VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,881)

page 11 of 95
  • CVE-2021-20108HigJul 19, 2021
    risk 0.49cvss 7.5epss 0.04

    Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send commands over port 9000. While these commands may not be…

  • CVE-2021-28651HigMay 27, 2021
    risk 0.49cvss 7.5epss 0.07

    An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that…

  • CVE-2021-20209HigMay 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are configured.

  • CVE-2020-25672HigMay 25, 2021
    risk 0.49cvss 7.5epss 0.03

    A memory leak vulnerability was found in Linux kernel in llcp_sock_connect

  • CVE-2020-20451HigMay 25, 2021
    risk 0.49cvss 7.5epss 0.01

    Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.

  • CVE-2021-32032HigMay 21, 2021
    risk 0.49cvss 7.5epss 0.02

    In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the event of a failure) can prevent the abort() operation in the associated cryptographic library from freeing internal resources, causing a memory leak.

  • CVE-2021-27386HigMay 12, 2021
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels…

  • CVE-2021-28665HigMay 6, 2021
    risk 0.49cvss 7.5epss 0.01

    Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.

  • CVE-2021-0230HigApr 22, 2021
    risk 0.49cvss 7.5epss 0.01

    On Juniper Networks SRX Series devices with link aggregation (lag) configured, executing any operation that fetches Aggregated Ethernet (AE) interface statistics, including but not limited to SNMP GET requests, causes a slow kernel memory leak. If all the available memory is…

  • CVE-2020-11255HigApr 7, 2021
    risk 0.49cvss 7.5epss 0.01

    Denial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is freed and rest of the memory is leaked in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2021-20216HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability.

  • CVE-2021-20215HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash.

  • CVE-2021-20214HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail can lead to a system crash.

  • CVE-2021-20212HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Memory leak if multiple filters are executed and the last one is skipped due to a pcre error leading to a system crash.

  • CVE-2021-20211HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Memory leak when client tags are active can cause a system crash.

  • CVE-2021-20210HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Memory leak in the show-status CGI handler when no filter files are configured can lead to a system crash.

  • CVE-2020-35502HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Memory leaks when a response is buffered and the buffer limit is reached or Privoxy is running out of memory can lead to a system crash.

  • CVE-2021-21723HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Some ZTE products have a DoS vulnerability. Due to the improper handling of memory release in some specific scenarios, a remote attacker can trigger the vulnerability by performing a series of operations, resulting in memory leak, which may eventually lead to device denial of…

  • CVE-2021-0202HigJan 15, 2021
    risk 0.49cvss 7.5epss 0.01

    On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPC (Modular Port Concentrator) where Integrated Routing and Bridging (IRB) interface is configured and it is mapped to a VPLS instance or a Bridge-Domain, certain network events at Customer Edge (CE)…

  • CVE-2018-11246HigJan 11, 2021
    risk 0.49cvss 7.5epss 0.01

    K7TSMngr.exe in K7Computing K7AntiVirus Premium 15.1.0.53 has a Memory Leak.