The product calls free() twice on the same memory address.
Volume of CVEs assigned to CWE-415 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
819 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0101CRITICAL A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause | Jan 29, 2018 | 10.0 | 86 | NO | YES |
CVE-2018-4990HIGH Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation c | Jul 9, 2018 | 8.8 | 83 | YES | NO |
CVE-2026-23918HIGH Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
This issue affects Apache HTTP Server: 2.4.66.
Users are recommended to upgrade to vers | May 4, 2026 | 8.8 | 82 | NO | YES |
CVE-2025-62215HIGH Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | Nov 11, 2025 | 7.0 | 80 | YES | YES |
CVE-2014-0502HIGH Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR b | Feb 21, 2014 | 8.8 | 78 | YES | NO |
CVE-2003-0545CRITICAL Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a cer | Nov 17, 2003 | 9.8 | 76 | NO | NO |
CVE-2026-33824CRITICAL Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. | Apr 14, 2026 | 9.8 | 71 | NO | NO |
CVE-2023-25136MEDIUM OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unaut | Feb 3, 2023 | 6.5 | 71 | NO | NO |
CVE-2021-22600HIGH A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgr | Jan 26, 2022 | 7.0 | 64 | YES | NO |
CVE-2019-11932HIGH A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19. | Oct 3, 2019 | 8.8 | 64 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.