VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,881)

page 65 of 95
  • CVE-2022-42323MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be…

  • CVE-2022-42322MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be…

  • CVE-2022-43151MedOct 31, 2022
    risk 0.36cvss 5.5epss 0.00

    timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-query.cc.

  • CVE-2022-40884MedOct 19, 2022
    risk 0.36cvss 5.5epss 0.00

    Bento4 1.6.0 has memory leaks via the mp4fragment.

  • CVE-2022-22240MedOct 18, 2022
    risk 0.36cvss 5.5epss 0.00

    An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated low privileged attacker to cause a…

  • CVE-2022-41847MedSep 30, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp.

  • CVE-2022-35085MedSep 21, 2022
    risk 0.36cvss 5.5epss 0.00

    SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.

  • CVE-2022-38600MedSep 15, 2022
    risk 0.36cvss 5.5epss 0.00

    Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vf_vo.c.

  • CVE-2022-36152MedAug 16, 2022
    risk 0.36cvss 5.5epss 0.00

    tifig v0.2.2 was discovered to contain a memory leak via operator new[](unsigned long) at /asan/asan_new_delete.cpp.

  • CVE-2022-35110MedAug 16, 2022
    risk 0.36cvss 5.5epss 0.00

    SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.

  • CVE-2021-33452MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c.

  • CVE-2021-33451MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.

  • CVE-2021-33450MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c.

  • CVE-2021-33437MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in mjs.c.

  • CVE-2022-1515MedMay 2, 2022
    risk 0.36cvss 5.5epss 0.01

    A memory leak was discovered in matio 1.5.21 and earlier in Mat_VarReadNextInfo5() in mat5.c via a crafted file. This issue can potentially result in DoS.

  • CVE-2021-44961MedMar 1, 2022
    risk 0.36cvss 5.5epss 0.01

    A memory leakage flaw exists in the class PerimeterGenerator of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. Specially crafted stl files can exhaust available memory. An attacker can provide malicious files to trigger this vulnerability.

  • CVE-2022-20046MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06142410; Issue ID: ALPS06142410.

  • CVE-2021-46481MedJan 25, 2022
    risk 0.36cvss 5.5epss 0.01

    Jsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c.

  • CVE-2020-22679MedOct 12, 2021
    risk 0.36cvss 5.5epss 0.01

    Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.

  • CVE-2020-22673MedOct 12, 2021
    risk 0.36cvss 5.5epss 0.01

    Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.