CWE-415: CWE-415

241
Total CVEs
25
Critical
192
High
7.8
Avg CVSS

Yearly Trend

2026
13
2025
79
2024
72
2023
22
2022
20

Top Affected Vendors

1 Linux 106
2 Microsoft 25
3 Debian 17
4 Google 11
5 Qualcomm 11
6 Fedoraproject 9
7 Huawei 7
8 Netapp 4
9 Cisco 3
10 Openbsd 3

All CWE-415 CVEs (241)

CVE-2024-26704
7.8

A double-free vulnerability in the Linux kernel's ext4 filesystem can lead to kernel panic and system crashes. This occurs when moving extents with ov...

Apr 3, 2024
CVE-2024-26694
7.8

This vulnerability is a double-free memory corruption bug in the iwlwifi driver in the Linux kernel. It allows attackers to potentially crash the syst...

Apr 3, 2024
CVE-2024-26653
7.8

This CVE describes a double-free vulnerability in the Linux kernel's ljca USB driver. When auxiliary_device_add() fails, the driver's error handling p...

Apr 1, 2024
CVE-2021-47123
7.8

This CVE describes a double-free vulnerability in the Linux kernel's io_uring subsystem. It allows attackers with local access to potentially cause me...

Mar 15, 2024
CVE-2021-46938
7.8

This CVE describes a double-free vulnerability in the Linux kernel's device-mapper request-based (dm-rq) subsystem. When loading a device-mapper table...

Feb 27, 2024
CVE-2023-40103
7.8

This CVE describes a double-free memory corruption vulnerability in Android's framework/base component that allows local privilege escalation without ...

Dec 4, 2023
CVE-2023-41374
7.8

A double free vulnerability in Kostac PLC Programming Software allows arbitrary code execution when users open specially crafted project files. This a...

Sep 20, 2023
CVE-2023-35371
7.8

This vulnerability in Microsoft Office allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially craft...

Aug 8, 2023
CVE-2023-33161
7.8

CVE-2023-33161 is a double-free vulnerability (CWE-415) in Microsoft Excel that allows remote code execution when a user opens a specially crafted mal...

Jul 11, 2023
CVE-2023-33137
7.8

This vulnerability allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted Excel file. It af...

Jun 14, 2023
CVE-2023-21106
7.8

This CVE describes a double-free vulnerability in the Adreno GPU driver for Android kernels, which could allow local attackers to corrupt memory and e...

May 15, 2023
CVE-2023-28464
7.8

This vulnerability is a use-after-free and double-free flaw in the Linux kernel's Bluetooth subsystem that can lead to privilege escalation. Attackers...

Mar 31, 2023
CVE-2023-21030
7.8

This CVE describes a double-free vulnerability in Android's keystore component that allows local privilege escalation. An unprivileged process can cor...

Mar 24, 2023
CVE-2022-40683
7.8

CVE-2022-40683 is a double-free vulnerability in Fortinet FortiWeb web application firewalls that could allow attackers to execute arbitrary code or c...

Feb 16, 2023
CVE-2021-39806
7.8

This CVE describes a double-free vulnerability in Android's label_backends_android.c that could allow local privilege escalation during servicemanager...

Jun 15, 2022
CVE-2021-42613
7.8

CVE-2021-42613 is a double-free vulnerability in Halibut's cleanup_index function that allows attackers to cause denial of service or potentially exec...

May 24, 2022
CVE-2022-29032
7.8

This vulnerability allows attackers to execute arbitrary code by exploiting a double-free memory corruption flaw in the CGM_NIST_Loader.dll library wh...

May 20, 2022
CVE-2022-29156
7.8

CVE-2022-29156 is a double-free vulnerability in the Linux kernel's RDMA Transport (RTRS) client driver that could allow local attackers to cause a ke...

Apr 13, 2022
CVE-2022-27416
7.8

CVE-2022-27416 is a double-free vulnerability in Tcpreplay v4.4.1 that allows attackers to execute arbitrary code or cause denial of service by exploi...

Apr 12, 2022
CVE-2022-28390
7.8

This vulnerability is a double-free memory corruption flaw in the EMS CAN-USB driver in the Linux kernel. It allows local attackers to potentially cra...

Apr 3, 2022
CVE-2021-42533
7.8

Adobe Bridge versions 11.1.1 and earlier contain a double free vulnerability when processing malicious DCM files. This could allow attackers to execut...

Mar 16, 2022
CVE-2021-46621
7.8

This is a double-free vulnerability in Bentley MicroStation CONNECT's JT file parser that allows remote code execution. Attackers can exploit it by tr...

Feb 18, 2022
CVE-2021-46625
7.8

CVE-2021-46625 is a double-free vulnerability in Bentley View's JT file parser that allows remote code execution when a user opens a malicious JT file...

Feb 18, 2022
CVE-2021-40574
7.8

CVE-2021-40574 is a double-free vulnerability in Gpac's MP4Box binary that allows attackers to cause denial of service, execute arbitrary code, or esc...

Jan 13, 2022
CVE-2021-40570
7.8

A double-free vulnerability in Gpac's MP4Box allows attackers to cause denial of service or potentially execute arbitrary code. This affects systems r...

