CWE-772
484 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Release of Resource after Effective Lifetime
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
CVEs (484)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Feb 20, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The Linux kernel from v2.3.36 before v2.6.39 allows local unprivileged users to cause a denial of service (memory consumption) by triggering creation of PTE pages. |
A memory leak vulnerability exists in Cisco IOS before 15.2(1)T due to a memory leak in the HTTP PROXY Server process (aka CSCtu52820), when configured with Cisco ISR Web Security with Cisco ScanSafe and User Authenticai...Show more |
7Canonical DebianFedoraproject+4 more12Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+9 moreJun 17, 2026 Dec 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. |
1Qualcomm 13Qcs405 Firmware Sd 205 FirmwareSd 210 Firmware+10 moreJun 17, 2026 Dec 12, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An unprivileged application can allocate GPU memory by calling memory allocation ioctl function and can exhaust all the memory which results in out of memory in Snapdragon Mobile, Snapdragon Voice & Music in QCS405, SD 2...Show more |
In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c driver, aka CID-a10feaf8c464. |
1Intel 7Ethernet 700 Series Software Ethernet Controller 710 Bm1 FirmwareEthernet Controller X710 At2 Firmware+4 moreJun 17, 2026 Nov 14, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access. |
1Intel 7Ethernet 700 Series Software Ethernet Controller 710 Bm1 FirmwareEthernet Controller X710 At2 Firmware+4 moreJun 17, 2026 Nov 14, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access. |
3Debian OpensuseRsyslog3Debian Linux OpensuseRsyslogNov 21, 2024 Nov 14, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more |
3Debian OpensuseRsyslog3Debian Linux OpensuseRsyslogNov 21, 2024 Nov 14, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more |
3Debian OpensuseRsyslog3Debian Linux OpensuseRsyslogNov 21, 2024 Nov 14, 2019 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon se...Show more |
3Debian PhpRedhat3Debian Linux Enterprise LinuxPhpNov 21, 2024 Nov 13, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output. |
An exploitable vulnerability exists in the grsecurity PaX patch for the function read_kmem, in PaX from version pax-linux-4.9.8-test1 to 4.9.24-test7, grsecurity official from version grsecurity-3.1-4.9.8-201702060653 to...Show more |
1Video Converter Project 1Video Converter Jun 17, 2026 Oct 19, 2019 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurrent conversions because many FFmpeg processes may be running at once. (The workload is not queued for...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Oct 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by...Show more |
A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are rejected as invalid when the server tries to load leases from storage on re...Show more |
Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function. |
A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1...Show more |
Foxit Reader before 9.7 allows an Access Violation and crash if insufficient memory exists. |
A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination. This can lead to a build-up...Show more |
A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users. Affects all versions prior to Firefox 60. |