VYPR

CWE-244

Improper Clearing of Heap Memory Before Release ('Heap Inspection')

VariantDraft

Description

Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.

When sensitive data such as a password or an encryption key is not removed from memory, it could be exposed to an attacker using a "heap inspection" attack that reads the sensitive data using memory dumps or other methods. The realloc() function is commonly used to increase the size of a block of allocated memory. This operation often requires copying the contents of the old memory block into a new and larger block. This operation leaves the contents of the original block intact but inaccessible to the program, preventing the program from being able to scrub sensitive data from memory. If an attacker can later examine the contents of a memory dump, the sensitive data could be exposed.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (21)

page 1 of 2
  • CVE-2026-20349HigKEVAug 11, 2026
    risk 0.68cvss 8.6epss 0.01

    A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting…

  • CVE-2026-20039HigMar 4, 2026
    risk 0.56cvss 8.6epss 0.00

    A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. …

  • CVE-2025-26305HigFeb 20, 2025
    risk 0.53cvss 8.2epss 0.00

    A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.

  • CVE-2025-26304HigFeb 20, 2025
    risk 0.53cvss 8.2epss 0.00

    A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8.

  • CVE-2025-70873HigMar 12, 2026
    risk 0.49cvss 7.5epss 0.00

    An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

  • CVE-2025-36118HigNov 17, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.

  • CVE-2025-5105HigMay 23, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in TOZED ZLT W51 up to 1.4.2 and classified as critical. Affected by this issue is some unknown functionality of the component Service Port 7777. The manipulation leads to improper clearing of heap memory before release. The attack may be launched…

  • CVE-2025-45663MedNov 3, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

  • CVE-2025-36083MedOct 28, 2025
    risk 0.40cvss 6.2epss 0.00

    IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release.

  • CVE-2025-33013MedJul 24, 2025
    risk 0.40cvss 6.2epss 0.00

    IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Container could disclose sensitive information to a local user due to improper clearing of heap memory…

  • CVE-2026-48025MedJul 28, 2026
    risk 0.38cvss epss 0.00

    nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, internal/pki/resolver.go:36-64 constructs a CAManager with the plaintext ed25519.PrivateKey after unwrapping via the master key; internal/pki/ca.go:13-16 stores it.…

  • CVE-2025-33101MedFeb 17, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniques due to improper clearing of heap memory.

  • CVE-2025-1722MedJan 20, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

  • CVE-2025-1719MedJan 20, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

  • CVE-2025-1721MedDec 26, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

  • CVE-2025-1759MedAug 18, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

  • CVE-2022-20943MedNov 15, 2022
    risk 0.38cvss 5.8epss 0.01

    Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected…

  • CVE-2022-20922MedNov 15, 2022
    risk 0.38cvss 5.8epss 0.01

    Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected…

  • CVE-2023-20070MedNov 1, 2023
    risk 0.26cvss 4.0epss 0.01

    A vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart. This vulnerability is due to a logic error in how memory allocations…

  • CVE-2023-20031MedNov 1, 2023
    risk 0.26cvss 4.0epss 0.00

    A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart. This vulnerability is due to a logic…