VYPR

CWE-401

Missing Release of Memory after Effective Lifetime

VariantDraftLikelihood: Medium

Description

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1,939)

page 95 of 97
  • CVE-2026-22024MedJan 10, 2026
    risk 0.00cvss 5.3epss 0.00

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the…

  • CVE-2026-21674LowJan 6, 2026
    risk 0.00cvss 3.3epss 0.00

    iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below contain a memory leak vulnerability in its XML MPE Parsing Path (iccFromXml). This issue is fixed in version 2.3.1.1.

  • CVE-2025-50951MedOct 23, 2025
    risk 0.00cvss 6.5epss 0.00

    FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.

  • CVE-2025-50949MedOct 23, 2025
    risk 0.00cvss 6.5epss 0.00

    FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.

  • CVE-2025-60361LowOct 17, 2025
    risk 0.00cvss 3.3epss 0.00

    radare2 v5.9.8 and before contains a memory leak in the function bochs_open.

  • CVE-2025-60360MedOct 17, 2025
    risk 0.00cvss 5.5epss 0.00

    radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.

  • CVE-2025-60359MedOct 17, 2025
    risk 0.00cvss 5.5epss 0.00

    radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.

  • CVE-2025-60358MedOct 16, 2025
    risk 0.00cvss 5.5epss 0.00

    radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.

  • CVE-2025-54939MedAug 1, 2025
    risk 0.00cvss 5.3epss 0.01

    LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.

  • CVE-2025-53537HigJul 23, 2025
    risk 0.00cvss 7.5epss 0.00

    LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces. In versions 0.5.50 and below, there is a traffic-induced memory leak that can starve the process of memory, leading to loss of visibility. To workaround this issue, set `suricata.yaml…

  • CVE-2024-8376HigOct 11, 2024
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.

  • CVE-2024-24267HigFeb 5, 2024
    risk 0.00cvss 7.5epss 0.02

    gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function.

  • CVE-2024-24259HigFeb 5, 2024
    risk 0.00cvss 7.5epss 0.01

    freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.

  • CVE-2024-24258HigFeb 5, 2024
    risk 0.00cvss 7.5epss 0.01

    freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.

  • CVE-2023-7192MedJan 2, 2024
    risk 0.00cvss 5.5epss 0.00

    A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service (DoS) attack due to a refcount overflow.

  • CVE-2023-41102HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version…

  • CVE-2023-28366HigSep 1, 2023
    risk 0.00cvss 7.5epss 0.01

    The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc…

  • CVE-2023-39978LowAug 8, 2023
    risk 0.00cvss 3.3epss 0.00

    ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.

  • CVE-2023-2700MedMay 15, 2023
    risk 0.00cvss 5.5epss 0.00

    A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.

  • CVE-2023-2618MedMay 10, 2023
    risk 0.00cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this issue is the function DecodedBitStreamParser::decodeHanziSegment of the file qrcode/decoder/decoded_bit_stream_parser.cpp. The manipulation leads to…