CWE-415: Double Free
The product calls free() twice on the same memory address.
270 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-23918 — Apache HTTP Server: http2: double free and possible RCE on early reset
- CVE-2026-87585 — Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially exe
- CVE-2024-27099 — Azure IoT Platform Device SDK Double Free Vulnerability
- CVE-2024-23809 — A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig
- CVE-2024-22097 — A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Project libbiosig Maste
- CVE-2024-10934 — OpenBSD NFS double-free vulnerability
- CVE-2025-55118 — BMC Control-M/Agent memory corruption in SSL/TLS communication
- CVE-2026-21918 — Junos OS: SRX and MX Series: When TCP packets occur in a specific sequence flowd crashes
- CVE-2025-61990 — TMM vulnerability
- CVE-2025-53948 — Santesoft Sante PACS Server Double Free
- CVE-2024-39564 — Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to RPD crash
- CVE-2025-20134 — Cisco Adaptive Security Appliance and Firepower Threat Defense Software SSL/TLS Certificate Denial of Service Vulnerability
- CVE-2025-13844 — CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious
- CVE-2024-47404 — Liteos_a has a double free vulnerability
- CVE-2025-47396 — Double Free in Graphics
- CVE-2025-47356 — Double Free in Video
- CVE-2025-47316 — Double Free in Video
- CVE-2025-27051 — Double Free in Windows WLAN Host
- CVE-2025-27046 — Double Free in Display
- CVE-2025-21432 — Double Free in SPS-HLOS
Recently published
- CVE-2026-87585 — Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially exe
- CVE-2026-79907 — Acrobat Reader | Double Free (CWE-415)
- CVE-2026-82325 — A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated
- CVE-2026-20510 — In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalatio
- CVE-2026-33630 — c-ares : Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP
- CVE-2026-84964 — Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client
- CVE-2026-82677 — valkey-io valkey Module Timer module.c moduleTimerHandler double free
- CVE-2026-19316 — Fireware OS Pre-Authentication Double Free in iked Allows Denial of Service (DoS)
- CVE-2026-75159 — MongoDB BI Connector Improper Memory Handling During Failed Kerberos Authentication May Cause Process Termination
- CVE-2026-18798 — QUIC Server May Trigger Double Free When Processing INITIAL Packet
- CVE-2026-47895 — In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but no
- CVE-2026-45202 — GPU DDK - Silent High-Order CMA Memory Leak & Double Free in `_FreeOSPages_Fast`
- CVE-2026-63652 — FreeRDP: Double-free of `client_formats` in the rdpsnd server channel on a malformed Client Audio Formats PDU
- CVE-2026-18663 — 389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext() via critical session tracking control
- CVE-2026-11894 — Double-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` error paths
- CVE-2026-11893 — Double free / use-after-free in Bouffalo Lab HCI driver send() error paths (hci_bflb)
- CVE-2026-20338 — ClamAV ZIP File Format Processing Memory Corruption Vulnerability
- CVE-2026-43622 — llama.cpp b1886–b7445 Double Free via llama-android.cpp
- CVE-2026-55995 — Double-free in the iSNS attribute decoder in open-iscsi
- CVE-2026-17573 — Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field