Vulnerabilities > Missing Release of Resource after Effective Lifetime

DATE CVE VULNERABILITY TITLE RISK
2017-03-15 CVE-2017-6414 Missing Release of Resource after Effective Lifetime vulnerability in Libcacard Project Libcacard 2.5.0/2.5.1/2.5.2
Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object.
local
low complexity
libcacard libcacard-project CWE-772
4.9
2017-03-15 CVE-2017-6386 Missing Release of Resource after Effective Lifetime vulnerability in Virglrenderer Project Virglrenderer
Memory leak in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_OBJECT_VERTEX_ELEMENTS commands.
local
low complexity
virglrenderer-project CWE-772
4.9
2017-03-15 CVE-2017-6317 Missing Release of Resource after Effective Lifetime vulnerability in Virglrenderer Project Virglrenderer 0.2.0/0.4.0/0.5.0
Memory leak in the add_shader_program function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via vectors involving the sprog variable.
local
low complexity
virglrenderer-project CWE-772
4.9
2017-03-15 CVE-2017-5993 Missing Release of Resource after Effective Lifetime vulnerability in Virglrenderer Project Virglrenderer 0.2.0/0.4.0/0.5.0
Memory leak in the vrend_renderer_init_blit_ctx function in vrend_blitter.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_CCMD_BLIT commands.
local
low complexity
virglrenderer-project CWE-772
4.9
2017-03-06 CVE-2017-6499 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
An issue was discovered in Magick++ in ImageMagick 6.9.7.
4.3
2017-03-02 CVE-2017-6384 Missing Release of Resource after Effective Lifetime vulnerability in Atheme 7.2.7
Memory leak in the login_user function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to consume memory and cause a denial of service.
network
low complexity
atheme CWE-772
7.8
2017-02-15 CVE-2017-5997 Missing Release of Resource after Effective Lifetime vulnerability in SAP Kernel 7.21/7.22/7.42
The SAP Message Server HTTP daemon in SAP KERNEL 7.21-7.49 allows remote attackers to cause a denial of service (memory consumption and process crash) via multiple msgserver/group?group= requests with a crafted size of the group parameter, aka SAP Security Note 2358972.
network
low complexity
sap CWE-772
5.0
2017-02-06 CVE-2017-2596 Missing Release of Resource after Effective Lifetime vulnerability in Linux Kernel
The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXON instruction, which allows KVM L1 guest OS users to cause a denial of service (host OS memory consumption) by leveraging the mishandling of page references.
local
low complexity
linux CWE-772
6.5
2017-02-03 CVE-2017-3812 Missing Release of Resource after Effective Lifetime vulnerability in Cisco Industrial Ethernet 2000 Series Firmware
A vulnerability in the implementation of Common Industrial Protocol (CIP) functionality in Cisco Industrial Ethernet 2000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to a system memory leak.
network
cisco CWE-772
7.1
2017-01-26 CVE-2017-3803 Missing Release of Resource after Effective Lifetime vulnerability in Cisco IOS 15.2(2)E3/15.2(4)E1
A vulnerability in the Cisco IOS Software forwarding queue of Cisco 2960X and 3750X switches could allow an unauthenticated, adjacent attacker to cause a memory leak in the software forwarding queue that would eventually lead to a partial denial of service (DoS) condition.
low complexity
cisco CWE-772
3.3