VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,881)

page 21 of 95
  • CVE-2020-22048MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c.

  • CVE-2020-22046MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.

  • CVE-2021-3544MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.00

    Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after…

  • CVE-2020-22044MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c.

  • CVE-2021-26111MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.00

    A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below may allow an attacker on an adjacent network to exhaust available memory by sending specifically crafted LLDP/CDP/EDP packets to the…

  • CVE-2020-22043MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak at the fifo_alloc_common function in libavutil/fifo.c.

  • CVE-2020-22042MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak is affected by: memory leak in the link_filter_inouts function in libavfilter/graphparser.c.

  • CVE-2020-22041MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_buffersrc_add_frame_flags function in buffersrc.

  • CVE-2020-22040MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 idue to a memory leak in the v_frame_alloc function in frame.c.

  • CVE-2020-22039MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the inavi_add_ientry function.

  • CVE-2020-22038MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.01

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c.

  • CVE-2020-22037MedJun 1, 2021
    risk 0.42cvss 6.5epss 0.02

    A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.

  • CVE-2021-20237HigMay 28, 2021
    risk 0.42cvss 7.5epss 0.02

    An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remote unauthenticated attacker to send crafted PUB messages that consume excessive memory if the CURVE/ZAP authentication is disabled on the…

  • CVE-2020-21839MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/decode.c:3638.

  • CVE-2021-0272MedApr 22, 2021
    risk 0.42cvss 6.5epss 0.00

    A kernel memory leak in QFX10002-32Q, QFX10002-60C, QFX10002-72Q, QFX10008, QFX10016 devices Flexible PIC Concentrators (FPCs) on Juniper Networks Junos OS allows an attacker to send genuine packets destined to the device to cause a Denial of Service (DoS) to the device. On…

  • CVE-2021-0257MedApr 22, 2021
    risk 0.42cvss 6.5epss 0.00

    On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPCs (Modular Port Concentrators) where Integrated Routing and Bridging (IRB) interfaces are configured and mapped to a VPLS instance or a Bridge-Domain, certain Layer 2 network events at Customer Edge…

  • CVE-2021-22312MedApr 8, 2021
    risk 0.42cvss 6.5epss 0.01

    There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service…

  • CVE-2021-0215MedJan 15, 2021
    risk 0.42cvss 6.5epss 0.01

    On Juniper Networks Junos EX series, QFX Series, MX Series and SRX branch series devices, a memory leak occurs every time the 802.1X authenticator port interface flaps which can lead to other processes, such as the pfex process, responsible for packet forwarding, to crash and…

  • CVE-2020-35893HigDec 31, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the simple-slab crate before 0.3.3 for Rust. remove() has an off-by-one error, causing memory leakage and a drop of uninitialized memory.

  • CVE-2020-35679HigDec 24, 2020
    risk 0.42cvss 7.5epss 0.03

    smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups.