VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,935)

page 66 of 97
  • CVE-2021-26393MedNov 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting…

  • CVE-2022-43255MedNov 2, 2022
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_odf_new_iod at odf/odf_code.c.

  • CVE-2022-43254MedNov 2, 2022
    risk 0.36cvss 5.5epss 0.00

    GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_list_new at utils/list.c.

  • CVE-2022-42326MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a transaction and it is later deleted in the…

  • CVE-2022-42325MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a transaction and it is later deleted in the…

  • CVE-2022-42323MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be…

  • CVE-2022-42322MedNov 1, 2022
    risk 0.36cvss 5.5epss 0.00

    Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be…

  • CVE-2022-43151MedOct 31, 2022
    risk 0.36cvss 5.5epss 0.00

    timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-query.cc.

  • CVE-2022-40884MedOct 19, 2022
    risk 0.36cvss 5.5epss 0.00

    Bento4 1.6.0 has memory leaks via the mp4fragment.

  • CVE-2022-22240MedOct 18, 2022
    risk 0.36cvss 5.5epss 0.00

    An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated low privileged attacker to cause a…

  • CVE-2022-41847MedSep 30, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp.

  • CVE-2022-35085MedSep 21, 2022
    risk 0.36cvss 5.5epss 0.00

    SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.

  • CVE-2022-38600MedSep 15, 2022
    risk 0.36cvss 5.5epss 0.00

    Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vf_vo.c.

  • CVE-2022-36152MedAug 16, 2022
    risk 0.36cvss 5.5epss 0.00

    tifig v0.2.2 was discovered to contain a memory leak via operator new[](unsigned long) at /asan/asan_new_delete.cpp.

  • CVE-2022-35110MedAug 16, 2022
    risk 0.36cvss 5.5epss 0.00

    SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.

  • CVE-2021-33452MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c.

  • CVE-2021-33451MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.

  • CVE-2021-33450MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c.

  • CVE-2021-33437MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in mjs.c.

  • CVE-2022-1515MedMay 2, 2022
    risk 0.36cvss 5.5epss 0.01

    A memory leak was discovered in matio 1.5.21 and earlier in Mat_VarReadNextInfo5() in mat5.c via a crafted file. This issue can potentially result in DoS.