VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,881)

page 89 of 95
  • CVE-2024-8376HigOct 11, 2024
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.

  • CVE-2024-24267HigFeb 5, 2024
    risk 0.00cvss 7.5epss 0.02

    gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function.

  • CVE-2024-24259HigFeb 5, 2024
    risk 0.00cvss 7.5epss 0.01

    freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.

  • CVE-2024-24258HigFeb 5, 2024
    risk 0.00cvss 7.5epss 0.01

    freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.

  • CVE-2023-7192MedJan 2, 2024
    risk 0.00cvss 5.5epss 0.00

    A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service (DoS) attack due to a refcount overflow.

  • CVE-2023-41102HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version…

  • CVE-2023-28366HigSep 1, 2023
    risk 0.00cvss 7.5epss 0.01

    The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc…

  • CVE-2023-39978LowAug 8, 2023
    risk 0.00cvss 3.3epss 0.00

    ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.

  • CVE-2023-2700MedMay 15, 2023
    risk 0.00cvss 5.5epss 0.00

    A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.

  • CVE-2023-2618MedMay 10, 2023
    risk 0.00cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this issue is the function DecodedBitStreamParser::decodeHanziSegment of the file qrcode/decoder/decoded_bit_stream_parser.cpp. The manipulation leads to…

  • CVE-2023-1074MedMar 27, 2023
    risk 0.00cvss 5.5epss 0.00

    A memory leak flaw was found in the Linux kernel's Stream Control Transmission Protocol. This issue may occur when a user starts a malicious networking service and someone connects to this service. This could allow a local user to starve resources, causing a denial of service.

  • CVE-2023-28096MedMar 15, 2023
    risk 0.00cvss 4.5epss 0.01

    OpenSIPS, a Session Initiation Protocol (SIP) server implementation, has a memory leak starting in the 2.3 branch and priot to versions 3.1.8 and 3.2.5. The memory leak was detected in the function `parse_mi_request` while performing coverage-guided fuzzing. This issue can be…

  • CVE-2023-26257HigFeb 27, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the Connected Vehicle Systems Alliance (COVESA; formerly GENIVI) dlt-daemon through 2.18.8. Dynamic memory is not released after it is allocated in dlt-control-common.c.

  • CVE-2023-25566HigFeb 14, 2023
    risk 0.00cvss 7.5epss 0.01

    GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, a memory leak can be triggered when parsing usernames which can trigger a denial-of-service. The domain portion of a username may be overridden causing an…

  • CVE-2023-23145HigJan 20, 2023
    risk 0.00cvss 7.8epss 0.00

    GPAC version 2.2-rev0-gab012bbfb-master was discovered to contain a memory leak in lsr_read_rare_full function.

  • CVE-2022-4743HigJan 12, 2023
    risk 0.00cvss 7.5epss 0.01

    A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4 and above. SDL-1.x are not affected.

  • CVE-2022-47941HigDec 23, 2022
    risk 0.00cvss 7.5epss 0.05

    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak.

  • CVE-2021-46854HigNov 23, 2022
    risk 0.00cvss 7.5epss 0.01

    mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.

  • CVE-2022-3957MedNov 11, 2022
    risk 0.00cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory leak. The attack can be launched…

  • CVE-2022-3646LowOct 21, 2022
    risk 0.00cvss 3.1epss 0.01

    A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function nilfs_attach_log_writer of the file fs/nilfs2/segment.c of the component BPF. The manipulation leads to memory leak. The attack may be initiated remotely. It is…