VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,889)

page 10 of 95
  • CVE-2021-42218HigMay 3, 2022
    risk 0.49cvss 7.5epss 0.01

    OMPL v1.5.2 contains a memory leak in VFRRT.cpp

  • CVE-2022-0853HigMar 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.

  • CVE-2021-40047HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a vulnerability of memory not being released after effective lifetime in the Bastet module. Successful exploitation of this vulnerability may affect integrity.

  • CVE-2020-22844HigFeb 28, 2022
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests.

  • CVE-2022-22336HigFeb 23, 2022
    risk 0.49cvss 7.5epss 0.02

    IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395.

  • CVE-2021-46082HigFeb 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol gateways were discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via crafted packets.

  • CVE-2021-37205HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions…

  • CVE-2022-22174HigJan 19, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the processing of inbound IPv6 packets in Juniper Networks Junos OS on QFX5000 Series and EX4600 switches may cause the memory to not be freed, leading to a packet DMA memory leak, and eventual Denial of Service (DoS) condition. Once the condition occurs,…

  • CVE-2022-22173HigJan 19, 2022
    risk 0.49cvss 7.5epss 0.01

    A Missing Release of Memory after Effective Lifetime vulnerability in the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause Denial of Service (DoS). In a scenario where Public Key Infrastructure (PKI) is…

  • CVE-2021-44542HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A memory leak vulnerability was found in Privoxy when handling errors.

  • CVE-2021-44541HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination.

  • CVE-2021-44540HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing.

  • CVE-2021-37046HigDec 7, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Memory leak vulnerability with the codec detection module in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart due to memory exhaustion.

  • CVE-2020-23876HigNov 10, 2021
    risk 0.49cvss 7.5epss 0.01

    pdf2xml v2.0 was discovered to contain a memory leak in the function TextPage::testLinkedText.

  • CVE-2021-34598HigNov 10, 2021
    risk 0.49cvss 7.5epss 0.01

    In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active

  • CVE-2021-36993HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Memory leaks vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

  • CVE-2021-30844HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.02

    A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A remote attacker may be able to leak memory.

  • CVE-2020-20665HigSep 30, 2021
    risk 0.49cvss 7.5epss 0.01

    rudp v0.6 was discovered to contain a memory leak in the component main.c.

  • CVE-2021-39282HigAug 18, 2021
    risk 0.49cvss 7.5epss 0.02

    Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files.

  • CVE-2020-22650HigJul 19, 2021
    risk 0.49cvss 7.5epss 0.01

    A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the occurrence of a large number of alarm events.