CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,774 vulnerabilities with CWE-401
CVE-2017-5526 MEDIUM
QEMU < 2.8.1.1 - Denial of Service via ES1370 Device Unplug Operations
CVSS 6.5
CVE-2017-5525 MEDIUM
QEMU < 2.8.1.1 - Denial of Service via AC97 Device Unplug Operations
CVSS 6.5
CVE-2016-10155 MEDIUM
QEMU < 2.8.1.1 - Denial of Service via Device Unplug Operations
CVSS 6.0
CVE-2016-9916 MEDIUM
QEMU < 2.8.0 - Memory Leak in 9p-proxy Backend
CVSS 6.5
CVE-2016-9915 MEDIUM
QEMU < 2.7.1 - Use-After-Free in 9p-handle
CVSS 6.5
CVE-2016-9914 MEDIUM
QEMU < 2.7.1 - Denial of Service via Memory Leak in 9p FileSystem
CVSS 6.5
CVE-2016-9913 MEDIUM
QEMU < 2.7.1 - Denial of Service via Memory Leak in v9fs_device_unrealize_common
CVSS 6.5
CVE-2016-6304 HIGH
OpenSSL <1.0.1u, <1.0.2i, <1.1.0a - DoS
CVSS 7.5
CVE-2016-4232 HIGH
Adobe Flash Player <18.0.0.366,19.x-22.x - Info Disclosure
CVSS 7.5
CVE-2015-8567 HIGH
QEMU < 2.5.1.1 - Memory Leak in VMXNET3 Network Driver
CVSS 7.7
CVE-2010-2942 MEDIUM
Linux kernel <2.6.36-rc2 - Info Disclosure
CVSS 5.5
CVE-2010-2249 MEDIUM
libpng < 1.2.44 and 1.4.x < 1.4.3 - Denial of Service via Malformed sCAL Chunk
CVSS 6.5
CVE-2009-5063
libpng < 1.2.38 - Denial of Service via Negative Embedded Profile Length in iCCP Chunk
CVE-2009-1378
OpenSSL 0.9.8-0.9.8k - Denial of Service via DTLS Fragment Handling Memory Leak
CVE-2009-0581
LittleCMS <1.18beta2 - Memory Corruption
CVE-2008-3913
ClamAV < 0.94 - Denial of Service via Memory Leak in Error Handling Logic
CVE-2007-2274
Opera Browser 9.2 - Denial of Service via Malformed Torrent File
CVE-2005-3181
Linux kernel <2.6.13.4 - Memory Leak
CVE-2005-3119
Linux Kernel 2.6.10-2.6.13 - Denial of Service via Memory Leak in request_key_auth_destroy
CVE-2004-0427
Linux Kernel 2.4.0-2.4.25 - Denial of Service via Clone System Call Memory Leak
CVE-2004-0222
OpenBSD < 3.4 - Denial of Service via ISAKMP Packet Memory Leak
CVE-2002-0574
FreeBSD < 4.5 - Denial of Service via ICMP Echo Packet Memory Leak
CVE-2001-0543
Exchange Server - Denial of Service via NNTP Memory Leak
CVE-2001-0136
ProFTPd 1.2.0rc2 - Denial of Service via USER Command Memory Leak
Details
Vulnerabilities 1,774
Exploit Likelihood Medium