CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,759 vulnerabilities with CWE-401
CVE-2022-35858 HIGH
Samsung mTower 0.3.0 - Memory Corruption
CVSS 7.8
CVE-2022-1651 HIGH
Linux Kernel 5.12-5.15.33 - Memory Leak in ACRN Virtual NIC Emulation
CVSS 7.1
CVE-2022-22209 HIGH
Juniper Junos OS 21.2-21.4 - Unauthenticated Denial of Service via Kernel Memory Leak
CVSS 7.5
CVE-2022-22205 HIGH
Juniper Networks Junos OS SRX Series - DoS
CVSS 7.5
CVE-2022-22204 MEDIUM
Juniper Networks Junos OS - Use After Free
CVSS 5.3
CVE-2022-26365 HIGH
Linux disk/nic frontends - Info Disclosure
CVSS 7.1
CVE-2022-33105 HIGH
Redis v7.0 - Memory Leak in streamGetEdgeID
CVSS 7.5
CVE-2022-29693 HIGH
unicorn-engine < 2.0.0 - Memory Leak in uc_close Function
CVSS 7.5
CVE-2022-29932 HIGH
PRIMEUR SPAZIO 2.5.1.954 - Unauthenticated Sensitive Data Exposure via HTTP Request
CVSS 7.5
CVE-2022-20785 HIGH
ClamAV < 0.103.5 and 0.104.0-0.104.2 - Use-After-Free in HTML File Parser
CVSS 7.5
CVE-2022-28487 HIGH
Tcpreplay <4.4.1 - Memory Corruption
CVSS 7.5
CVE-2022-1515 MEDIUM
matio < 1.5.22 - Memory Leak in Mat_VarReadNextInfo5()
CVSS 5.5
CVE-2022-23159 MEDIUM
Dell PowerScale OneFS 8.2.2-9.3.0 - Authenticated Denial of Service via Memory Management Issue
CVSS 4.8
CVE-2022-27950 MEDIUM
Linux Kernel < 5.16.11 - Memory Leak in HID ELO Driver
CVSS 5.5
CVE-2022-0854 MEDIUM
Linux Kernel < 5.16 - Memory Leak in DMA Subsystem
CVSS 5.5
CVE-2022-0742 CRITICAL
Linux Kernel 5.13+ - Denial of Service via ICMPv6 Type 130/131 Packet Memory Leak
CVSS 9.1
CVE-2022-24756 HIGH
Bareos 18.2-19.2.12 - Authenticated Denial of Service via PAM Authentication Memory Leak
CVSS 7.5
CVE-2022-0853 HIGH
Red Hat Decision Manager - Memory Leak via UserTransaction
CVSS 7.5
CVE-2022-26878 MEDIUM
Linux kernel <5.16.3 - Memory Corruption
CVSS 5.5
CVE-2022-24599 MEDIUM
Autofile Audio File Library 0.3.6 - Info Disclosure
CVSS 6.5
CVE-2022-22336 HIGH
IBM Sterling External Authentication Server & Secure Proxy 6.0.3.0/6.0.2.0/3.4.3.2 DoS via Resource Leak
CVSS 7.5
CVE-2022-24959 MEDIUM
Linux Kernel < 5.16.5 - Memory Leak in YAM Driver
CVSS 5.5
CVE-2022-20046 MEDIUM
Android - Memory Corruption in Bluetooth
CVSS 5.5
CVE-2022-23585 MEDIUM
TensorFlow < 2.5.3 - Use-After-Free in PNG Image Decoder
CVSS 4.3
CVE-2022-23578 MEDIUM
TensorFlow < 2.5.3 - Use-After-Free in ImmutableExecutorState::Initialize
CVSS 4.3
Details
Vulnerabilities 1,759
Exploit Likelihood Medium