CWE-772— Missing Release of Resource after Effective Lifetime
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.— MITRE CWE catalog
551 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-772page 8 of 12
- CVE-2017-9404MEDIUMCVSS 6.5EG 6.52017-06-02
In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.
- CVE-2017-9403MEDIUMCVSS 6.5EG 6.52017-06-02
In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file.
- CVE-2017-9262MEDIUMCVSS 6.5EG 6.52017-05-29
In ImageMagick 7.0.5-6 Q16, the ReadJNGImage function in coders/png.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-9261MEDIUMCVSS 6.5EG 6.52017-05-29
In ImageMagick 7.0.5-6 Q16, the ReadMNGImage function in coders/png.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8379MEDIUMCVSS 6.5EG 6.52017-05-23
Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.
- CVE-2017-9143MEDIUMCVSS 6.5EG 6.52017-05-22
In ImageMagick 7.0.5-5, the ReadARTImage function in coders/art.c allows attackers to cause a denial of service (memory leak) via a crafted .art file.
- CVE-2017-8830MEDIUMCVSS 6.5EG 6.52017-05-08
In ImageMagick 7.0.5-6, the ReadBMPImage function in bmp.c:1379 allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8765MEDIUMCVSS 6.5EG 6.52017-05-04
The function named ReadICONImage in coders\icon.c in ImageMagick 7.0.5-5 has a memory leak vulnerability which can cause memory exhaustion via a crafted ICON file.
- CVE-2017-8086MEDIUMCVSS 6.5EG 6.52017-05-02
Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (memory consumption) via vectors involving the orig_value variable.
- CVE-2017-8357MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadEPTImage function in ept.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8356MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadSUNImage function in sun.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8355MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadMTVImage function in mtv.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8354MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadBMPImage function in bmp.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8353MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadPICTImage function in pict.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8352MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadXWDImage function in xwd.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8351MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadPCDImage function in pcd.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8350MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadJNGImage function in png.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8349MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadSFWImage function in sfw.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8348MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadMATImage function in mat.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8347MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadEXRImage function in exr.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8346MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadDCMImage function in dcm.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8345MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadMNGImage function in png.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8344MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadPCXImage function in pcx.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-8343MEDIUMCVSS 6.5EG 6.52017-04-30
In ImageMagick 7.0.5-5, the ReadAAIImage function in aai.c allows attackers to cause a denial of service (memory leak) via a crafted file.
- CVE-2017-2312MEDIUMCVSS 6.5EG 6.52017-04-24
On Juniper Networks devices running Junos OS affected versions and with LDP enabled, a specific LDP packet destined to the RE (Routing Engine) will consume a small amount of the memory allocated for the rpd (routing protocol daemon) proces…
- CVE-2017-7943MEDIUMCVSS 6.5EG 6.52017-04-18
The ReadSVGImage function in svg.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.
- CVE-2017-7942MEDIUMCVSS 6.5EG 6.52017-04-18
The ReadAVSImage function in avs.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.
- CVE-2017-7941MEDIUMCVSS 6.5EG 6.52017-04-18
The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.
- CVE-2015-8568MEDIUMCVSS 6.5EG 6.52017-04-11
Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device repeatedly.
- CVE-2017-6414MEDIUMCVSS 6.5EG 6.52017-03-15
Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object.
- CVE-2017-6386MEDIUMCVSS 6.5EG 6.52017-03-15
Memory leak in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_OBJECT_VERTEX_ELEMENTS comma…
- CVE-2017-6317MEDIUMCVSS 6.5EG 6.52017-03-15
Memory leak in the add_shader_program function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via vectors involving the sprog variable.
- CVE-2017-5993MEDIUMCVSS 6.5EG 6.52017-03-15
Memory leak in the vrend_renderer_init_blit_ctx function in vrend_blitter.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_CCMD_BLIT commands.
- CVE-2017-2596MEDIUMCVSS 6.5EG 6.52017-02-06
The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXON instruction, which allows KVM L1 guest OS users to cause a denial of service (host OS memory consumption) by leveragi…
- CVE-2016-9912MEDIUMCVSS 6.5EG 6.52016-12-23
Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while destroying gpu resource object in 'virtio_gpu_resource_destroy'. A guest user/process could use this flaw…
- CVE-2016-9911MEDIUMCVSS 6.5EG 6.52016-12-23
Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, re…
- CVE-2016-9907MEDIUMCVSS 6.5EG 6.52016-12-23
Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to lea…
- CVE-2015-8631MEDIUMCVSS 6.5EG 6.52016-02-13
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifyin…
- CVE-2019-6474MEDIUMCVSS 5.7EG 6.52019-10-16
A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are rejected as invalid when the server tries to load leases from storage on restart. If the numbe…
- CVE-2018-10924MEDIUMCVSS 5.3EG 6.52018-09-04
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.
- CVE-2017-12278MEDIUMCVSS 6.3EG 6.32017-11-02
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Wireless LAN Controllers could allow an authenticated, remote attacker to cause an affected device to restart, resulting in a denial of service (DoS) condi…
- CVE-2024-22383MEDIUMCVSS 6.2EG 6.22024-03-05
Missing release of resource after effective lifetime (CWE-772) in the Controller 7000 resulted in HBUS connected T-Series readers to not automatically recover after coming under attack over the RS-485 interface, resulting in a persistent …
- CVE-2021-30002MEDIUMCVSS 6.2EG 6.22021-04-02
An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments, aka CID-fb18802a338b.
- CVE-2017-7377MEDIUMCVSS 6.0EG 6.02017-04-10
The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in…
- CVE-2016-7995MEDIUMCVSS 6.0EG 6.02016-12-10
Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG) ind…
- CVE-2016-7994MEDIUMCVSS 6.0EG 6.02016-12-10
Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of VIRTIO_GPU_CMD_R…
- CVE-2016-7466MEDIUMCVSS 6.0EG 6.02016-12-10
Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by…
- CVE-2016-9106MEDIUMCVSS 6.0EG 6.02016-12-09
Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) by leveraging failure to free an IO vector.
- CVE-2016-9105MEDIUMCVSS 6.0EG 6.02016-12-09
Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors involving a reference to the source fid object.
- CVE-2016-9102MEDIUMCVSS 6.0EG 6.02016-12-09
Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) via a large number of Txattrcreate mess…
Map vulnerabilities like CWE-772 to your infrastructure
EchelonGraph correlates every CVE — across CWE-772 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →