CWE-772— Missing Release of Resource after Effective Lifetime
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.— MITRE CWE catalog
518 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-772page 9 of 11
- CVE-2021-29982MEDIUMCVSS 6.5EG 6.52021-08-17
Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, resulting in the potential leak of a single bit of memory. This vulnerability affects Firefox < 91 and Thunderbird < 91.
- CVE-2021-30002MEDIUMCVSS 6.2EG 6.22021-04-02
An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments, aka CID-fb18802a338b.
- CVE-2021-30129MEDIUMCVSS 6.5EG 6.52021-07-12
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was …
- CVE-2021-31378MEDIUMCVSS 6.8EG 6.82021-10-19
In broadband environments, including but not limited to Enhanced Subscriber Management, (CHAP, PPP, DHCP, etc.), on Juniper Networks Junos OS devices where RADIUS servers are configured for managing subscriber access and a subscriber is lo…
- CVE-2021-33437MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in mjs.c.
- CVE-2021-34581HIGHCVSS 7.5EG 7.52021-08-31
Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 in versions FW4 up to FW15 allows an unauthenticated attacker to cause DoS on the devic…
- CVE-2021-39282HIGHCVSS 7.5EG 7.52021-08-18
Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files.
- CVE-2021-40008HIGHCVSS 7.5EG 7.52021-12-13
There is a memory leak vulnerability in CloudEngine 12800 V200R019C00SPC800, CloudEngine 5800 V200R019C00SPC800, CloudEngine 6800 V200R019C00SPC800 and CloudEngine 7800 V200R019C00SPC800. The software does not sufficiently track and releas…
- CVE-2021-40797MEDIUMCVSS 6.5EG 6.52021-09-08
An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to co…
- CVE-2021-4190HIGHCVSS 7.5EG 7.52021-12-30
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file
- CVE-2021-42075HIGHCVSS 7.5EG 7.52021-11-08
An issue was discovered in Barrier before 2.3.4. The barriers component (aka the server-side implementation of Barrier) does not correctly close file descriptors for established TCP connections. An unauthenticated remote attacker can thus …
- CVE-2021-42197HIGHCVSS 7.8EG 7.82022-06-02
An issue was discovered in swftools through 20201222 through a memory leak in the swftools when swfdump is used. It allows an attacker to cause code execution.
- CVE-2021-42340HIGHCVSS 7.5EG 7.52021-10-14
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not rele…
- CVE-2021-42859HIGHCVSS 7.5EG 7.52022-05-26
A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 development code, but othe…
- CVE-2021-42860HIGHCVSS 7.5EG 7.52022-05-26
A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it will cause a stack-buffer-overflow in mxml_string_getc:2611. NOTE: it is unclear whether this input is allowed by the API …
- CVE-2021-47283MEDIUMCVSS 5.5EG 5.52024-05-21
In the Linux kernel, the following vulnerability has been resolved: net:sfc: fix non-freed irq in legacy irq mode SFC driver can be configured via modparam to work using MSI-X, MSI or legacy IRQ interrupts. In the last one, the interrupt…
- CVE-2021-47389MEDIUMCVSS 5.1EG 5.12024-05-21
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: fix missing sev_decommission in sev_receive_start DECOMMISSION the current SEV context if binding an ASID fails after RECEIVE_START. Per AMD's SEV API, RECEIV…
- CVE-2022-1100MEDIUMCVSS 4.3EG 4.32022-04-04
A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 prior to 14.8.5, and 14.9.0 prior to 14.9.2. The api to update an asset as a link from a release had a regex check which …
- CVE-2022-20023MEDIUMCVSS 6.5EG 6.52022-01-04
In Bluetooth, there is a possible application crash due to bluetooth flooding a device with LMP_AU_rand packet. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is no…
- CVE-2022-20697HIGHCVSS 8.6EG 8.62022-04-15
A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper resource manage…
- CVE-2022-22155MEDIUMCVSS 6.5EG 6.52022-01-19
An Uncontrolled Resource Consumption vulnerability in the handling of IPv6 neighbor state change events in Juniper Networks Junos OS allows an adjacent attacker to cause a memory leak in the Flexible PIC Concentrator (FPC) of an ACX5448 ro…
- CVE-2022-22170HIGHCVSS 7.5EG 7.52022-01-19
A Missing Release of Resource after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause a Denial of Service (DoS) by sending specific pac…
- CVE-2022-22215MEDIUMCVSS 6.5EG 6.52022-07-20
A Missing Release of File Descriptor or Handle after Effective Lifetime vulnerability in plugable authentication module (PAM) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to …
- CVE-2022-26353HIGHCVSS 7.5EG 7.52022-03-16
A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results.…
- CVE-2022-26354LOWCVSS 3.2EG 3.22022-03-16
A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions <= 6.2.0.
