VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,889)

page 9 of 95
  • CVE-2022-2963HigOct 14, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.

  • CVE-2022-38371HigOct 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.7), APOGEE…

  • CVE-2022-38178HigSep 21, 2022
    risk 0.49cvss 7.5epss 0.03

    By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

  • CVE-2022-38177HigSep 21, 2022
    risk 0.49cvss 7.5epss 0.03

    By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

  • CVE-2022-2906HigSep 21, 2022
    risk 0.49cvss 7.5epss 0.02

    An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.

  • CVE-2022-39005HigSep 16, 2022
    risk 0.49cvss 7.5epss 0.01

    The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.

  • CVE-2022-39004HigSep 16, 2022
    risk 0.49cvss 7.5epss 0.01

    The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.

  • CVE-2022-40281HigSep 8, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.

  • CVE-2022-22067HigSep 2, 2022
    risk 0.49cvss 7.5epss 0.00

    Potential memory leak in modem during the processing of NSA RRC Reconfiguration with invalid Radio Bearer Config in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2021-42523HigAug 25, 2022
    risk 0.49cvss 7.5epss 0.01

    There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to…

  • CVE-2021-42522HigAug 25, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of libxml2 API. The vendor forgot to call 'g_free()' to release the return value of 'xmlGetProp()'.

  • CVE-2021-33646HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.

  • CVE-2021-33645HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.02

    The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.

  • CVE-2022-22209HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a Denial of Service (DoS). On all Junos platforms, the Kernel Routing Table (KRT) queue can get stuck due to a…

  • CVE-2022-22205HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A Missing Release of Memory after Effective Lifetime vulnerability in the Application Quality of Experience (appqoe) subsystem of the PFE of Juniper Networks Junos OS on SRX Series allows an unauthenticated network based attacker to cause a Denial of Service (DoS). Upon…

  • CVE-2021-41490HigJun 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior.

  • CVE-2021-35078HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.00

    Possible memory leak due to improper validation of certificate chain length while parsing server certificate chain in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2018-17240HigJun 10, 2022
    risk 0.49cvss 7.5epss 0.04

    There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password).

  • CVE-2022-29932HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.03

    The HTTP Server in PRIMEUR SPAZIO 2.5.1.954 (File Transfer) allows an unauthenticated attacker to obtain sensitive data (related to the content of transferred files) via a crafted HTTP request.

  • CVE-2022-20785HigMay 4, 2022
    risk 0.49cvss 7.5epss 0.07

    On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in HTML file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior…