← Back
CWE-772

469 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

JSON object

Loading...

CVEs (469)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Freebsd
1Freebsd
Jun 17, 2026
May 13, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a race condition in the cryptodev module permitted a data structure in the kernel to be used after it...Show more
In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a race condition in the cryptodev module permitted a data structure in the kernel to be used after it was freed, allowing an unprivileged process can overwrite arbitrary kernel memory.Show less
1Linux
1Linux Kernel
Jun 17, 2026
May 9, 2020
N/A· v4
4.7 MEDIUM· v3
4.7 MEDIUM· v2
An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE files...Show more
An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.Show less
1Nanometrics
2Centaur
Titansma
Jun 17, 2026
Apr 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.
1Google
1Android
Nov 21, 2024
Apr 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) (Exynos7420 or Exynox8890 chipsets) software. The Camera application can leak uninitialized memory via ion. The Samsung ID is SVE-2016-6989 (April...Show more
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) (Exynos7420 or Exynox8890 chipsets) software. The Camera application can leak uninitialized memory via ion. The Samsung ID is SVE-2016-6989 (April 2017).Show less
1Tp Link
1Archer C50
Jun 17, 2026
Mar 25, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Nov 21, 2024
Feb 20, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The Linux kernel from v2.3.36 before v2.6.39 allows local unprivileged users to cause a denial of service (memory consumption) by triggering creation of PTE pages.
1Cisco
1Ios
Nov 21, 2024
Feb 12, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
A memory leak vulnerability exists in Cisco IOS before 15.2(1)T due to a memory leak in the HTTP PROXY Server process (aka CSCtu52820), when configured with Cisco ISR Web Security with Cisco ScanSafe and User Authenticai...Show more
A memory leak vulnerability exists in Cisco IOS before 15.2(1)T due to a memory leak in the HTTP PROXY Server process (aka CSCtu52820), when configured with Cisco ISR Web Security with Cisco ScanSafe and User Authenticaiton NTLM configured.Show less
7Canonical
DebianFedoraproject+4 more
12Active Iq Unified Manager
Clustered Data OntapClustered Data Ontap Antivirus Connector+9 more
Jun 17, 2026
Dec 24, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
1Qualcomm
13Qcs405 Firmware
Sd 205 FirmwareSd 210 Firmware+10 more
Jun 17, 2026
Dec 12, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An unprivileged application can allocate GPU memory by calling memory allocation ioctl function and can exhaust all the memory which results in out of memory in Snapdragon Mobile, Snapdragon Voice & Music in QCS405, SD 2...Show more
An unprivileged application can allocate GPU memory by calling memory allocation ioctl function and can exhaust all the memory which results in out of memory in Snapdragon Mobile, Snapdragon Voice & Music in QCS405, SD 210/SD 212/SD 205, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 845 / SD 850, SD 855Show less
1Linux
1Linux Kernel
Jun 17, 2026
Dec 3, 2019
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c driver, aka CID-a10feaf8c464.
1Intel
7Ethernet 700 Series Software
Ethernet Controller 710 Bm1 FirmwareEthernet Controller X710 At2 Firmware+4 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.
1Intel
7Ethernet 700 Series Software
Ethernet Controller 710 Bm1 FirmwareEthernet Controller X710 At2 Firmware+4 more
Jun 17, 2026
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.
3Debian
OpensuseRsyslog
3Debian Linux
OpensuseRsyslog
Nov 21, 2024
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one rulesetShow less
3Debian
OpensuseRsyslog
3Debian Linux
OpensuseRsyslog
Nov 21, 2024
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset.Show less
3Debian
OpensuseRsyslog
3Debian Linux
OpensuseRsyslog
Nov 21, 2024
Nov 14, 2019
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon se...Show more
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service via a sequence of repeated log messages sent within short periods of time.Show less
3Debian
PhpRedhat
3Debian Linux
Enterprise LinuxPhp
Nov 21, 2024
Nov 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.
1Opensrcsec
2Grsecurity
Pax
Jun 17, 2026
Oct 31, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An exploitable vulnerability exists in the grsecurity PaX patch for the function read_kmem, in PaX from version pax-linux-4.9.8-test1 to 4.9.24-test7, grsecurity official from version grsecurity-3.1-4.9.8-201702060653 to...Show more
An exploitable vulnerability exists in the grsecurity PaX patch for the function read_kmem, in PaX from version pax-linux-4.9.8-test1 to 4.9.24-test7, grsecurity official from version grsecurity-3.1-4.9.8-201702060653 to grsecurity-3.1-4.9.24-201704252333, grsecurity unofficial from version v4.9.25-unofficialgrsec to v4.9.74-unofficialgrsec. PaX adds a temp buffer to the read_kmem function, which is never freed when an invalid address is supplied. This results in a memory leakage that can lead to a crash of the system. An attacker needs to induce a read to /dev/kmem using an invalid address to exploit this vulnerability.Show less
1Video Converter Project
1Video Converter
Jun 17, 2026
Oct 19, 2019
N/A· v4
7.7 HIGH· v3
6.8 MEDIUM· v2
The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurrent conversions because many FFmpeg processes may be running at once. (The workload is not queued for...Show more
The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurrent conversions because many FFmpeg processes may be running at once. (The workload is not queued for serial execution.)Show less
2Canonical
Linux
2Linux Kernel
Ubuntu Linux
Jun 17, 2026
Oct 18, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by...Show more
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.Show less
1Isc
1Kea
Jun 17, 2026
Oct 16, 2019
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are rejected as invalid when the server tries to load leases from storage on re...Show more
A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are rejected as invalid when the server tries to load leases from storage on restart. If the number of such leases exceeds a hard-coded limit in the Kea code, a server trying to restart will conclude that there is a problem with its lease store and give up. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1.6.0-beta2Show less