- CVE-2022-26356MEDIUMCVSS 5.6EG 5.62022-04-05
Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty hypercalls. A sui…
- CVE-2022-26878MEDIUMCVSS 5.5EG 5.52022-03-11
drivers/bluetooth/virtio_bt.c in the Linux kernel before 5.16.3 has a memory leak (socket buffers have memory allocated but not freed).
- CVE-2022-28187MEDIUMCVSS 5.5EG 5.52022-05-17
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where the memory management software does not release a resource after its effective lifetime has ended, which may lead to denial of se…
- CVE-2022-29884HIGHCVSS 7.5EG 7.52022-07-12
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < CPC80 V16.30), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < CPC80 V16.30), CP-8021 MASTER MODULE (All versions < CPC80 V16.30), C…
- CVE-2022-31222MEDIUMCVSS 2.3EG 4.42022-09-12
Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by consuming excess memory in order to cause the applica…
- CVE-2022-32149HIGHCVSS 7.5EG 7.52022-10-14
An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse.
- CVE-2022-34503MEDIUMCVSS 6.5EG 6.52022-07-22
QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
- CVE-2022-35110MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.
- CVE-2022-36152MEDIUMCVSS 5.5EG 5.52022-08-16
tifig v0.2.2 was discovered to contain a memory leak via operator new[](unsigned long) at /asan/asan_new_delete.cpp.
- CVE-2022-40280HIGHCVSS 7.5EG 7.52022-09-08
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisioningdatabasemanager.c has a missing sqlite3_close after sqlite3_open_v2, leading to a denial of service.
- CVE-2022-41952MEDIUMCVSS 6.5EG 6.52022-11-22
Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after `max_spider_size` (default: 10M) …
- CVE-2022-45887MEDIUMCVSS 4.7EG 4.72022-11-25
An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the lack of a dvb_frontend_detach call.
- CVE-2022-50189HIGHCVSS 7.1EG 7.12025-06-18
In the Linux kernel, the following vulnerability has been resolved: tools/power turbostat: Fix file pointer leak Currently if a fscanf fails then an early return leaks an open file pointer. Fix this by fclosing the file before the return…
- CVE-2023-1150HIGHCVSS 7.5EG 7.52023-06-26
Uncontrolled resource consumption in Series WAGO 750-3x/-8x products may allow an unauthenticated remote attacker to DoS the MODBUS server with specially crafted packets.
- CVE-2023-20095HIGHCVSS 8.6EG 8.62023-11-01
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condi…
- CVE-2023-22302MEDIUMCVSS 5.9EG 5.92023-02-01
In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when an HTTP profile is configured on a virtual server and conditions beyond the attacker’s control exist on the target pool member, undisclo…
- CVE-2023-22996MEDIUMCVSS 5.5EG 5.52023-02-28
In the Linux kernel before 5.17.2, drivers/soc/qcom/qcom_aoss.c does not release an of_find_device_by_node reference after use, e.g., with put_device.
- CVE-2023-31274MEDIUMCVSS 5.3EG 5.32024-01-18
AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to cause the PI Message Subsystem of a PI Server to consume available memory resulting in throttled processing of ne…
- CVE-2023-32255MEDIUMCVSS 5.3EG 5.32025-08-02
A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an unknown NTLMSSP message type, potentially leading to resource exhaustion.
- CVE-2023-36533HIGHCVSS 7.1EG 7.12023-08-08
Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.
- CVE-2023-41094CRITICALCVSS 9.8EG 10.02023-10-04
TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing d…
- CVE-2023-45814MEDIUMCVSS 5.3EG 5.32023-10-18
Bunkum is an open-source protocol-agnostic request server for custom game servers. First, a little bit of background. So, in the beginning, Bunkum's `AuthenticationService` only supported injecting `IUser`s. However, as Refresh and SoundSh…
- CVE-2023-47124MEDIUMCVSS 5.9EG 5.92023-12-04
Traefik is an open source HTTP reverse proxy and load balancer. When Traefik is configured to use the `HTTPChallenge` to generate and renew the Let's Encrypt TLS certificates, the delay authorized to solve the challenge (50 seconds) can be…
- CVE-2023-47216MEDIUMCVSS 5.5EG 5.52024-01-02
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through occupy all resources
- CVE-2023-53152MEDIUMCVSS 5.5EG 5.52025-09-15
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix calltrace warning in amddrm_buddy_fini The following call trace is observed when removing the amdgpu driver, which is caused by that BOs allocated for ps…
Map vulnerabilities like CWE-772 to your infrastructure
EchelonGraph correlates every CVE — across CWE-772 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →