VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,881)

page 68 of 95
  • CVE-2020-3995MedOct 20, 2020
    risk 0.35cvss 5.3epss 0.01

    In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors contain a memory leak vulnerability. A malicious actor with access to a virtual…

  • CVE-2020-5924MedAug 26, 2020
    risk 0.35cvss 5.3epss 0.01

    In BIG-IP APM versions 12.1.0-12.1.5.1 and 11.6.1-11.6.5.2, RADIUS authentication leaks memory when the username for authentication is not set.

  • CVE-2019-20023MedDec 27, 2019
    risk 0.35cvss 6.5epss 0.01

    A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.

  • CVE-2019-19046MedNov 18, 2019
    risk 0.35cvss 6.5epss 0.03

    A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering ida_simple_get() failure, aka CID-4aa7afb0ee20. NOTE: third parties…

  • CVE-2019-6647MedSep 4, 2019
    risk 0.35cvss 5.3epss 0.01

    On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, 12.1.0-12.1.4.1, 11.5.2-11.6.4, when processing authentication attempts for control-plane users MCPD leaks a small amount of memory. Under rare conditions attackers with access to the management interface could…

  • CVE-2026-48141MedJun 19, 2026
    risk 0.34cvss 5.3epss 0.00

    There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhaustion.  This affects NI grpc-device 2.17.0 and prior versions.

  • CVE-2026-43506MedMay 1, 2026
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by memory leaks from unauthenticated connections.

  • CVE-2026-20106MedMar 4, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to exhaust device memory…

  • CVE-2025-56226MedJan 14, 2026
    risk 0.34cvss 5.3epss 0.00

    Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode.c file.

  • CVE-2025-20077MedAug 12, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing release of memory after effective lifetime in the UEFI OobRasMmbiHandlerDriver module for some Intel(R) reference server platforms may allow a privileged user to enable denial of service via local access.

  • CVE-2025-1992MedMay 5, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user in federation environment, to cause a denial of service due to insufficient release of allocated memory after usage.

  • CVE-2024-9135MedMar 4, 2025
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping.

  • CVE-2024-39539MedJul 11, 2024
    risk 0.34cvss 5.3epss 0.00

    A Missing Release of Memory after Effective Lifetime vulnerability in Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS). In a subscriber management scenario continuous subscriber logins will trigger a memory…

  • CVE-2024-39536MedJul 11, 2024
    risk 0.34cvss 5.3epss 0.00

    A Missing Release of Memory after Effective Lifetime vulnerability in the Periodic Packet Management Daemon (ppmd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS). When a BFD session configured…

  • CVE-2022-48764MedJun 20, 2024
    risk 0.34cvss 5.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Free kvm_cpuid_entry2 array on post-KVM_RUN KVM_SET_CPUID{,2} Free the "struct kvm_cpuid_entry2" array on successful post-KVM_RUN KVM_SET_CPUID{,2} to fix a memory leak, the callers of…

  • CVE-2022-48698MedMay 3, 2024
    risk 0.34cvss 5.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix memory leak when using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. Fix this up by properly calling…

  • CVE-2023-4513MedAug 24, 2023
    risk 0.34cvss 5.3epss 0.00

    BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file

  • CVE-2023-2683MedJun 15, 2023
    risk 0.34cvss 5.3epss 0.00

    A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.

  • CVE-2023-26083LowKEVApr 6, 2023
    risk 0.34cvss 3.3epss 0.01

    Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall GPU Kernel Driver all versions from r19p0 - r42p0, and Avalon GPU Kernel Driver all versions from…

  • CVE-2022-22204MedJul 20, 2022
    risk 0.34cvss 5.3epss 0.01

    An Improper Release of Memory Before Removing Last Reference vulnerability in the Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Juniper Networks Junos OS allows unauthenticated network-based attacker to cause a partial Denial of Service (DoS). On all MX…