Jan 13, 2022
CVE-2021-30703
7.8

This CVE describes a double free vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileges....

Sep 8, 2021
CVE-2021-22425
7.8

This CVE describes a double free vulnerability in HarmonyOS that allows local attackers to gain root privileges. The vulnerability affects Huawei devi...

Aug 3, 2021
CVE-2021-31449
7.8

This vulnerability in Foxit Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing spe...

May 7, 2021
CVE-2021-0437
7.8

This CVE describes a double-free vulnerability in Android's DRM plugin that could allow local privilege escalation. Attackers could exploit this to ga...

Apr 13, 2021
CVE-2021-29627
7.8

A double-free vulnerability in FreeBSD's accept filter implementation allows attackers to potentially execute arbitrary code or cause denial of servic...

Apr 7, 2021
CVE-2019-19005
7.8

CVE-2019-19005 is a double-free vulnerability in autotrace 0.31.1 that allows attackers to cause memory corruption by processing a malformed bitmap im...

Feb 11, 2021
CVE-2026-25556
7.5

MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in the barcode decoding functionality. When processing specially crafted inpu...

Feb 6, 2026
CVE-2026-21918
7.5

A double free vulnerability in Juniper's flow processing daemon (flowd) allows unauthenticated attackers to cause denial-of-service by sending a speci...

Jan 15, 2026
CVE-2025-53948
7.5

CVE-2025-53948 is a denial-of-service vulnerability in Sante PACS Server where a remote attacker can crash the main thread by sending a specially craf...

Aug 18, 2025
CVE-2025-5262
7.5

A double-free vulnerability in Thunderbird's WebRTC encoder initialization could cause memory corruption and potentially exploitable crashes. This aff...

May 27, 2025
CVE-2024-39564
7.5

A double-free vulnerability in Juniper Junos OS and Junos OS Evolved routing process daemon (rpd) allows attackers to cause denial of service by sendi...

Feb 5, 2025
CVE-2024-2002
7.5

A double-free vulnerability in libdwarf allows memory corruption when processing specially crafted DWARF debugging information files. This could lead ...

Mar 18, 2024
CVE-2023-38434
7.5

CVE-2023-38434 is a double-free vulnerability in xHTTP's close_connection function that can be triggered via malformed HTTP request methods. This allo...

Jul 18, 2023
CVE-2022-4450
7.5

A double-free vulnerability in OpenSSL's PEM parsing functions allows attackers to cause denial of service through specially crafted PEM files. The vu...

Feb 8, 2023
CVE-2021-41688
7.5

CVE-2021-41688 is a double-free vulnerability in DCMTK's dcmqrdb program that allows attackers to cause denial of service by sending specific requests...

Jun 28, 2022
CVE-2022-31291
7.5

CVE-2022-31291 is a double-free vulnerability in dlt-daemon's configuration file parser that allows attackers to cause memory corruption via crafted T...

Jun 16, 2022
CVE-2021-4091
7.5

CVE-2021-4091 is a double-free vulnerability in 389 Directory Server's handling of virtual attributes during persistent searches. An attacker can send...

Feb 18, 2022
CVE-2021-40038
7.5

CVE-2021-40038 is a double free vulnerability in the AOD (Always On Display) module of Huawei smartphones running HarmonyOS. This memory corruption fl...

Jan 10, 2022
CVE-2021-31996
7.5

This vulnerability in the algorithmica Rust crate allows double-free memory corruption in the merge_sort::merge() function. Attackers can potentially ...

May 3, 2021
CVE-2021-22332
7.5

A double free vulnerability in Huawei CloudEngine switches allows attackers to cause memory corruption by freeing the same pointer twice. This can lea...

Apr 28, 2021
CVE-2021-29929
7.5

This vulnerability in the endian_trait Rust crate allows double-free memory corruption when a user-provided Endian implementation panics. This affects...

Apr 1, 2021
CVE-2021-29931
7.5

This vulnerability in the arenavec Rust crate allows double-free memory corruption when a panic occurs during object destruction. It affects Rust appl...

Apr 1, 2021
CVE-2021-29933
7.5

This vulnerability in the insert_many Rust crate allows double-free memory corruption when the .next() method panics, potentially leading to use-after...

Apr 1, 2021
CVE-2021-29938
7.5

This vulnerability in the Rust slice-deque crate allows a double free/double drop condition when a panic occurs in a predicate function during SliceDe...

Apr 1, 2021
CVE-2025-21182
7.4

This vulnerability allows an authenticated attacker to exploit the Windows Resilient File System (ReFS) Deduplication Service to gain SYSTEM privilege...

Feb 11, 2025

About CWE-415 (CWE-415)

Our database tracks 241 CVEs classified as CWE-415, with 25 rated critical and 192 rated high severity. The average CVSS score for CWE-415 vulnerabilities is 7.8.

External reference: View CWE-415 on MITRE CWE →

Monitor CWE-415 Vulnerabilities

Get alerted when new CWE-415 CVEs affect your infrastructure.

Start Monitoring Free