VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,935)

page 10 of 97
  • CVE-2021-42522HigAug 25, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of libxml2 API. The vendor forgot to call 'g_free()' to release the return value of 'xmlGetProp()'.

  • CVE-2021-33646HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.

  • CVE-2021-33645HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.

  • CVE-2022-22209HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a Denial of Service (DoS). On all Junos platforms, the Kernel Routing Table (KRT) queue can get stuck due to a…

  • CVE-2022-22205HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A Missing Release of Memory after Effective Lifetime vulnerability in the Application Quality of Experience (appqoe) subsystem of the PFE of Juniper Networks Junos OS on SRX Series allows an unauthenticated network based attacker to cause a Denial of Service (DoS). Upon…

  • CVE-2021-41490HigJun 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior.

  • CVE-2021-35078HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.00

    Possible memory leak due to improper validation of certificate chain length while parsing server certificate chain in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2018-17240HigJun 10, 2022
    risk 0.49cvss 7.5epss 0.04

    There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password).

  • CVE-2022-29932HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.03

    The HTTP Server in PRIMEUR SPAZIO 2.5.1.954 (File Transfer) allows an unauthenticated attacker to obtain sensitive data (related to the content of transferred files) via a crafted HTTP request.

  • CVE-2022-20785HigMay 4, 2022
    risk 0.49cvss 7.5epss 0.07

    On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in HTML file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior…

  • CVE-2021-42218HigMay 3, 2022
    risk 0.49cvss 7.5epss 0.01

    OMPL v1.5.2 contains a memory leak in VFRRT.cpp

  • CVE-2022-0853HigMar 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.

  • CVE-2021-40047HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a vulnerability of memory not being released after effective lifetime in the Bastet module. Successful exploitation of this vulnerability may affect integrity.

  • CVE-2020-22844HigFeb 28, 2022
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests.

  • CVE-2022-22336HigFeb 23, 2022
    risk 0.49cvss 7.5epss 0.02

    IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395.

  • CVE-2021-46082HigFeb 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol gateways were discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via crafted packets.

  • CVE-2021-37205HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions…

  • CVE-2022-22174HigJan 19, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the processing of inbound IPv6 packets in Juniper Networks Junos OS on QFX5000 Series and EX4600 switches may cause the memory to not be freed, leading to a packet DMA memory leak, and eventual Denial of Service (DoS) condition. Once the condition occurs,…

  • CVE-2022-22173HigJan 19, 2022
    risk 0.49cvss 7.5epss 0.01

    A Missing Release of Memory after Effective Lifetime vulnerability in the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause Denial of Service (DoS). In a scenario where Public Key Infrastructure (PKI) is…

  • CVE-2021-44542HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A memory leak vulnerability was found in Privoxy when handling errors.