CWE-401
Missing Release of Memory after Effective Lifetime
Description
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (1,881)
page 65 of 95| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-42323 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2022 | Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be… | ||
| CVE-2022-42322 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2022 | Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be… | ||
| CVE-2022-43151 | Med | 0.36 | 5.5 | 0.00 | Oct 31, 2022 | timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-query.cc. | ||
| CVE-2022-40884 | Med | 0.36 | 5.5 | 0.00 | Oct 19, 2022 | Bento4 1.6.0 has memory leaks via the mp4fragment. | ||
| CVE-2022-22240 | Med | 0.36 | 5.5 | 0.00 | Oct 18, 2022 | An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated low privileged attacker to cause a… | ||
| CVE-2022-41847 | Med | 0.36 | 5.5 | 0.00 | Sep 30, 2022 | An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp. | ||
| CVE-2022-35085 | Med | 0.36 | 5.5 | 0.00 | Sep 21, 2022 | SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c. | ||
| CVE-2022-38600 | Med | 0.36 | 5.5 | 0.00 | Sep 15, 2022 | Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vf_vo.c. | ||
| CVE-2022-36152 | Med | 0.36 | 5.5 | 0.00 | Aug 16, 2022 | tifig v0.2.2 was discovered to contain a memory leak via operator new[](unsigned long) at /asan/asan_new_delete.cpp. | ||
| CVE-2022-35110 | Med | 0.36 | 5.5 | 0.00 | Aug 16, 2022 | SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c. | ||
| CVE-2021-33452 | Med | 0.36 | 5.5 | 0.00 | Jul 26, 2022 | An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c. | ||
| CVE-2021-33451 | Med | 0.36 | 5.5 | 0.00 | Jul 26, 2022 | An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c. | ||
| CVE-2021-33450 | Med | 0.36 | 5.5 | 0.00 | Jul 26, 2022 | An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c. | ||
| CVE-2021-33437 | Med | 0.36 | 5.5 | 0.00 | Jul 26, 2022 | An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in mjs.c. | ||
| CVE-2022-1515 | Med | 0.36 | 5.5 | 0.01 | May 2, 2022 | A memory leak was discovered in matio 1.5.21 and earlier in Mat_VarReadNextInfo5() in mat5.c via a crafted file. This issue can potentially result in DoS. | ||
| CVE-2021-44961 | Med | 0.36 | 5.5 | 0.01 | Mar 1, 2022 | A memory leakage flaw exists in the class PerimeterGenerator of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. Specially crafted stl files can exhaust available memory. An attacker can provide malicious files to trigger this vulnerability. | ||
| CVE-2022-20046 | Med | 0.36 | 5.5 | 0.00 | Feb 9, 2022 | In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06142410; Issue ID: ALPS06142410. | ||
| CVE-2021-46481 | Med | 0.36 | 5.5 | 0.01 | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c. | ||
| CVE-2020-22679 | Med | 0.36 | 5.5 | 0.01 | Oct 12, 2021 | Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input. | ||
| CVE-2020-22673 | Med | 0.36 | 5.5 | 0.01 | Oct 12, 2021 | Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input. |
- risk 0.36cvss 5.5epss 0.00
Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be…
- risk 0.36cvss 5.5epss 0.00
Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be…
- risk 0.36cvss 5.5epss 0.00
timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-query.cc.
- risk 0.36cvss 5.5epss 0.00
Bento4 1.6.0 has memory leaks via the mp4fragment.
- risk 0.36cvss 5.5epss 0.00
An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated low privileged attacker to cause a…
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp.
- risk 0.36cvss 5.5epss 0.00
SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.
- risk 0.36cvss 5.5epss 0.00
Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vf_vo.c.
- risk 0.36cvss 5.5epss 0.00
tifig v0.2.2 was discovered to contain a memory leak via operator new[](unsigned long) at /asan/asan_new_delete.cpp.
- risk 0.36cvss 5.5epss 0.00
SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in mjs.c.
- risk 0.36cvss 5.5epss 0.01
A memory leak was discovered in matio 1.5.21 and earlier in Mat_VarReadNextInfo5() in mat5.c via a crafted file. This issue can potentially result in DoS.
- risk 0.36cvss 5.5epss 0.01
A memory leakage flaw exists in the class PerimeterGenerator of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. Specially crafted stl files can exhaust available memory. An attacker can provide malicious files to trigger this vulnerability.
- risk 0.36cvss 5.5epss 0.00
In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06142410; Issue ID: ALPS06142410.
- risk 0.36cvss 5.5epss 0.01
Jsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c.
- risk 0.36cvss 5.5epss 0.01
Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.
- risk 0.36cvss 5.5epss 0.01
Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.