CWE-415: CWE-415

241
Total CVEs
25
Critical
192
High
7.8
Avg CVSS

Yearly Trend

2026
13
2025
79
2024
72
2023
22
2022
20

Top Affected Vendors

1 Linux 106
2 Microsoft 25
3 Debian 17
4 Google 11
5 Qualcomm 11
6 Fedoraproject 9
7 Huawei 7
8 Netapp 4
9 Cisco 3
10 Openbsd 3

All CWE-415 CVEs (241)

CVE-2025-21183
7.4

This vulnerability allows an authenticated attacker to exploit the Windows Resilient File System (ReFS) Deduplication Service to gain SYSTEM privilege...

Feb 11, 2025
CVE-2024-44098
7.4

CVE-2024-44098 is a double-free vulnerability in Android's Low-Level Wearable Interface Subsystem (LWIS) that allows local privilege escalation withou...

Oct 25, 2024
CVE-2023-41325
7.4

CVE-2023-41325 is a double-free vulnerability in OP-TEE's TA binary signature verification function. This allows attackers to potentially corrupt memo...

Sep 15, 2023
CVE-2023-45664
7.3

A double-free vulnerability in stb_image library allows crafted GIF images to cause memory corruption. This affects any application using vulnerable v...

Oct 21, 2023
CVE-2023-45679
7.3

CVE-2023-45679 is a double-free vulnerability in stb_vorbis library that occurs when processing malicious Ogg Vorbis files. If exploited, it could lea...

Oct 21, 2023
CVE-2022-40515
7.3

This vulnerability allows memory corruption through a double-free error when processing specially crafted 3gp video files with invalid metadata atoms....

Mar 10, 2023
CVE-2022-22086
7.3

This vulnerability allows memory corruption through a double free error when parsing malformed 3gp video files with invalid metadata atoms. It affects...

Jun 14, 2022
CVE-2021-1910
7.3

This vulnerability is a double-free memory corruption flaw in Qualcomm Snapdragon video processing components. It allows attackers to potentially exec...

May 7, 2021
CVE-2024-27127
7.2

This double free vulnerability in QNAP operating systems allows authenticated attackers to execute arbitrary code remotely. It affects multiple QNAP N...

May 21, 2024
CVE-2024-36030
7.1

This CVE describes a double-free memory corruption vulnerability in the Linux kernel's octeontx2-af driver. The flaw occurs when the rvu_npc_freemem()...

May 30, 2024
CVE-2021-28041
7.1

This CVE describes a double-free vulnerability in ssh-agent component of OpenSSH versions before 8.5. It could allow attackers to potentially execute ...

Mar 5, 2021
CVE-2026-20863
7.0

This vulnerability involves a double-free memory corruption flaw in the Windows Win32K ICOMP component. An authenticated attacker could exploit this t...

Jan 13, 2026
CVE-2025-59289
7.0

A double free vulnerability in Windows Bluetooth Service allows authenticated attackers to execute arbitrary code with elevated SYSTEM privileges. Thi...

Oct 14, 2025
CVE-2025-37915
7.0

A double-free vulnerability in the Linux kernel's DRR (Deficit Round Robin) qdisc scheduler occurs when netem is used as a child qdisc, causing reentr...

May 20, 2025
CVE-2024-49095
7.0

This vulnerability allows an authenticated attacker to exploit the Windows PrintWorkflowUserSvc service to gain SYSTEM-level privileges on affected Wi...

Dec 12, 2024
CVE-2024-38157
7.0

This vulnerability in Azure IoT SDK allows remote attackers to execute arbitrary code on affected systems by exploiting a double-free memory corruptio...

Aug 13, 2024
CVE-2024-21445
7.0

This vulnerability allows an authenticated attacker to exploit the Windows USB Print Driver to gain SYSTEM-level privileges on affected systems. It af...

Mar 12, 2024
CVE-2023-45584
6.6

A double free vulnerability in multiple Fortinet products allows privileged attackers to execute arbitrary code or commands via crafted HTTP/HTTPS req...

Aug 12, 2025
CVE-2025-57785
6.5

A double free vulnerability in the XSLT show_index function of Hiawatha webserver version 11.7 allows unauthenticated attackers to corrupt memory, pot...

Jan 26, 2026
CVE-2025-23096
6.5

A double free vulnerability in Samsung Exynos mobile processors allows local attackers to escalate privileges on affected devices. This affects smartp...

