Vulnerabilities > Double Free

DATE CVE VULNERABILITY TITLE RISK
2017-11-22 CVE-2017-6166 Double Free vulnerability in F5 products
In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management Microkernel (TMM) may crash when processing fragmented packets.
network
high complexity
f5 CWE-415
5.9
2017-11-17 CVE-2017-1000232 Double Free vulnerability in Nlnetlabs Ldns 1.7.0
A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.
network
low complexity
nlnetlabs CWE-415
critical
9.8
2017-11-17 CVE-2017-1000231 Double Free vulnerability in Nlnetlabs Ldns 1.7.0
A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.
network
low complexity
nlnetlabs CWE-415
critical
9.8
2017-11-16 CVE-2017-11032 Double Free vulnerability in Google Android
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a double free can occur when kmalloc fails to allocate memory for pointers resp/req in the service-locator driver function service_locator_send_msg().
local
low complexity
google CWE-415
7.8
2017-11-14 CVE-2017-16820 Double Free vulnerability in Collectd
The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other impact).
network
low complexity
collectd CWE-415
critical
9.8
2017-10-24 CVE-2017-15186 Double Free vulnerability in Ffmpeg
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
network
low complexity
ffmpeg CWE-415
6.5
2017-10-22 CVE-2015-5177 Double Free vulnerability in multiple products
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.
network
low complexity
openslp debian CWE-415
7.5
2017-10-18 CVE-2015-1239 Double Free vulnerability in multiple products
Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.
network
low complexity
uclouvain google debian CWE-415
6.5
2017-10-16 CVE-2017-14952 Double Free vulnerability in Icu-Project International Components for Unicode
Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue.
network
low complexity
icu-project CWE-415
critical
9.8
2017-10-15 CVE-2017-15364 Double Free vulnerability in Ccsv Project Ccsv 1.1.0
The foreach function in ext/ccsv.c in Ccsv 1.1.0 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact via a crafted file.
local
low complexity
ccsv-project CWE-415
5.5