VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,935)

page 9 of 97
  • CVE-2023-30637HigApr 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Baidu braft 1.1.2 has a memory leak related to use of the new operator in example/atomic/atomic_server. NOTE: installations with brpc-0.14.0 and later are unaffected.

  • CVE-2022-45920HigJan 26, 2023
    risk 0.49cvss 7.5epss 0.01

    In Softing uaToolkit Embedded before 1.41, a malformed CreateMonitoredItems request may cause a memory leak.

  • CVE-2023-22417HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A Missing Release of Memory after Effective Lifetime vulnerability in the Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). In an IPsec VPN environment, a memory leak will be seen if a…

  • CVE-2023-22410HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A Missing Release of Memory after Effective Lifetime vulnerability in the Juniper Networks Junos OS on MX Series platforms with MPC10/MPC11 line cards, allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). Devices are only vulnerable when the Suspicious…

  • CVE-2022-43272HigDec 2, 2022
    risk 0.49cvss 7.5epss 0.02

    DCMTK v3.6.7 was discovered to contain a memory leak via the T_ASC_Association object.

  • CVE-2022-43223HigNov 1, 2022
    risk 0.49cvss 7.5epss 0.01

    open5gs v2.4.11 was discovered to contain a memory leak in the component ngap-handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted UE attachment.

  • CVE-2022-43222HigNov 1, 2022
    risk 0.49cvss 7.5epss 0.01

    open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

  • CVE-2022-43221HigNov 1, 2022
    risk 0.49cvss 7.5epss 0.01

    open5gs v2.4.11 was discovered to contain a memory leak in the component src/upf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.

  • CVE-2022-41832HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when a SIP profile is configured on a virtual server, undisclosed messages can cause an increase in memory resource utilization.

  • CVE-2022-41624HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.2, 15.1.x before 15.1.7, 14.1.x before 14.1.5.2, and 13.1.x before 13.1.5.1, when a sideband iRule is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization.

  • CVE-2022-2963HigOct 14, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.

  • CVE-2022-38371HigOct 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.7), APOGEE…

  • CVE-2022-38178HigSep 21, 2022
    risk 0.49cvss 7.5epss 0.03

    By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

  • CVE-2022-38177HigSep 21, 2022
    risk 0.49cvss 7.5epss 0.03

    By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

  • CVE-2022-2906HigSep 21, 2022
    risk 0.49cvss 7.5epss 0.02

    An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.

  • CVE-2022-39005HigSep 16, 2022
    risk 0.49cvss 7.5epss 0.01

    The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.

  • CVE-2022-39004HigSep 16, 2022
    risk 0.49cvss 7.5epss 0.01

    The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.

  • CVE-2022-40281HigSep 8, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.

  • CVE-2022-22067HigSep 2, 2022
    risk 0.49cvss 7.5epss 0.00

    Potential memory leak in modem during the processing of NSA RRC Reconfiguration with invalid Radio Bearer Config in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2021-42523HigAug 25, 2022
    risk 0.49cvss 7.5epss 0.01

    There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxml2 emphasizes that the caller needs to…