CWE-772— Missing Release of Resource after Effective Lifetime
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.— MITRE CWE catalog
551 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-772page 1 of 12
- CVE-2018-0158CRITICALCVSS 8.6EG 9.0⚠ KEV2018-03-28
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a …
- CVE-2024-20481CRITICALCVSS 5.8EG 9.0⚠ KEV2024-10-23
A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (Do…
- CVE-2023-41094CRITICALCVSS 9.8EG 10.02023-10-04
TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing d…
- CVE-2021-21811CRITICALCVSS 9.8EG 9.82021-08-31
A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger t…
- CVE-2020-35876CRITICALCVSS 9.8EG 9.82020-12-31
An issue was discovered in the rio crate through 2020-05-11 for Rust. A struct can be leaked, allowing attackers to obtain sensitive information, cause a use-after-free, or cause a data race.
- CVE-2020-12134CRITICALCVSS 9.8EG 9.82020-04-24
Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.
- CVE-2017-15032CRITICALCVSS 9.8EG 9.82017-10-05
ImageMagick version 7.0.7-2 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
- CVE-2017-14138CRITICALCVSS 9.8EG 9.82017-09-04
ImageMagick 7.0.6-5 has a memory leak vulnerability in ReadWEBPImage in coders/webp.c because memory is not freed in certain error cases, as demonstrated by VP8 errors.
- CVE-2017-11641CRITICALCVSS 9.8EG 9.82017-07-26
GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixel_cache.c during writing of Magick Persistent Cache (MPC) files.
- CVE-2026-39830CRITICALCVSS 9.1EG 9.12026-05-22
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connecti…
- CVE-2017-14495CRITICALCVSS 7.5EG 9.02017-10-03
Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation.
- CVE-2020-14339HIGHCVSS 8.8EG 8.82020-12-03
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malic…
- CVE-2018-19760HIGHCVSS 8.8EG 8.82018-11-30
cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak.
- CVE-2017-13146HIGHCVSS 8.8EG 8.82017-08-23
In ImageMagick before 6.9.8-5 and 7.x before 7.0.5-6, there is a memory leak in the ReadMATImage function in coders/mat.c.
- CVE-2017-12669HIGHCVSS 8.8EG 8.82017-08-07
ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteCALSImage in coders/cals.c.
- CVE-2017-12668HIGHCVSS 8.8EG 8.82017-08-07
ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePCXImage in coders/pcx.c.
- CVE-2017-12667HIGHCVSS 8.8EG 8.82017-08-07
ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadMATImage in coders\mat.c.
- CVE-2017-12666HIGHCVSS 8.8EG 8.82017-08-07
ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteINLINEImage in coders/inline.c.
- CVE-2017-12665HIGHCVSS 8.8EG 8.82017-08-07
ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePICTImage in coders/pict.c.
- CVE-2017-12664HIGHCVSS 8.8EG 8.82017-08-07
ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePALMImage in coders/palm.c.
- CVE-2017-12663HIGHCVSS 8.8EG 8.82017-08-07
ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteMAPImage in coders/map.c.
- CVE-2017-12662HIGHCVSS 8.8EG 8.82017-08-07
ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePDFImage in coders/pdf.c.
- CVE-2017-12644HIGHCVSS 8.8EG 8.82017-08-07
ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadDCMImage in coders\dcm.c.
- CVE-2017-12642HIGHCVSS 8.8EG 8.82017-08-07
ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadMPCImage in coders\mpc.c.
- CVE-2017-12641HIGHCVSS 8.8EG 8.82017-08-07
ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadOneJNGImage in coders\png.c.
- CVE-2017-11310HIGHCVSS 8.8EG 8.82017-07-13
The read_user_chunk_callback function in coders\png.c in ImageMagick 7.0.6-1 Q16 2017-06-21 (beta) has memory leak vulnerabilities via crafted PNG files.
