In the Linux kernel, the following vulnerability has been resolved: net: usb: lan78xx: Fix double free issue with inter
In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix potential double remove of hotplug sl
In the Linux kernel, the following vulnerability has been resolved: EDAC/igen6: Avoid segmentation fault on module unlo
A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a n
A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(fre
Double-Free Vulnerability in uD3TN BPv7 Caused by Malformed Endpoint Identifier allows remote attacker to reliably cause
In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free.
A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulner
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix the double free in rvu_npc_freeme
Windows USB Print Driver Elevation of Privilege Vulnerability
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix double free of the ha->vp_map po
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix double free err_addr pointer warnin
Azure IoT SDK Remote Code Execution Vulnerability
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix the double free in scmi_deb
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
Memory corruption when IPv6 prefix timer object`s lifetime expires which are created while Netmgr daemon gets an IPv6 ad
Linux Kernel Bluetooth CMTP Module Double Free Privilege Escalation Vulnerability. This vulnerability allows local attac
Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.
A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileged attacker
In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridg
This issue tracks two CWE-416 Use After Free (UAF) and one CWE-415 Double Free vulnerabilities in Goahead versions <= 6.
In the Linux kernel, the following vulnerability has been resolved: iio: core: fix ioctl handlers removal Currently io
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix double free in SMC transpor
In the Linux kernel, the following vulnerability has been resolved: tcp: fix tcp_init_transfer() to not reset icsk_ca_i
In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Only free buffer VA that i
It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the h
The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net
Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availabil
Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availabil
Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a windo
In the Linux kernel, the following vulnerability has been resolved: nvme-fc: do not wait in vain when unloading module
In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls
Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a bu
In the Linux kernel, the following vulnerability has been resolved: net: pds_core: Fix possible double free in error ha
Inconsistent handling of error cases in bluetooth hci may lead to a double free condition of a network buffer.
Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pi
A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004,
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a
Memory corruption due to double free in core while initializing the encryption key.
kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated
A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.
A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unaut
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). I
Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed.
Memory corruption due to double free in Core while mapping HLOS address to the list.
Memory corruption in Linux Networking due to double free while handling a hyp-assign.
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
TensorFlow is an open source machine learning platform. Prior to versions 2.12.0 and 2.11.1, `nn_ops.fractional_avg_pool
A double free in Fortinet FortiWeb version 7.0.0 through 7.0.3 may allows attacker to execute unauthorized code or comma
Windows Media Remote Code Execution Vulnerability
Frequently Asked Questions
What is CWE-415?
CWE-415 (CWE-415) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-415?
There are 982 CVE records associated with CWE-415 in our database. Of these, 103 are critical severity, 519 are high severity, and 168 are medium severity.
How can I protect against CWE-415 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-415 using AI-powered security agents.
Detect CWE-415 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-415 vulnerabilities across your infrastructure.
Get Started