Total
483 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-11032 | 1 Google | 1 Android | 2017-11-30 | 4.6 MEDIUM | 7.8 HIGH |
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a double free can occur when kmalloc fails to allocate memory for pointers resp/req in the service-locator driver function service_locator_send_msg(). | |||||
CVE-2017-15186 | 1 Ffmpeg | 1 Ffmpeg | 2017-11-29 | 4.3 MEDIUM | 6.5 MEDIUM |
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file. | |||||
CVE-2015-5177 | 2 Debian, Openslp | 2 Debian Linux, Openslp | 2017-11-07 | 5.0 MEDIUM | 7.5 HIGH |
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package. | |||||
CVE-2017-6353 | 1 Linux | 1 Linux Kernel | 2017-11-04 | 4.9 MEDIUM | 5.5 MEDIUM |
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986. | |||||
CVE-2017-10914 | 1 Xen | 1 Xen | 2017-11-04 | 6.8 MEDIUM | 8.1 HIGH |
The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA-218 bug 2. | |||||
CVE-2016-6912 | 1 Libgd | 1 Libgd | 2017-11-04 | 7.5 HIGH | 9.8 CRITICAL |
Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values. | |||||
CVE-2017-15364 | 1 Ccsv Project | 1 Ccsv | 2017-11-01 | 4.3 MEDIUM | 5.5 MEDIUM |
The foreach function in ext/ccsv.c in Ccsv 1.1.0 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact via a crafted file. | |||||
CVE-2017-9686 | 1 Google | 1 Android | 2017-10-19 | 4.6 MEDIUM | 7.8 HIGH |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a possible double free/use after free in the SPS driver when debugfs logging is used. | |||||
CVE-2017-9687 | 1 Google | 1 Android | 2017-10-19 | 4.6 MEDIUM | 7.8 HIGH |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, two concurrent threads/processes can write the value of "0" to the debugfs file that controls ipa ipc log which will lead to the double-free in ipc_log_context_destroy(). Another issue is the Use-After-Free which can happen due to the race condition when the ipc log is deallocated via the debugfs call during a log print. | |||||
CVE-2015-7700 | 1 Pngcrush Project | 1 Pngcrush | 2017-09-05 | 7.5 HIGH | 9.8 CRITICAL |
Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors. | |||||
CVE-2017-12925 | 1 Libfpx Project | 1 Libfpx | 2017-09-01 | 4.3 MEDIUM | 6.5 MEDIUM |
Double free vulnerability in DfFromLB in docfile.cxx in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service via a crafted fpx image. | |||||
CVE-2014-1252 | 1 Apple | 3 Iphone Os, Mac Os X, Pages | 2017-08-29 | 7.5 HIGH | N/A |
Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file. | |||||
CVE-2017-8265 | 1 Google | 1 Android | 2017-08-22 | 5.1 MEDIUM | 7.0 HIGH |
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a video driver which can lead to a double free. | |||||
CVE-2017-1000072 | 1 Creolabs | 1 Gravity | 2017-07-19 | 7.5 HIGH | 9.8 CRITICAL |
Creolabs Gravity version 1.0 is vulnerable to a Double Free in gravity_value resulting potentially leading to modification of unexpected memory locations | |||||
CVE-2017-2425 | 1 Apple | 1 Mac Os X | 2017-07-12 | 6.8 MEDIUM | 7.8 HIGH |
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "SecurityFoundation" component. A double free vulnerability allows remote attackers to execute arbitrary code via a crafted certificate. | |||||
CVE-2017-7373 | 1 Google | 1 Android | 2017-07-08 | 9.3 HIGH | 7.8 HIGH |
In all Android releases from CAF using the Linux kernel, a double free vulnerability exists in a display driver. | |||||
CVE-2015-9007 | 1 Google | 1 Android | 2017-06-08 | 9.3 HIGH | 7.8 HIGH |
In TrustZone in all Android releases from CAF using the Linux kernel, a Double Free vulnerability could potentially exist. | |||||
CVE-2014-9807 | 1 Imagemagick | 1 Imagemagick | 2017-04-04 | 4.3 MEDIUM | 5.5 MEDIUM |
The pdb coder in ImageMagick allows remote attackers to cause a denial of service (double free) via unspecified vectors. | |||||
CVE-2015-8894 | 1 Imagemagick | 1 Imagemagick | 2017-03-17 | 4.3 MEDIUM | 5.5 MEDIUM |
Double free vulnerability in coders/tga.c in ImageMagick 7.0.0 and later allows remote attackers to cause a denial of service (application crash) via a crafted tga file. | |||||
CVE-2017-5836 | 1 Libimobiledevice | 1 Libplist | 2017-03-07 | 5.0 MEDIUM | 7.5 HIGH |
The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is treated as a PLIST_KEY and then triggers an invalid free. |