In Confirmation of keystore_cli_v2.cpp, there is a possible way to corrupt memory due to a double free. This could lead
A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the devic
hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_con
Visual Studio Remote Code Execution Vulnerability
In adreno_set_param of adreno_gpu.c, there is a possible memory corruption due to a double free. This could lead to loca
Windows Geolocation Service Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Double free issue exists in Kostac PLC Programming Software Version 1.6.11.0 and earlier. Arbitrary code may be executed
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a double free via the gf_filterpacket_del function at /
In multiple locations, there is a possible way to corrupt memory due to a double free. This could lead to local escalati
The DUBAI module has a double free vulnerability. Successful exploitation of this vulnerability may affect system availa
The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any h
A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, duri
xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method.
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
stb_image is a single file MIT licensed library for processing images. A crafted image file can trigger `stbi__load_gif_
stb_image is a single file MIT licensed library for processing images. It may look like `stbi__load_gif_main` doesn’t g
stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allo
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
Windows Filtering Platform Elevation of Privilege Vulnerability
A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
Memory corruption in display due to double free while allocating frame buffer memory
Memory corruption in Linux android due to double free while calling unregister provider after register call.
A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. Th
In rpmb , there is a possible double free due to improper locking. This could lead to local escalation of privilege with
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed i
An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComp
Hnswlib 0.7.0 has a double free in init_index when the M argument is a large integer.
Double Free vulnerability in Nothings Stb Image.h v.2.28 allows a remote attacker to cause a denial of service via a cra
Double free in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable informa
Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows loca
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was
A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resour
Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function wit
Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or co
A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop
In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for register
Samsung Mobile Processor Exynos 2200 allows a GPU Double Free (issue 1 of 2).
There is a Double free vulnerability in Smartphone.Successful exploitation of this vulnerability may cause a kernel cras
A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-
A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remo
Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to
Frequently Asked Questions
What is CWE-415?
CWE-415 (CWE-415) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-415?
There are 982 CVE records associated with CWE-415 in our database. Of these, 103 are critical severity, 519 are high severity, and 168 are medium severity.
How can I protect against CWE-415 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-415 using AI-powered security agents.
Detect CWE-415 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-415 vulnerabilities across your infrastructure.
Get Started