VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,935)

page 8 of 97
  • CVE-2024-3382HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that are running PAN-OS…

  • CVE-2023-52610HigMar 18, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix skb leak and crash on ooo frags act_ct adds skb->users before defragmentation. If frags arrive in order, the last frag's reference is reset in: inet_frag_reasm_prepare skb_morph …

  • CVE-2023-33086HigMar 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.

  • CVE-2023-33084HigMar 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing IE fragments from server during DTLS handshake.

  • CVE-2024-24148HigFeb 28, 2024
    risk 0.49cvss 7.5epss 0.01

    A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

  • CVE-2024-27508HigFeb 27, 2024
    risk 0.49cvss 7.5epss 0.01

    Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c.

  • CVE-2024-27507HigFeb 27, 2024
    risk 0.49cvss 7.5epss 0.01

    libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.

  • CVE-2023-33049HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.

  • CVE-2024-24265HigFeb 5, 2024
    risk 0.49cvss 7.5epss 0.01

    gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function.

  • CVE-2024-22563HigJan 19, 2024
    risk 0.49cvss 7.5epss 0.01

    openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.

  • CVE-2024-21611HigJan 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A Missing Release of Memory after Effective Lifetime vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). In a Juniper Flow Monitoring (jflow)…

  • CVE-2023-0248HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.00

    An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover the reader's communication memory between the card and reader.

  • CVE-2023-38380HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions), SIMATIC CP 1243-1 IEC (incl. SIPLUS…

  • CVE-2023-44192HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause memory leak, leading to Denial of Service (DoS). On all Junos OS QFX5000 Series platforms, when pseudo-VTEP…

  • CVE-2023-40534HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.01

    When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed requests can cause TMM to terminate.  Note: Software versions…

  • CVE-2023-5156HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.

  • CVE-2023-32247HigJul 24, 2023
    risk 0.49cvss 7.5epss 0.04

    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_SESSION_SETUP commands. The issue results from the lack of control of resource consumption. An attacker can leverage this vulnerability to…

  • CVE-2023-31517HigMay 23, 2023
    risk 0.49cvss 7.5epss 0.01

    A memory leak in the component CConsole::Chain of Teeworlds v0.7.5 allows attackers to cause a Denial of Service (DoS) via opening a crafted file.

  • CVE-2023-29163HigMay 3, 2023
    risk 0.49cvss 7.5epss 0.01

    When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2023-28982HigApr 17, 2023
    risk 0.49cvss 7.5epss 0.01

    A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). In a BGP rib sharding scenario, when an…