Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-415

MITRE ↗

CWE-415

103
CRITICAL
519
HIGH
168
MEDIUM
13
LOW
809 CVEs · Page 3/17
6.8
CVE-2026-56109

The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def()

6.7
CVE-2025-20786

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2026-21530

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-32170

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

6.5
CVE-2025-57785

A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticate

6.5
CVE-2026-43706

A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2,

6.4
CVE-2025-68657

Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hi

6.4
CVE-2026-4358

A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-fre

6.4
CVE-2026-10653

The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and t

6.3
CVE-2026-14604

A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporte

6.2
CVE-2026-31053

A double free vulnerability exists in librz/bin/format/le/le.c in the function le_load_fixup_record(). When processing m

6.2
CVE-2026-13713

YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on

6.1
CVE-2026-58381

A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function whe

5.9
CVE-2026-11893

The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetoo

5.9
CVE-2026-11894

The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the

5.9
CVE-2026-18663

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Sess

5.9
CVE-2026-75159

An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication m

5.8
CVE-2026-20026

Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an u

5.8
CVE-2026-46690

unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-v

5.6
CVE-2026-34867

Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affe

5.5
CVE-2026-20415

In imgsys, there is a possible memory corruption due to improper locking. This could lead to local denial of service if

5.5
CVE-2026-5657

iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

5.5
CVE-2026-17573

A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized c

5.5
CVE-2026-45202

Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possib

5.3
CVE-2025-13844

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious

5.3
CVE-2026-33995

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a double-free vulnerability in

5.3
CVE-2026-5186

A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb

5.1
CVE-2026-28537

Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availab

5.1
CVE-2026-23868

Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect erro

5.1
CVE-2026-6654

Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic

5.0
CVE-2025-61145

libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.

5.0
CVE-2026-35188

Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_requ

4.7
CVE-2026-32848

NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem

4.3
CVE-2026-55653

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group

3.7
CVE-2026-48850

PuTTY 0.72 before 0.84 has a double free in RSA KEX.

3.3
CVE-2025-12343

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in

3.3
CVE-2026-45324

Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cm

3.3
CVE-2025-15667

A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrit

2.5
CVE-2026-44348

PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_ha

CVE-2026-12659

A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of e

CVE-2026-55995

A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects

CVE-2026-63652

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels

CVE-2026-19316

A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to creat

9.8
CVE-2025-21673

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::ho

9.8
CVE-2025-38411

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix double put of request If a netfs reques

9.8
CVE-2025-38490

In the Linux kernel, the following vulnerability has been resolved: net: libwx: remove duplicate page_pool_put_full_pag

9.8
CVE-2023-53360

In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Rework scratch handling for READ_PLUS (aga

9.8
CVE-2022-50401

In the Linux kernel, the following vulnerability has been resolved: nfsd: under NFSv4.1, fix double svc_xprt_put on rpc

8.9
CVE-2025-55118

Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issu

8.8
CVE-2024-35365

FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically

Frequently Asked Questions

What is CWE-415?

CWE-415 (CWE-415) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-415?

There are 982 CVE records associated with CWE-415 in our database. Of these, 103 are critical severity, 519 are high severity, and 168 are medium severity.

How can I protect against CWE-415 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-415 using AI-powered security agents.

Detect CWE-415 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-415 vulnerabilities across your infrastructure.

Get Started