CWE-772
469 CVEs • Abstraction: Base • Likelihood of Exploit: High
Missing Release of Resource after Effective Lifetime
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
CVEs (469)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function. |
A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1...Show more |
Foxit Reader before 9.7 allows an Access Violation and crash if insufficient memory exists. |
A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination. This can lead to a build-up...Show more |
A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users. Affects all versions prior to Firefox 60. |
3Debian FedoraprojectRedhat3389 Directory Server Debian LinuxEnterprise LinuxJun 17, 2026 Apr 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests....Show more |
2Canonical Ceph2Civetweb Ubuntu LinuxJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors fo...Show more |
3Libtiff OpensuseSuse5Leap LibtiffLinux Enterprise Desktop+2 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to...Show more |
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not release a resource after its effective lifetime has ended, which...Show more |
An extension to hooks capabilities which debuted in Kea 1.4.0 introduced a memory leak for operators who are using certain hooks library facilities. In order to support multiple requests simultaneously, Kea 1.4 added a c...Show more |
2F5 Gnu2Binutils Traffix Signaling Delivery ControllerNov 21, 2024 Jan 2, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfi...Show more |
2Debian Jasper Project2Debian Linux JasperMay 6, 2025 Dec 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used. |
There is memory leak at liblas::Open (liblas/liblas.hpp) in libLAS 1.8.1. |
An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_StdcFileByteStream::Create in System/StdC/Ap4StdCFileByteStream.cpp, as demonstrated by mp42hls. |
An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42hls. |
3Canonical OpensuseQemu3Leap QemuUbuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled. |
3Canonical FedoraprojectQemu3Fedora QemuUbuntu LinuxNov 21, 2024 Dec 17, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error. |
3F5 GnuNetapp3Binutils Traffix Signaling Delivery ControllerVasa ProviderNov 21, 2024 Dec 10, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service...Show more |
1Libconfuse Project 1Libconfuse Nov 21, 2024 Nov 30, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak. |
1Powerdns 2Authoritative RecursorNov 21, 2024 Nov 29, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed records that can lead to...Show more |