CWE-772— Missing Release of Resource after Effective Lifetime
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.— MITRE CWE catalog
518 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-772page 6 of 11
- CVE-2018-11097HIGHCVSS 7.5EG 7.52018-05-15
An issue was discovered in cloudwu/cstring through 2016-11-09. There is a memory leak vulnerability that could lead to a program crash.
- CVE-2018-11364HIGHCVSS 7.5EG 7.52018-05-22
sav_parse_machine_integer_info_record in spss/readstat_sav_read.c in libreadstat.a in ReadStat 0.1.1 has a memory leak related to an iconv_open call.
- CVE-2018-11655MEDIUMCVSS 6.5EG 6.52018-06-01
In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCore/cache.c, which allows attackers to cause a denial of service via a crafted CALS image file.
- CVE-2018-11656MEDIUMCVSS 6.5EG 6.52018-06-01
In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cause a denial of service via a crafted DCM image file.
- CVE-2018-12093HIGHCVSS 7.5EG 7.52018-06-11
tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h.
- CVE-2018-13066HIGHCVSS 7.5EG 7.52018-07-02
There is a memory leak in util/parser.c in libming 0.4.8, which will lead to a denial of service via parseSWF_DEFINEBUTTON2, parseSWF_DEFINEFONT, parseSWF_DEFINEFONTINFO, parseSWF_DEFINELOSSLESS, parseSWF_DEFINESPRITE, parseSWF_DEFINETEXT,…
- CVE-2018-13153MEDIUMCVSS 6.5EG 6.52018-07-05
In ImageMagick 7.0.8-4, there is a memory leak in the XMagickCommand function in MagickCore/animate.c.
- CVE-2018-13419MEDIUMCVSS 6.5EG 6.52018-07-07
An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c, as demonstrated by sndfile-convert. NOTE: The maintainer and third parties were unable to reproduce and closed the issue
- CVE-2018-13420HIGHCVSS 7.5EG 7.52018-07-07
Google gperftools 2.7 has a memory leak in malloc_extension.cc, related to MallocExtension::Register and InitModule. NOTE: the software maintainer indicates that this is not a bug; it is only a false-positive report from the LeakSanitizer …
- CVE-2018-13843HIGHCVSS 7.5EG 7.52018-07-10
An issue has been found in HTSlib 1.8. It is a memory leak in bgzf_getline in bgzf.c. NOTE: the software maintainer's position is that the "failure to free memory" can be fixed in applications that use the HTSlib library (such as test/test…
- CVE-2018-14072HIGHCVSS 7.5EG 7.52018-07-15
libsixel 1.8.1 has a memory leak in sixel_decoder_decode in decoder.c, image_buffer_resize in fromsixel.c, and sixel_decode_raw in fromsixel.c.
- CVE-2018-14073HIGHCVSS 7.5EG 7.52018-07-15
libsixel 1.8.1 has a memory leak in sixel_allocator_new in allocator.c.
- CVE-2018-14434MEDIUMCVSS 6.5EG 6.52018-07-20
ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.
- CVE-2018-14435MEDIUMCVSS 6.5EG 6.52018-07-20
ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.
- CVE-2018-14436MEDIUMCVSS 6.5EG 6.52018-07-20
ImageMagick 7.0.8-4 has a memory leak in ReadMIFFImage in coders/miff.c.
- CVE-2018-14437MEDIUMCVSS 6.5EG 6.52018-07-20
ImageMagick 7.0.8-4 has a memory leak in parse8BIM in coders/meta.c.
- CVE-2018-16548MEDIUMCVSS 6.5EG 6.52018-09-05
An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack.
- CVE-2018-16640MEDIUMCVSS 6.5EG 6.52018-09-06
ImageMagick 7.0.8-5 has a memory leak vulnerability in the function ReadOneJNGImage in coders/png.c.
- CVE-2018-16641MEDIUMCVSS 6.5EG 6.52018-09-06
ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c.
- CVE-2018-16750MEDIUMCVSS 6.5EG 6.52018-09-09
In ImageMagick 7.0.7-29 and earlier, a memory leak in the formatIPTCfromBuffer function in coders/meta.c was found.
- CVE-2018-16807HIGHCVSS 7.5EG 7.52018-09-11
In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Kerberos protocol parser.
