← Back
CWE-772

469 CVEs • Abstraction: Base • Likelihood of Exploit: High

Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

JSON object

Loading...

CVEs (469)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Boa
1Boa
Nov 21, 2024
Oct 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.
1Isc
1Bind
Jun 17, 2026
Oct 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1...Show more
A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected.Show less
1Foxitsoftware
1Reader
Jun 17, 2026
Oct 4, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Foxit Reader before 9.7 allows an Access Violation and crash if insufficient memory exists.
1Cisco
1Nx Os
Jun 17, 2026
Aug 28, 2019
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination. This can lead to a build-up...Show more
A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination. This can lead to a build-up of VSH processes that overtime can deplete system memory. When there is no system memory available, this can cause unexpected system behaviors and crashes. The vulnerability is due to the VSH process not being properly deleted when a remote management connection to the device is disconnected. An attacker could exploit this vulnerability by repeatedly performing a remote management connection to the device and terminating the connection in an unexpected manner. A successful exploit could allow the attacker to cause the VSH processes to fail to delete, which can lead to a system-wide denial of service (DoS) condition. The attacker must have valid user credentials to log in to the device using the remote management connection.Show less
1Mozilla
1Firefox
Nov 21, 2024
Apr 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users. Affects all versions prior to Firefox 60.
3Debian
FedoraprojectRedhat
3389 Directory Server
Debian LinuxEnterprise Linux
Jun 17, 2026
Apr 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests....Show more
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.Show less
2Canonical
Ceph
2Civetweb
Ubuntu Linux
Jun 17, 2026
Mar 27, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors fo...Show more
A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors for ceph-radosgw service resulting in a remote denial of service.Show less
3Libtiff
OpensuseSuse
5Leap
LibtiffLinux Enterprise Desktop+2 more
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to...Show more
LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issueShow less
1Nvidia
1Gpu Driver
Jun 17, 2026
Feb 27, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not release a resource after its effective lifetime has ended, which...Show more
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not release a resource after its effective lifetime has ended, which may lead to denial of service.Show less
1Isc
1Kea
Jun 17, 2026
Jan 16, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An extension to hooks capabilities which debuted in Kea 1.4.0 introduced a memory leak for operators who are using certain hooks library facilities. In order to support multiple requests simultaneously, Kea 1.4 added a c...Show more
An extension to hooks capabilities which debuted in Kea 1.4.0 introduced a memory leak for operators who are using certain hooks library facilities. In order to support multiple requests simultaneously, Kea 1.4 added a callout handle store but unfortunately the initial implementation of this store does not properly free memory in every case. Hooks which make use of query4 or query6 parameters in their callouts can leak memory, resulting in the eventual exhaustion of available memory and subsequent failure of the server process. Affects Kea DHCP 1.4.0.Show less
2F5
Gnu
2Binutils
Traffix Signaling Delivery Controller
Nov 21, 2024
Jan 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfi...Show more
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.Show less
2Debian
Jasper Project
2Debian Linux
Jasper
May 6, 2025
Dec 31, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
1Liblas
1Liblas
Nov 21, 2024
Dec 28, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
There is memory leak at liblas::Open (liblas/liblas.hpp) in libLAS 1.8.1.
1Axiosys
1Bento4
Nov 21, 2024
Dec 23, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_StdcFileByteStream::Create in System/StdC/Ap4StdCFileByteStream.cpp, as demonstrated by mp42hls.
1Axiosys
1Bento4
Nov 21, 2024
Dec 23, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42hls.
3Canonical
OpensuseQemu
3Leap
QemuUbuntu Linux
Nov 21, 2024
Dec 20, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.
3Canonical
FedoraprojectQemu
3Fedora
QemuUbuntu Linux
Nov 21, 2024
Dec 17, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.
3F5
GnuNetapp
3Binutils
Traffix Signaling Delivery ControllerVasa Provider
Nov 21, 2024
Dec 10, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service...Show more
The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service (memory consumption), as demonstrated by nm.Show less
1Libconfuse Project
1Libconfuse
Nov 21, 2024
Nov 30, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak.
1Powerdns
2Authoritative
Recursor
Nov 21, 2024
Nov 29, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed records that can lead to...Show more
PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed records that can lead to remote denial of service.Show less