CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,772 vulnerabilities with CWE-401
CVE-2020-3195 HIGH
Cisco ASA & FTD OSPF Packet Processing Unauthenticated DoS
CVSS 7.5
CVE-2020-3189 HIGH
Cisco Firepower Threat Defense - Memory Leak
CVSS 8.6
CVE-2020-12656 MEDIUM
Linux Kernel < 5.6.10 - Memory Leak in rpcsec_gss_krb5 gss_mech_free
CVSS 5.5
CVE-2020-5883 HIGH
BIG-IP 13.1.0-13.1.3.1, 14.0.0-14.0.1, 14.1.0-14.1.2.3, 15.0.0-15.0.1 Memory Leak via HTTP Explicit Proxy
CVSS 7.5
CVE-2020-12430 MEDIUM
libvirt 4.10.0-6.x < 6.1.0 - Memory Leak in virDomainListGetStats API
CVSS 6.5
CVE-2020-4267 MEDIUM
IBM MQ 8.0.0.0-8.0.0.13, 9.1.0.0-9.1.0.3 & MQ Appliance 9.1.0-9.1.4 - Authenticated DoS via Memory Leak
CVSS 6.5
CVE-2020-1625 MEDIUM
Juniper Junos OS - Denial of Service via IRB Interface Flap Memory Leak
CVSS 6.5
CVE-2020-3914 MEDIUM
iPadOS < 13.4 - Unauthorized Memory Read via Memory Initialization Issue
CVSS 5.5
CVE-2020-6080 HIGH
libmicrodns 0.1.0 - Denial of Service via mDNS Message Parsing
CVSS 7.5
CVE-2020-6079 HIGH
libmicrodns 0.1.0 - Denial of Service via mDNS Message Parsing
CVSS 7.5
CVE-2020-10840 HIGH
Samsung mobile devices P(9.0)-Q(10.0) - Info Disclosure
CVSS 7.1
CVE-2020-10593 HIGH
Tor <0.3.5.10, 0.4.x <0.4.1.9, 0.4.2.x <0.4.2.7 - DoS
CVSS 7.5
CVE-2020-9431 HIGH
Wireshark 2.6.0-2.6.14, 3.0.0-3.0.8, 3.2.0-3.2.1 - Use-After-Free in LTE RRC Dissector
CVSS 7.5
CVE-2020-1815 HIGH
Huawei NIP6800 <V500R001C30-V500R005C00 - Memory Corruption
CVSS 7.5
CVE-2020-8991 LOW
LVM2 2.02 - Memory Leak in vg_lookup
CVSS 2.3
CVE-2020-3756 HIGH
Adobe Acrobat <2019.021.20061 - Memory Corruption
CVSS 7.5
CVE-2020-3753 HIGH
Adobe Acrobat <2019.021.20061 - Memory Corruption
CVSS 7.5
CVE-2020-7217 HIGH
openSUSE wicked < 0.6.55 - Denial of Service via DHCP4 Client-ID Mismatch
CVSS 7.5
CVE-2020-7216 HIGH
openSUSE wicked < 0.6.55 - Denial of Service via DHCP4 Packet Without Message Type Option
CVSS 7.5
CVE-2020-1603 HIGH
Juniper Junos OS - Denial of Service via IPv6 Packet Handling Memory Leak
CVSS 8.6
CVE-2019-14559 HIGH
EDK II - Unauthenticated Denial of Service via Network Resource Consumption
CVSS 7.5
CVE-2019-20888 HIGH
Mattermost Server < 5.7 - Denial of Service via Outgoing Webhook or Slash Command Integration
CVSS 7.5
CVE-2019-20810 MEDIUM
Linux Kernel < 5.6 - Use-After-Free in go7007_snd_init
CVSS 5.5
CVE-2019-10547 HIGH
Qualcomm Snapdragon Firmware - Use-After-Free via ION IOCTL Calls
CVSS 7.8
CVE-2019-20382 LOW
QEMU 4.1.0 - Memory Leak in VNC Disconnect Operation
CVSS 3.5
Details
Vulnerabilities 1,772
Exploit Likelihood Medium