Vulnerabilities > Missing Release of Resource after Effective Lifetime

DATE CVE VULNERABILITY TITLE RISK
2018-09-11 CVE-2018-16807 Missing Release of Resource after Effective Lifetime vulnerability in BRO
In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Kerberos protocol parser.
network
low complexity
bro CWE-772
7.5
2018-09-09 CVE-2018-16750 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In ImageMagick 7.0.7-29 and earlier, a memory leak in the formatIPTCfromBuffer function in coders/meta.c was found.
network
low complexity
imagemagick canonical CWE-772
6.5
2018-09-06 CVE-2018-16641 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.86
ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c.
network
low complexity
imagemagick CWE-772
6.5
2018-09-06 CVE-2018-16640 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
ImageMagick 7.0.8-5 has a memory leak vulnerability in the function ReadOneJNGImage in coders/png.c.
network
low complexity
imagemagick canonical CWE-772
6.5
2018-09-05 CVE-2018-16548 Missing Release of Resource after Effective Lifetime vulnerability in Zziplib Project Zziplib
An issue was discovered in ZZIPlib through 0.13.69.
network
low complexity
zziplib-project CWE-772
6.5
2018-09-04 CVE-2018-6554 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (memory consumption) by repeatedly binding an AF_IRDA socket.
local
low complexity
linux debian canonical CWE-772
5.5
2018-09-04 CVE-2018-10924 Missing Release of Resource after Effective Lifetime vulnerability in Gluster Glusterfs
It was discovered that fsync(2) system call in glusterfs client code leaks memory.
network
low complexity
gluster CWE-772
6.5
2018-08-23 CVE-2018-1999043 Missing Release of Resource after Effective Lifetime vulnerability in Jenkins
A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows attackers to create ephemeral in-memory user records by attempting to log in using invalid credentials.
network
low complexity
jenkins CWE-772
7.5
2018-08-20 CVE-2018-1000215 Missing Release of Resource after Effective Lifetime vulnerability in Cjson Project Cjson
Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS).
network
low complexity
cjson-project CWE-772
7.5
2018-07-31 CVE-2018-7994 Missing Release of Resource after Effective Lifetime vulnerability in Huawei products
Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability.
network
low complexity
huawei CWE-772
7.5