CWE-415

CWE-415 · 5 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-415, highest CVSS first.

  1. CRITICAL 9.9CVE-2026-89078

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due …

    gitlab

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.8CVE-2026-91018public PoC

    lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.8CVE-2026-6794

    IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary code in the context of the affected process.

    concert · linux kernel

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 5.7CVE-2026-17050public PoC

    The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c). On three failure paths — a failed full-length GET_DES…

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-11388

    Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.1.0 before 7.3.1.6.

    AI risk analysis on Exploit-DB.ai →