Jun 4, 2025
CVE-2025-4574
6.5

A race condition in crossbeam-channel's Channel type Drop implementation can cause double-free memory corruption when channels are dropped concurrentl...

May 13, 2025
CVE-2025-68657
6.4

This CVE describes a double-free vulnerability in Espressif ESP-IDF USB Host HID Driver that can corrupt heap metadata. Attackers could potentially cr...

Jan 12, 2026
CVE-2024-3187
5.9

CVE-2024-3187 involves memory corruption vulnerabilities (Use After Free and Double Free) in Goahead web server when JavaScript templates are processe...

Oct 17, 2024
CVE-2026-20026
5.8

This vulnerability in Cisco products allows unauthenticated remote attackers to cause Snort 3 Detection Engine to leak sensitive information or restar...

Jan 7, 2026
CVE-2026-20415
5.5

This vulnerability in the imgsys component allows memory corruption due to improper locking. It enables local denial of service attacks when exploited...

Feb 2, 2026
CVE-2025-39914
5.5

This is a double-free vulnerability in the Linux kernel's tracing subsystem where fault injection during memory allocation can cause the same tracepoi...

Oct 1, 2025
CVE-2023-53360
5.5

A double-free vulnerability in the Linux kernel's NFSv4.2 READ_PLUS implementation could cause kernel crashes (oops) when processing certain network f...

Sep 17, 2025
CVE-2025-38186
5.5

A double-free vulnerability in the Linux kernel's bnxt_en driver allows local attackers to cause a kernel panic (denial of service) by triggering mult...

Jul 4, 2025
CVE-2025-37933
5.5

A double-free vulnerability in the Linux kernel's octeon_ep driver can cause host system hangs when the driver is unloaded after losing heartbeat mess...

May 20, 2025
CVE-2025-37779
5.5

A double-free vulnerability in the Linux kernel's lib/iov_iter component allows memory corruption when processing I/O operations with non-slab folios....

May 1, 2025
CVE-2022-49203
5.5

This CVE describes a double-free vulnerability in the AMD display driver component of the Linux kernel that occurs during GPU reset operations. The vu...

Feb 26, 2025
CVE-2024-50152
5.5

This CVE describes a double-free memory corruption vulnerability in the Linux kernel's SMB client implementation. An attacker could potentially cause ...

Nov 7, 2024
CVE-2024-42234
5.5

A race condition in the Linux kernel's memory management subsystem can cause crashes or kernel panics when large memory pages are being migrated while...

Aug 7, 2024
CVE-2023-52888
5.5

This CVE addresses a double-free vulnerability in the MediaTek vcodec driver in the Linux kernel where buffer virtual addresses (VAs) could be freed m...

Jul 30, 2024
CVE-2023-52739
5.5

This CVE describes a double-free vulnerability in the Linux kernel's memory management subsystem. A race condition in the __free_pages function can ca...

May 21, 2024
CVE-2025-13844
5.3

A double free vulnerability in Rapsody software allows attackers to cause heap memory corruption by tricking users into importing malicious SSD projec...

Jan 15, 2026
CVE-2026-28537
5.1

A double free vulnerability in the window module could allow attackers to crash affected systems, potentially causing denial of service. This affects ...

Mar 5, 2026
CVE-2025-65955
4.9

This CVE describes a double-free vulnerability in ImageMagick's Magick++ layer when Options::fontFamily is called with an empty string. This can lead ...

Dec 2, 2025
CVE-2024-53698
4.9

A double free vulnerability in QNAP operating systems could allow remote attackers with administrator access to modify memory, potentially leading to ...

Mar 7, 2025
CVE-2023-52383
4.7

A double-free vulnerability in the RSMC module of Huawei devices running HarmonyOS allows attackers to cause denial of service by freeing the same mem...

May 14, 2024
CVE-2024-42123
4.4

This CVE describes a double-free vulnerability in the AMD GPU driver within the Linux kernel. When triggered, it could cause kernel crashes or potenti...

Jul 30, 2024

About CWE-415 (CWE-415)

Our database tracks 241 CVEs classified as CWE-415, with 25 rated critical and 192 rated high severity. The average CVSS score for CWE-415 vulnerabilities is 7.8.

External reference: View CWE-415 on MITRE CWE →

Monitor CWE-415 Vulnerabilities

Get alerted when new CWE-415 CVEs affect your infrastructure.

Start Monitoring Free