- CVE-2018-17234MEDIUMCVSS 6.5EG 6.52018-09-20
Memory leak in the H5O__chunk_deserialize() function in H5Ocache.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
- CVE-2018-17332HIGHCVSS 7.5EG 7.52018-09-22
An issue was discovered in libsvg2 through 2012-10-19. The svgGetNextPathField function in svg_string.c returns its input pointer in certain circumstances, which might result in a memory leak caused by wasteful malloc calls.
- CVE-2018-17437MEDIUMCVSS 6.5EG 6.52018-09-24
Memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
- CVE-2018-17965MEDIUMCVSS 6.5EG 6.52018-10-03
ImageMagick 7.0.7-28 has a memory leak vulnerability in WriteSGIImage in coders/sgi.c.
- CVE-2018-17966MEDIUMCVSS 6.5EG 6.52018-10-03
ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePDBImage in coders/pdb.c.
- CVE-2018-17967MEDIUMCVSS 6.5EG 6.52018-10-03
ImageMagick 7.0.7-28 has a memory leak vulnerability in ReadBGRImage in coders/bgr.c.
- CVE-2018-18016MEDIUMCVSS 6.5EG 6.52018-10-05
ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePCXImage in coders/pcx.c.
- CVE-2018-18226HIGHCVSS 7.5EG 7.52018-10-12
In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory. This was addressed in epan/dissectors/packet-steam-ihs-discovery.c by changing the memory-management approach.
- CVE-2018-18443MEDIUMCVSS 4.3EG 4.32018-10-17
OpenEXR 2.3.0 has a memory leak in ThreadPool in IlmBase/IlmThread/IlmThreadPool.cpp, as demonstrated by exrmultiview.
- CVE-2018-18482MEDIUMCVSS 6.5EG 6.52018-10-18
An issue was discovered in libpg_query 10-1.0.2. There is a memory leak in pg_query_raw_parse in pg_query_parse.c, which might lead to a denial of service.
- CVE-2018-18544MEDIUMCVSS 6.5EG 6.52018-10-21
There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.
- CVE-2018-18897MEDIUMCVSS 6.5EG 6.52018-11-02
An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.
- CVE-2018-19132MEDIUMCVSS 5.9EG 5.92018-11-09
Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet.
- CVE-2018-19139MEDIUMCVSS 5.5EG 5.52018-11-09
An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.
- CVE-2018-19213MEDIUMCVSS 5.5EG 5.52018-11-12
Netwide Assembler (NASM) through 2.14rc16 has memory leaks that may lead to DoS, related to nasm_malloc in nasmlib/malloc.c.
- CVE-2018-19760HIGHCVSS 8.8EG 8.82018-11-30
cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak.
- CVE-2018-1999043HIGHCVSS 7.5EG 7.52018-08-23
A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows attackers to create ephemeral in-memory user records by attempt…
- CVE-2018-20002MEDIUMCVSS 5.5EG 5.52018-12-10
The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service (memory consumptio…
- CVE-2018-20123MEDIUMCVSS 5.5EG 5.52018-12-17
pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.
- CVE-2018-20126MEDIUMCVSS 5.5EG 5.52018-12-20
hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.
- CVE-2018-20407MEDIUMCVSS 6.5EG 6.52018-12-23
An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42hls.
- CVE-2018-20408MEDIUMCVSS 6.5EG 6.52018-12-23
An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_StdcFileByteStream::Create in System/StdC/Ap4StdCFileByteStream.cpp, as demonstrated by mp42hls.
- CVE-2018-20540MEDIUMCVSS 6.5EG 6.52018-12-28
There is memory leak at liblas::Open (liblas/liblas.hpp) in libLAS 1.8.1.
- CVE-2018-20622MEDIUMCVSS 6.5EG 6.52018-12-31
JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used.
- CVE-2018-20657HIGHCVSS 7.5EG 7.52019-01-02
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue…
- CVE-2018-21028HIGHCVSS 7.5EG 7.52019-10-11
Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.
- CVE-2018-3658MEDIUMCVSS 5.3EG 5.32018-09-12
Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.
- CVE-2018-5179HIGHCVSS 7.5EG 7.52019-04-26
A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users. Affects all versions prior to Firefox 60.
- CVE-2018-5246MEDIUMCVSS 6.5EG 6.52018-01-05
In ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadPATTERNImage in coders/pattern.c.
Map vulnerabilities like CWE-772 to your infrastructure
EchelonGraph correlates every CVE — across CWE-772 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →