The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def()
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticate
A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2,
Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hi
A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-fre
The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and t
A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporte
A double free vulnerability exists in librz/bin/format/le/le.c in the function le_load_fixup_record(). When processing m
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on
A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function whe
The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetoo
The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Sess
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication m
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an u
unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-v
Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affe
In imgsys, there is a possible memory corruption due to improper locking. This could lead to local denial of service if
iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized c
Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possib
CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a double-free vulnerability in
A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb
Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availab
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect erro
Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic
libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_requ
NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in
Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cm
A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrit
PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_ha
A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of e
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels
A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to creat
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::ho
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix double put of request If a netfs reques
In the Linux kernel, the following vulnerability has been resolved: net: libwx: remove duplicate page_pool_put_full_pag
In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Rework scratch handling for READ_PLUS (aga
In the Linux kernel, the following vulnerability has been resolved: nfsd: under NFSv4.1, fix double svc_xprt_put on rpc
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issu
FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically
Frequently Asked Questions
What is CWE-415?
CWE-415 (CWE-415) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-415?
There are 982 CVE records associated with CWE-415 in our database. Of these, 103 are critical severity, 519 are high severity, and 168 are medium severity.
How can I protect against CWE-415 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-415 using AI-powered security agents.
Detect CWE-415 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-415 vulnerabilities across your infrastructure.
Get Started