VYPR

CWE-772

Missing Release of Resource after Effective Lifetime

BaseDraftLikelihood: High

Description

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-469

CVEs mapped to this weakness (494)

page 24 of 25
  • CVE-2026-12353MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.

  • CVE-2026-36590HigJul 15, 2026
    risk 0.00cvss 7.5epss 0.01

    An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component

  • CVE-2026-13351HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small number of maliciously fragmented IPv6 packets. When such a packet is handled by the fragment-header processing path, the associated RX network packet buffer…

  • CVE-2025-62723MedOct 24, 2025
    risk 0.00cvss 4.3epss 0.00

    FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user can create sessions and have them collect QoS messages. When not sent to a client, these are then not released upon (eventual) session expiration. Version 1.23.2…

  • CVE-2023-22996MedFeb 28, 2023
    risk 0.00cvss 5.5epss 0.00

    In the Linux kernel before 5.17.2, drivers/soc/qcom/qcom_aoss.c does not release an of_find_device_by_node reference after use, e.g., with put_device.

  • CVE-2022-45887MedNov 25, 2022
    risk 0.00cvss 4.7epss 0.00

    An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the lack of a dvb_frontend_detach call.

  • CVE-2022-26354LowMar 16, 2022
    risk 0.00cvss 3.2epss 0.00

    A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.

  • CVE-2022-26353HigMar 16, 2022
    risk 0.00cvss 7.5epss 0.03

    A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.

  • CVE-2022-21698HigFeb 15, 2022
    risk 0.00cvss 7.5epss 0.06

    client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through…

  • CVE-2020-35876CriDec 31, 2020
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in the rio crate through 2020-05-11 for Rust. A struct can be leaked, allowing attackers to obtain sensitive information, cause a use-after-free, or cause a data race.

  • CVE-2019-19533LowDec 3, 2019
    risk 0.00cvss 2.4epss 0.00

    In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c driver, aka CID-a10feaf8c464.

  • CVE-2018-21028HigOct 11, 2019
    risk 0.00cvss 7.5epss 0.02

    Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.

  • CVE-2019-3821HigMar 27, 2019
    risk 0.00cvss 7.5epss 0.03

    A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors for ceph-radosgw service resulting in a remote denial of…

  • CVE-2018-19132MedNov 9, 2018
    risk 0.00cvss 5.9epss 0.06

    Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet.

  • CVE-2018-16807HigSep 11, 2018
    risk 0.00cvss 7.5epss 0.01

    In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Kerberos protocol parser.

  • CVE-2018-16641MedSep 6, 2018
    risk 0.00cvss 6.5epss 0.02

    ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c.

  • CVE-2018-16640MedSep 6, 2018
    risk 0.00cvss 6.5epss 0.03

    ImageMagick 7.0.8-5 has a memory leak vulnerability in the function ReadOneJNGImage in coders/png.c.

  • CVE-2018-10205MedApr 19, 2018
    risk 0.00cvss 5.3epss 0.01

    hyperstart 1.0.0 in HyperHQ Hyper has memory leaks in the container_setup_modules and hyper_rescan_scsi functions in container.c, related to runV 1.0.0 for Docker.

  • CVE-2018-8087MedMar 13, 2018
    risk 0.00cvss 5.5epss 0.00

    Memory leak in the hwsim_new_radio_nl function in drivers/net/wireless/mac80211_hwsim.c in the Linux kernel through 4.15.9 allows local users to cause a denial of service (memory consumption) by triggering an out-of-array error case.

  • CVE-2018-7757MedMar 8, 2018
    risk 0.00cvss 5.5epss 0.01

    Memory leak in the sas_smp_get_phy_events function in drivers/scsi/libsas/sas_expander.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (memory consumption) via many read accesses to files in the /sys/class/sas_phy directory, as demonstrated…