Vulnerabilities > Double Free

DATE CVE VULNERABILITY TITLE RISK
2018-12-20 CVE-2018-1000877 Double Free vulnerability in multiple products
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0 that can result in Crash/DoS.
8.8
2018-12-20 CVE-2018-11987 Double Free vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, if there is an unlikely memory alloc failure for the secure pool in boot, it can result in wrong pointer access causing kernel panic.
local
low complexity
google CWE-415
4.6
2018-12-06 CVE-2018-9553 Double Free vulnerability in Google Android
In MasteringMetadata::Parse of mkvparser.cc there is a possible double free due to an insecure default value.
network
google CWE-415
critical
9.3
2018-11-28 CVE-2018-16841 Double Free vulnerability in multiple products
Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service.
network
low complexity
samba canonical debian CWE-415
4.0
2018-11-27 CVE-2018-11918 Double Free vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, memory allocated is automatically released by the kernel if the 'probe' function fails with an error code.
local
low complexity
google CWE-415
4.6
2018-11-27 CVE-2018-11823 Double Free vulnerability in Google Android
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, freeing device memory in driver probe failure will result in double free issue in power module.
local
low complexity
google CWE-415
4.6
2018-11-06 CVE-2018-9415 Double Free vulnerability in multiple products
In driver_override_store and driver_override_show of bus.c, there is a possible double free due to improper locking.
local
low complexity
google canonical CWE-415
4.6
2018-11-06 CVE-2018-9356 Double Free vulnerability in Google Android
In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free.
network
low complexity
google CWE-415
critical
10.0
2018-10-29 CVE-2018-18751 Double Free vulnerability in multiple products
An issue was discovered in GNU gettext 0.19.8.
network
low complexity
gnu canonical redhat CWE-415
7.5
2018-10-29 CVE-2018-18718 Double Free vulnerability in multiple products
An issue was discovered in gThumb through 3.6.2.
local
low complexity
gnome debian CWE-415
4.6