- CVE-2017-11170HIGHCVSS 8.8EG 8.82017-07-11
The ReadTGAImage function in coders\tga.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via invalid colors data in the header of a TGA or VST file.
- CVE-2026-93926HIGHCVSS 8.7EG 8.72026-10-02
Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgra…
- CVE-2026-69664HIGHCVSS 8.7EG 8.72026-09-01
Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hexad…
- CVE-2026-71380HIGHCVSS 8.7EG 8.72026-09-01
Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with a large Content-Length and then stallin…
- CVE-2026-13505HIGHCVSS 8.7EG 8.72026-08-08
In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A DRBGs, SymmetricSecretKey and the PBKD …
- CVE-2025-65947HIGHCVSS 8.7EG 8.72025-11-21
thread-amount is a tool that gets the amount of threads in the current process. Prior to version 0.2.2, there are resource leaks when querying thread counts on Windows and Apple platforms. In Windows platforms, the thread_amount function c…
- CVE-2021-22883HIGHCVSS 7.5EG 8.72021-03-03
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor l…
- CVE-2026-20250HIGHCVSS 8.6EG 8.62026-09-16
A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devic…
- CVE-2026-20082HIGHCVSS 8.6EG 8.62026-03-04
A vulnerability in the handling of the embryonic connection limits in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause incoming TCP SYN packets to be dropped incorrec…
- CVE-2025-30256HIGHCVSS 8.6EG 8.62025-08-20
A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted series of HTTP requests can lead to a reboot. An attacker can send multiple network packets to trigger t…
- CVE-2024-2398HIGHCVSS 8.6EG 8.62024-03-27
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does n…
- CVE-2023-20095HIGHCVSS 8.6EG 8.62023-11-01
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condi…
- CVE-2022-20697HIGHCVSS 8.6EG 8.62022-04-15
A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper resource manage…
- CVE-2021-1523HIGHCVSS 8.6EG 8.62021-08-25
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) Mode could allow an unauthenticated, remote attacker to cause a queue wedge on a leaf switch, which could result in critical control pla…
- CVE-2018-0421HIGHCVSS 8.6EG 8.62018-10-05
A vulnerability in TCP connection management in Cisco Prime Access Registrar could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the application unexpectedly restarts. The vulnerability is due …
- CVE-2017-12245HIGHCVSS 8.6EG 8.62017-10-05
A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause depletion of system memory, aka a Firepower Detection Engine SSL Decryption Memory Consump…
- CVE-2026-35227HIGHCVSS 8.2EG 8.22026-05-12
An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new c…
- CVE-2026-23185HIGHCVSS 7.8EG 7.82026-02-14
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: cancel mlo_scan_start_wk mlo_scan_start_wk is not canceled on disconnection. In fact, it is not canceled anywhere except in the restart cleanup, wher…
- CVE-2021-42197HIGHCVSS 7.8EG 7.82022-06-02
An issue was discovered in swftools through 20201222 through a memory leak in the swftools when swfdump is used. It allows an attacker to cause code execution.
- CVE-2019-18198HIGHCVSS 7.8EG 7.82019-10-18
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to…
- CVE-2017-1000408HIGHCVSS 7.8EG 7.82018-02-01
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.
- CVE-2017-15845HIGHCVSS 7.8EG 7.82018-01-10
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an invalid input of firmware size (negative value) from user space can potentially lead to the memory leak or buffer overflow d…
- CVE-2017-0719HIGHCVSS 7.8EG 7.82017-08-09
A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273673.
- CVE-2010-4683HIGHCVSS v2 7.8EG 7.82011-01-07
Memory leak in Cisco IOS before 15.0(1)XA5 might allow remote attackers to cause a denial of service (memory consumption) by sending a crafted SIP REGISTER message over UDP, aka Bug ID CSCtg41733.
Map vulnerabilities like CWE-772 to your infrastructure
EchelonGraph correlates every CVE — across CWE-772 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →