VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,881)

page 84 of 95
  • CVE-2019-19065MedNov 18, 2019
    risk 0.24cvss 4.7epss 0.00

    A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering rhashtable_init() failures, aka CID-34b3be18a04e. NOTE: This has been disputed as not…

  • CVE-2019-16994MedSep 30, 2019
    risk 0.24cvss 4.7epss 0.00

    In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev, which may cause denial of service, aka CID-07f12b26e21a.

  • CVE-2025-46686LowJul 23, 2025
    risk 0.23cvss 3.5epss 0.00

    Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient…

  • CVE-2019-20382LowMar 5, 2020
    risk 0.23cvss 3.5epss 0.01

    QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.

  • CVE-2019-19068MedNov 18, 2019
    risk 0.23cvss 4.6epss 0.00

    A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.

  • CVE-2019-18809MedNov 7, 2019
    risk 0.23cvss 4.6epss 0.00

    A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559.

  • CVE-2020-27755LowDec 8, 2020
    risk 0.22cvss 3.3epss 0.01

    in SetImageExtent() of /MagickCore/image.c, an incorrect image depth size can cause a memory leak because the code which checks for the proper image depth size does not reset the size in the event there is an invalid size. The patch resets the depth to a proper size before…

  • CVE-2019-19072MedNov 18, 2019
    risk 0.22cvss 4.4epss 0.00

    A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6.

  • CVE-2019-19067MedNov 18, 2019
    risk 0.22cvss 4.4epss 0.00

    Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption) by triggering mfd_add_hotplug_devices() or pm_genpd_add_device() failures, aka…

  • CVE-2019-19045MedNov 18, 2019
    risk 0.22cvss 4.4epss 0.01

    A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.

  • CVE-2026-0639LowMar 16, 2026
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.

  • CVE-2025-15572LowFeb 10, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation leads to memory leak. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Unfortunately, the project has no…

  • CVE-2025-27562LowAug 11, 2025
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

  • CVE-2025-24925LowAug 11, 2025
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

  • CVE-2025-24844LowAug 11, 2025
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

  • CVE-2025-8225LowJul 27, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The…

  • CVE-2025-7068LowJul 4, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5FL__malloc of the file src/H5FL.c. The manipulation leads to memory leak. Attacking locally is a requirement. The exploit has been disclosed to the public and…

  • CVE-2025-6498LowJun 23, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAlloc of the file src/alloc.c. The manipulation leads to memory leak. It is possible to launch the attack on the local host. The exploit has been disclosed to the…

  • CVE-2025-5324LowMay 29, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability, which was classified as problematic, was found in TechPowerUp GPU-Z 2.23.0. Affected is the function sub_140001880 in the library GPU-Z.sys of the component 0x8000645C IOCTL Handler. The manipulation leads to memory leak. It is possible to launch the attack on…

  • CVE-2025-22886LowMay 6, 2025
    risk 0.21cvss 3.3epss 0.00

    in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.