CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,774 vulnerabilities with CWE-401
CVE-2019-6135 HIGH
libiec61850 1.3.1 - Memory Leak in Asn1PrimitiveValue_create
CVSS 7.5
CVE-2019-6132 HIGH
Bento4 1.5.1-627 - Memory Leak in AP4_DescriptorFactory
CVSS 7.5
CVE-2019-6129 MEDIUM
libpng 1.6.36 - Memory Leak in png_create_info_struct
CVSS 6.5
CVE-2019-6128 HIGH
libtiff 4.0.10 - Memory Leak in TIFFFdOpen
CVSS 8.8
CVE-2018-17240 HIGH
Netwave IP Camera - Info Disclosure
CVSS 7.5
CVE-2018-11246 HIGH
K7Computing K7AntiVirus Premium 15.1.0.53 - Memory Leak in K7TSMngr.exe
CVSS 7.5
CVE-2018-21079 HIGH
Android - Kernel Pointer Leak in USB Gadget Driver
CVSS 7.5
CVE-2018-21017 MEDIUM
GPAC 0.7.1 - Use-After-Free in dinf_Read
CVSS 6.5
CVE-2018-15377 HIGH
Cisco IOS Software/Cisco IOS XE Software - Memory Leak
CVSS 8.6
CVE-2018-13844 HIGH
htslib 1.8 - Memory Leak in fai_read
CVSS 7.5
CVE-2018-0158 HIGH KEV
Cisco IOS and IOS XE - Denial of Service via IKEv2 Packet Processing
CVSS 8.6
CVE-2018-0901 MEDIUM
Windows Kernel - Information Disclosure via Memory Address Handling
CVSS 4.7
CVE-2018-0895 MEDIUM
Windows Kernel - Information Disclosure via Memory Address Handling
CVSS 4.7
CVE-2018-0891 MEDIUM
Internet Explorer - Information Disclosure via Scripting Engine Memory Handling
CVSS 4.3
CVE-2018-0832 MEDIUM
Windows Kernel - Information Disclosure via Memory Object Handling
CVSS 4.7
CVE-2017-7654 HIGH
Eclipse Mosquitto < 1.4.15 - Unauthenticated Memory Leak via Crafted CONNECT Packets
CVSS 7.5
CVE-2017-15094 MEDIUM
PowerDNS Recursor 4.0.0-4.0.6 - Memory Leak in DNSSEC ECDSA Key Parsing
CVSS 5.9
CVE-2017-9374 MEDIUM
QEMU < 2.8.1.1 - Memory Leak via USB EHCI Emulation Hot-Unplug
CVSS 5.5
CVE-2017-9373 MEDIUM
QEMU < 2.8.1.1 - Denial of Service via AHCI Device Hot-Unplug
CVSS 5.5
CVE-2017-9060 MEDIUM
QEMU < 2.8.1.1 - Denial of Service via Virtio GPU Scanout Command
CVSS 5.5
CVE-2017-5857 MEDIUM
QEMU < 2.8.1.1 - Denial of Service via Virgl Resource Unref Memory Leak
CVSS 6.5
CVE-2017-5856 MEDIUM
QEMU < 2.8.1.1 - Denial of Service via MegaRAID Firmware Interface Command Memory Leak
CVSS 6.5
CVE-2017-5579 MEDIUM
QEMU < 2.8.1.1 - Denial of Service via Serial Device Unplug Operations
CVSS 6.5
CVE-2017-5578 MEDIUM
QEMU < 2.8.1.1 - Denial of Service via Virtio GPU Resource Attach Backing Command
CVSS 6.5
CVE-2017-5552 MEDIUM
QEMU < 2.8.1.1 - Memory Leak in virgl_resource_attach_backing
CVSS 6.5
Details
Vulnerabilities 1,774
Exploit Likelihood Medium