VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,881)

page 23 of 95
  • CVE-2019-19064HigNov 18, 2019
    risk 0.42cvss 7.5epss 0.03

    A memory leak in the fsl_lpspi_probe() function in drivers/spi/spi-fsl-lpspi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering pm_runtime_get_sync() failures, aka CID-057b8945f78f. NOTE: third parties dispute…

  • CVE-2019-19049HigNov 18, 2019
    risk 0.42cvss 7.5epss 0.04

    A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a. NOTE: third parties dispute the…

  • CVE-2019-19048HigNov 18, 2019
    risk 0.42cvss 7.5epss 0.04

    A memory leak in the crypto_reportstat() function in drivers/virt/vboxguest/vboxguest_utils.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering copy_form_user() failures, aka CID-e0b0cb938864.

  • CVE-2019-19044HigNov 18, 2019
    risk 0.42cvss 7.5epss 0.04

    Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering kcalloc() or v3d_job_init() failures, aka CID-29cd13cfd762.

  • CVE-2019-5293MedNov 13, 2019
    risk 0.42cvss 6.5epss 0.01

    Some Huawei products have a memory leak vulnerability when handling some messages. A remote attacker with operation privilege could exploit the vulnerability by sending specific messages continuously. Successful exploit may cause some service to be abnormal.

  • CVE-2019-18812HigNov 7, 2019
    risk 0.42cvss 7.5epss 0.03

    A memory leak in the sof_dfsentry_write() function in sound/soc/sof/debug.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-c0a333d842ef.

  • CVE-2019-17371MedOct 9, 2019
    risk 0.42cvss 6.5epss 0.01

    gif2png 2.5.13 has a memory leak in the writefile function.

  • CVE-2019-17178HigOct 4, 2019
    risk 0.42cvss 7.5epss 0.03

    HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.

  • CVE-2019-17177HigOct 4, 2019
    risk 0.42cvss 7.5epss 0.03

    libfreerdp/codec/region.c in FreeRDP through 1.1.x and 2.x through 2.0.0-rc4 has memory leaks because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.

  • CVE-2019-16995HigSep 30, 2019
    risk 0.42cvss 7.5epss 0.04

    In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.

  • CVE-2019-4141MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    IBM MQ 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.9, 8.0.0.0 - 8.0.0.11, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.1 - 9.1.2 is vulnerable to a denial of service attack caused by a memory leak in the clustering code. IBM X-Force ID: 158337.

  • CVE-2019-16713MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.02

    ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c.

  • CVE-2019-16712MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.03

    ImageMagick 7.0.8-43 has a memory leak in Huffman2DEncodeImage in coders/ps3.c, as demonstrated by WritePS3Image.

  • CVE-2019-16711MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.02

    ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.

  • CVE-2019-16710MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.02

    ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.

  • CVE-2019-16709MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.03

    ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.

  • CVE-2019-16708MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.02

    ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.

  • CVE-2019-11010MedApr 8, 2019
    risk 0.42cvss 6.5epss 0.02

    In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.

  • CVE-2019-7175HigMar 7, 2019
    risk 0.42cvss 7.5epss 0.03

    In ImageMagick before 7.0.8-25, some memory leaks exist in DecodeImage in coders/pcd.c.

  • CVE-2019-7398HigFeb 5, 2019
    risk 0.42cvss 7.5epss 0.04

    In ImageMagick before 7.0.8-25, a memory leak exists in WriteDIBImage in coders/dib.c.