was discovered in the scratchpad crate before 1.3.1 for Rust. The move_elements function can have a double-free
An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a double free
In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to
An issue was discovered in the through crate through 2021-02-18 for Rust. There is a double free (in through and through
An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in IdMap::clone_from up
An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in get_or_insert upon a
An issue was discovered in the id-map crate through 2021-02-26 for Rust. A double free can occur in remove_set upon a pa
In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than
In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the ele
Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in m
Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_pa
An issue was discovered in the sys-info crate before 0.8.0 for Rust. sys_info::disk_info calls can trigger a double free
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_sessi
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring
Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corrupti
GNU LibreDWG 0.12.3.4163 through 0.12.3.4191 has a double-free in bit_chain_free (called from dwg_encode_MTEXT and dwg_e
An issue was discovered in libredwg through v0.10.1.3751. dwg_free_MATERIAL_private() in dwg.spec has a double free.
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco
A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapd
Memory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto,
Possible memory corruption due to improper check when application loader object is explicitly destructed while applicati
A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability
A possible double free or invalid memory access in audio driver while reading Speaker Protection parameters in Snapdrago
A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitma
In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and
In main of main.cpp, there is a possible memory corruption due to a double free. This could lead to local escalation of
In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, liste
In setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalation of privilege in
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37
In memory management driver, there is a possible memory corruption due to a double free. This could lead to local escala
In memory management driver, there is a possible memory corruption due to a double free. This could lead to local escala
mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).
A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Ro
TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.r
Frequently Asked Questions
What is CWE-415?
CWE-415 (CWE-415) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-415?
There are 982 CVE records associated with CWE-415 in our database. Of these, 103 are critical severity, 519 are high severity, and 168 are medium severity.
How can I protect against CWE-415 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-415 using AI-powered security agents.
Detect CWE-415 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-415 vulnerabilities across your infrastructure.
Get Started