CWE-244
21 CVEs • Abstraction: Variant
Improper Clearing of Heap Memory Before Release ('Heap Inspection')
Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.
CVEs (21)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 5Cyber Vision Firepower Threat DefenseSecure Firewall Threat Defense+2 moreAug 11, 2026 Nov 15, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies o...Show more |