CWE-401
1,910 CVEs • Abstraction: Variant • Likelihood of Exploit: Medium
Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
CVEs (1,910)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The SMI handler for the FwBlockServiceSmm driver uses an untrusted pointer as the location to copy data to an attacker-specified buffer, leading to...Show more |
4Debian FedoraprojectIsc+1 more4Active Iq Unified Manager BindDebian Linux+1 moreSep 1, 2026 Sep 21, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for l...Show more |
4Debian FedoraprojectIsc+1 more4Active Iq Unified Manager BindDebian Linux+1 moreSep 1, 2026 Sep 21, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for l...Show more |
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential...Show more |
SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c. |
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. |
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. |
Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vf_vo.c. |
An memory leak issue was discovered in AP4_StdcFileByteStream::Create in mp42ts in Bento4 v1.6.0-639, allows attackers to cause a denial of service via a crafted file. |
1Dell 25Chengming 3900 Firmware Inspiron 14 Plus 7420 FirmwareInspiron 16 Plus 7620 Firmware+22 moreJun 17, 2026 Sep 12, 2022 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by consuming excess memory in order t...Show more |
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure. |
1Qualcomm 59Ar8035 Firmware Qca6390 FirmwareQca6391 Firmware+56 moreJun 17, 2026 Sep 2, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Potential memory leak in modem during the processing of NSA RRC Reconfiguration with invalid Radio Bearer Config in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile |
2Fedoraproject Imagemagick2Fedora ImagemagickJun 17, 2026 Aug 26, 2022 N/A· v4 3.3 LOW· v3 N/A· v2 A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks. |
There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing aft...Show more |
There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of libxml2 API. The vendor forgot to call 'g_free()' to release the return...Show more |
3Debian DogtagpkiRedhat3Debian Linux Enterprise LinuxNetwork Security Services For JavaJun 17, 2026 Aug 24, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an...Show more |
4Canonical FedoraprojectOpenvswitch+1 more4Enterprise Linux Fast Datapath FedoraOpenvswitch+1 moreJun 17, 2026 Aug 23, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments. |
A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The vulnerability is similar to the older CVE-2019-18808. The highest threat from th...Show more |
A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O (VFIO) Mediated devices. This flaw could allow a local attacker to leak internal...Show more |
1Redhat 7Fuse Integration Camel KIntegration Camel Quarkus+4 moreJun 17, 2026 Aug 23, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is a...Show more |