VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,881)

page 18 of 95
  • CVE-2025-26308MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    A memory leak has been identified in the parseSWF_FILTERLIST function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.

  • CVE-2025-26307MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    A memory leak has been identified in the parseSWF_IMPORTASSETS2 function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.

  • CVE-2025-26306MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    A memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted file.

  • CVE-2025-25469MedFeb 18, 2025
    risk 0.42cvss 6.5epss 0.00

    FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/iamf.c.

  • CVE-2025-25199HigFeb 12, 2025
    risk 0.42cvss 7.5epss 0.01

    go-crypto-winnative Go crypto backend for Windows using Cryptography API: Next Generation (CNG). Prior to commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41, calls to `cng.TLS1PRF` don't release the key handle, producing a small memory leak every time. Commit…

  • CVE-2024-47493MedOct 11, 2024
    risk 0.42cvss 6.5epss 0.00

    A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of the Juniper Networks Junos OS on the MX Series platforms with Trio-based FPCs allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). In case of…

  • CVE-2024-7884HigSep 5, 2024
    risk 0.42cvss 7.5epss 0.01

    When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked and stored in a struct called CallFutureState. A bug in the polling…

  • CVE-2024-41066HigJul 29, 2024
    risk 0.42cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Add tx check to prevent skb leak Below is a summary of how the driver stores a reference to an skb during transmit: tx_buff[free_map[consumer_index]]->skb = new_skb; free_map[consumer_index] =…

  • CVE-2024-41172HigJul 19, 2024
    risk 0.42cvss 7.5epss 0.01

    In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the…

  • CVE-2024-39550MedJul 11, 2024
    risk 0.42cvss 6.5epss 0.00

    A Missing Release of Memory after Effective Lifetime vulnerability in the rtlogd process of Juniper Networks Junos OS on MX Series with SPC3 allows an unauthenticated, adjacent attacker to trigger internal events cause ( which can be done by repeated port flaps) to cause a…

  • CVE-2024-5294MedMay 23, 2024
    risk 0.42cvss 6.5epss 0.00

    D-Link DIR-3040 prog.cgi websSecurityHandler Memory Leak Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of D-Link DIR-3040 routers. Authentication is not required to exploit…

  • CVE-2024-35853MedMay 17, 2024
    risk 0.42cvss 6.4epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix memory leak during rehash The rehash delayed work migrates filters from one region to another. This is done by iterating over all chunks (all the filters with the same priority)…

  • CVE-2024-27393HigMay 14, 2024
    risk 0.42cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: xen-netfront: Add missing skb_mark_for_recycle Notice that skb_mark_for_recycle() is introduced later than fixes tag in commit 6a5bcd84e886 ("page_pool: Allow drivers to hint on SKB recycling"). It is…

  • CVE-2024-21609MedApr 12, 2024
    risk 0.42cvss 6.5epss 0.00

    A Missing Release of Memory after Effective Lifetime vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an administratively adjacent attacker which is able to successfully establish IPsec tunnels to cause a Denial of…

  • CVE-2024-1394HigMar 21, 2024
    risk 0.42cvss 7.5epss 0.02

    A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are…

  • CVE-2024-24155MedFeb 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4…

  • CVE-2024-24150MedFeb 29, 2024
    risk 0.42cvss 6.5epss 0.01

    A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

  • CVE-2024-24149MedFeb 29, 2024
    risk 0.42cvss 6.5epss 0.01

    A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

  • CVE-2024-24147MedFeb 29, 2024
    risk 0.42cvss 6.5epss 0.01

    A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.

  • CVE-2024-24146MedFeb 29, 2024
    risk 0.42cvss 6.5epss 0.01

    A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.