CWE-401
1,910 CVEs • Abstraction: Variant • Likelihood of Exploit: Medium
Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
CVEs (1,910)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In WebKitGTK before 2.32.4, there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create, leading to a segmentation violation and application crash, a different vulnerability than CVE-2021...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Dec 24, 2021 N/A· v4 5.5 MEDIUM· v3 4.7 MEDIUM· v2 An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function in net/rds/connection.c in a certain combination of circumstances. |
A memory leak vulnerability was found in Privoxy when handling errors. |
A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination. |
A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing. |
There is a Memory leak vulnerability with the codec detection module in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart due to memory exhaustion. |
2Bluez Debian2Bluez Debian LinuxJun 17, 2026 Nov 12, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be fre...Show more |
pdf2xml v2.0 was discovered to contain a memory leak in the function TextPage::testLinkedText. |
1Phoenixcontact 2Fl Mguard 1102 Firmware Fl Mguard 1105 FirmwareJun 17, 2026 Nov 10, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active |
There is a Memory leaks vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability. |
2Cisco Snort5Firepower Threat Defense Secure Firewall Management CenterSecure Firewall Threat Defense+2 moreAug 11, 2026 Oct 27, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an...Show more |
1Cisco 11Adaptive Security Appliance Software Asa 5505 FirmwareAsa 5512 X Firmware+8 moreAug 11, 2026 Oct 27, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS)...Show more |
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. FreeSWITCH prior to version 1.10.7 is...Show more |
A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows an adjacent attacker to cause a Denial of Service (DoS) by sendin...Show more |
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A remote attacker may be able to leak memory. |
Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input. |
Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input. |
A vulnerability in the proxy service of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial of service (DoS) condition on an af...Show more |
rudp v0.6 was discovered to contain a memory leak in the component main.c. |
1Cisco 1Aironet Access Point Software Jun 17, 2026 Sep 23, 2021 N/A· v4 7.4 HIGH· v3 6.1 MEDIUM· v2 A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a den...Show more |