CWE-401
Missing Release of Memory after Effective Lifetime
Description
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (1,889)
page 10 of 95| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-42218 | Hig | 0.49 | 7.5 | 0.01 | May 3, 2022 | OMPL v1.5.2 contains a memory leak in VFRRT.cpp | ||
| CVE-2022-0853 | Hig | 0.49 | 7.5 | 0.01 | Mar 11, 2022 | A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability. | ||
| CVE-2021-40047 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2022 | There is a vulnerability of memory not being released after effective lifetime in the Bastet module. Successful exploitation of this vulnerability may affect integrity. | ||
| CVE-2020-22844 | Hig | 0.49 | 7.5 | 0.01 | Feb 28, 2022 | A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests. | ||
| CVE-2022-22336 | Hig | 0.49 | 7.5 | 0.02 | Feb 23, 2022 | IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395. | ||
| CVE-2021-46082 | Hig | 0.49 | 7.5 | 0.01 | Feb 18, 2022 | Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol gateways were discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via crafted packets. | ||
| CVE-2021-37205 | Hig | 0.49 | 7.5 | 0.02 | Feb 9, 2022 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions… | ||
| CVE-2022-22174 | Hig | 0.49 | 7.5 | 0.01 | Jan 19, 2022 | A vulnerability in the processing of inbound IPv6 packets in Juniper Networks Junos OS on QFX5000 Series and EX4600 switches may cause the memory to not be freed, leading to a packet DMA memory leak, and eventual Denial of Service (DoS) condition. Once the condition occurs,… | ||
| CVE-2022-22173 | Hig | 0.49 | 7.5 | 0.01 | Jan 19, 2022 | A Missing Release of Memory after Effective Lifetime vulnerability in the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause Denial of Service (DoS). In a scenario where Public Key Infrastructure (PKI) is… | ||
| CVE-2021-44542 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2021 | A memory leak vulnerability was found in Privoxy when handling errors. | ||
| CVE-2021-44541 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2021 | A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination. | ||
| CVE-2021-44540 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2021 | A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing. | ||
| CVE-2021-37046 | Hig | 0.49 | 7.5 | 0.01 | Dec 7, 2021 | There is a Memory leak vulnerability with the codec detection module in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart due to memory exhaustion. | ||
| CVE-2020-23876 | Hig | 0.49 | 7.5 | 0.01 | Nov 10, 2021 | pdf2xml v2.0 was discovered to contain a memory leak in the function TextPage::testLinkedText. | ||
| CVE-2021-34598 | Hig | 0.49 | 7.5 | 0.01 | Nov 10, 2021 | In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active | ||
| CVE-2021-36993 | Hig | 0.49 | 7.5 | 0.01 | Oct 28, 2021 | There is a Memory leaks vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability. | ||
| CVE-2021-30844 | Hig | 0.49 | 7.5 | 0.02 | Oct 19, 2021 | A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A remote attacker may be able to leak memory. | ||
| CVE-2020-20665 | Hig | 0.49 | 7.5 | 0.01 | Sep 30, 2021 | rudp v0.6 was discovered to contain a memory leak in the component main.c. | ||
| CVE-2021-39282 | Hig | 0.49 | 7.5 | 0.02 | Aug 18, 2021 | Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files. | ||
| CVE-2020-22650 | Hig | 0.49 | 7.5 | 0.01 | Jul 19, 2021 | A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the occurrence of a large number of alarm events. |
- risk 0.49cvss 7.5epss 0.01
OMPL v1.5.2 contains a memory leak in VFRRT.cpp
- risk 0.49cvss 7.5epss 0.01
A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.
- risk 0.49cvss 7.5epss 0.01
There is a vulnerability of memory not being released after effective lifetime in the Bastet module. Successful exploitation of this vulnerability may affect integrity.
- risk 0.49cvss 7.5epss 0.01
A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests.
- risk 0.49cvss 7.5epss 0.02
IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395.
- risk 0.49cvss 7.5epss 0.01
Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol gateways were discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via crafted packets.
- risk 0.49cvss 7.5epss 0.02
A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions…
- risk 0.49cvss 7.5epss 0.01
A vulnerability in the processing of inbound IPv6 packets in Juniper Networks Junos OS on QFX5000 Series and EX4600 switches may cause the memory to not be freed, leading to a packet DMA memory leak, and eventual Denial of Service (DoS) condition. Once the condition occurs,…
- risk 0.49cvss 7.5epss 0.01
A Missing Release of Memory after Effective Lifetime vulnerability in the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause Denial of Service (DoS). In a scenario where Public Key Infrastructure (PKI) is…
- risk 0.49cvss 7.5epss 0.01
A memory leak vulnerability was found in Privoxy when handling errors.
- risk 0.49cvss 7.5epss 0.01
A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination.
- risk 0.49cvss 7.5epss 0.01
A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing.
- risk 0.49cvss 7.5epss 0.01
There is a Memory leak vulnerability with the codec detection module in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart due to memory exhaustion.
- risk 0.49cvss 7.5epss 0.01
pdf2xml v2.0 was discovered to contain a memory leak in the function TextPage::testLinkedText.
- risk 0.49cvss 7.5epss 0.01
In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active
- risk 0.49cvss 7.5epss 0.01
There is a Memory leaks vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.
- risk 0.49cvss 7.5epss 0.02
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A remote attacker may be able to leak memory.
- risk 0.49cvss 7.5epss 0.01
rudp v0.6 was discovered to contain a memory leak in the component main.c.
- risk 0.49cvss 7.5epss 0.02
Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files.
- risk 0.49cvss 7.5epss 0.01
A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the occurrence of a large number of alarm events.