← Vulnerability feed

Vulnerability record · CVE-2017-18201 · published 26 February 2018

CVE-2017-18201: Gnu libcdio double free vulnerability

Gnu · Libcdio

An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.

9.8 CVSS 3.0 Critical EPSS 3.2% · top 12.2% CWE-415 · Double free
9.8CVSS 3.0 base score, v2 7.5
3.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-18201 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-18198Gnu libcdio out-of-bounds read vulnerabilityprint_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or…EPSS 3.4%8.4CVE-2024-36600Gnu libcdio stack-based buffer overflow vulnerabilityBuffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.EPSS 0.36%6.5CVE-2017-18199Gnu libcdio null pointer dereference vulnerabilityrealloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (NULL Pointer Dereference) via a crafted i…EPSS 3.3%5.0CVE-2007-6613Gnu libcdio memory buffer overflow vulnerabilityStack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GNU Compact Disc Input and Control Library (libcdio…EPSS 13%9.8CVE-2026-33824Double free in Windows IKE Extension enables remote code executionA double free flaw (CWE-415) exists in the Windows IKE Extension, reachable over the network by an unauthenticated attacker. Successful exploitation …KEVEPSS 1.6%analysed7.0CVE-2025-62215Windows Kernel race condition and double free privilege escalationA race condition combined with a double free in the Windows Kernel lets a locally authenticated attacker corrupt kernel memory and elevate privileges…KEVEPSS 6.0%analysed8.8CVE-2014-0502Adobe Flash Player Double Free Enables Remote Code ExecutionAdobe Flash Player, Adobe AIR, and the AIR SDK contain a double free vulnerability (CWE-415) that allows remote attackers to execute arbitrary code. …KEVEPSS 25%analysed8.8CVE-2018-4990Adobe Acrobat and Reader double free allows code executionAdobe Acrobat and Reader contain a double free (CWE-415) in versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and e…KEVEPSS 36%analysed

Source: NIST National Vulnerability Database (record CVE-2017-18201), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.