VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,881)

page 64 of 95
  • CVE-2022-47011MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered function parse_stab_struct_fields in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.

  • CVE-2022-47010MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.

  • CVE-2022-47008MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.

  • CVE-2022-47007MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.

  • CVE-2020-26683MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    A memory leak issue discovered in /pdf/pdf-font-add.c in Artifex Software MuPDF 1.17.0 allows attackers to obtain sensitive information.

  • CVE-2023-33717MedJun 2, 2023
    risk 0.36cvss 5.5epss 0.00

    mp4v2 v2.1.3 was discovered to contain a memory leak when a method calling MP4File::ReadBytes() had allocated memory but did not catch exceptions thrown by ReadBytes()

  • CVE-2023-33719MedJun 1, 2023
    risk 0.36cvss 5.5epss 0.00

    mp4v2 v2.1.3 was discovered to contain a memory leak via MP4SdpAtom::Read() at atom_sdp.cpp

  • CVE-2023-33716MedJun 1, 2023
    risk 0.36cvss 5.5epss 0.00

    mp4v2 v2.1.3 was discovered to contain a memory leak via the class MP4StringProperty at mp4property.cpp.

  • CVE-2023-31973MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    yasm v1.3.0 was discovered to contain a use after free via the function expand_mmac_params at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy.

  • CVE-2023-23205MedFeb 24, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in lib60870 v2.3.2. There is a memory leak in lib60870/lib60870-C/examples/multi_client_server/multi_client_server.c.

  • CVE-2023-0597MedFeb 23, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location of exception stack(s) or other important data. A local user could use this flaw to get access to some important data with expected…

  • CVE-2023-0615MedFeb 6, 2023
    risk 0.36cvss 5.5epss 0.00

    A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test code functionality. This issue occurs when a user triggers ioctls, such as VIDIOC_S_DV_TIMINGS ioctl. This could allow a local user to crash the system if vivid…

  • CVE-2022-46490MedJan 5, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the afrt_box_read function at box_code_adobe.c.

  • CVE-2022-46489MedJan 5, 2023
    risk 0.36cvss 5.5epss 0.00

    GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the gf_isom_box_parse_ex function at box_funcs.c.

  • CVE-2022-45204MedNov 29, 2022
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a memory leak via the function dimC_box_read at isomedia/box_code_3gpp.c.

  • CVE-2021-26393MedNov 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting…

  • CVE-2022-43255MedNov 2, 2022
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_odf_new_iod at odf/odf_code.c.

  • CVE-2022-43254MedNov 2, 2022
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_list_new at utils/list.c.

  • CVE-2022-42326MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a transaction and it is later deleted in the…

  • CVE-2022-42325MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a transaction and it is later deleted in the…