VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,935)

page 88 of 97
  • CVE-2023-2602LowJun 6, 2023
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.

  • CVE-2023-31975LowMay 9, 2023
    risk 0.21cvss 3.3epss 0.00

    yasm v1.3.0 was discovered to contain a memory leak via the function yasm_intnum_copy at /libyasm/intnum.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy.

  • CVE-2022-23585MedFeb 4, 2022
    risk 0.21cvss 4.3epss 0.01

    Tensorflow is an Open Source Machine Learning Framework. When decoding PNG images TensorFlow can produce a memory leak if the image is invalid. After calling `png::CommonInitDecode(..., &decode)`, the `decode` value contains allocated buffers which can only be freed by calling…

  • CVE-2022-23578MedFeb 4, 2022
    risk 0.21cvss 4.3epss 0.01

    Tensorflow is an Open Source Machine Learning Framework. If a graph node is invalid, TensorFlow can leak memory in the implementation of `ImmutableExecutorState::Initialize`. Here, we set `item->kernel` to `nullptr` but it is a simple `OpKernel*` pointer so the memory that was…

  • CVE-2020-3959LowMay 29, 2020
    risk 0.21cvss 3.3epss 0.00

    VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMware Fusion (11.x before 11.1.0) contain a memory leak vulnerability in the VMCI module. A malicious actor with local non-administrative access to a…

  • CVE-2019-3815LowJan 28, 2019
    risk 0.21cvss 3.3epss 0.00

    A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this…

  • CVE-2025-8277LowSep 9, 2025
    risk 0.20cvss 3.1epss 0.00

    A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client…

  • CVE-2025-1152LowFeb 10, 2025
    risk 0.20cvss 3.1epss 0.01

    A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather…

  • CVE-2025-1151LowFeb 10, 2025
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather…

  • CVE-2025-1150LowFeb 10, 2025
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an…

  • CVE-2025-1149LowFeb 10, 2025
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of…

  • CVE-2025-1148LowFeb 10, 2025
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an…

  • CVE-2020-26420LowDec 11, 2020
    risk 0.20cvss 3.1epss 0.03

    Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.

  • CVE-2020-26419LowDec 11, 2020
    risk 0.20cvss 3.1epss 0.03

    Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.

  • CVE-2020-26418LowDec 11, 2020
    risk 0.20cvss 3.1epss 0.03

    Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.

  • CVE-2025-61146MedFeb 23, 2026
    risk 0.19cvss 4.0epss 0.00

    saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.

  • CVE-2019-19073MedNov 18, 2019
    risk 0.19cvss 4.0epss 0.01

    Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout() failures. This affects the htc_config_pipe_credits() function, the…

  • CVE-2026-78131LowSep 11, 2026
    risk 0.17cvss 3.7epss 0.00

    strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.

  • CVE-2026-78127LowSep 11, 2026
    risk 0.17cvss 3.7epss 0.00

    libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.

  • CVE-2026-78124LowSep 11, 2026
    risk 0.17cvss 3.7epss 0.00

    strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.