Vulnerabilities > Missing Release of Resource after Effective Lifetime

DATE CVE VULNERABILITY TITLE RISK
2019-10-18 CVE-2019-18198 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
local
low complexity
linux canonical CWE-772
7.8
2019-10-16 CVE-2019-6474 Missing Release of Resource after Effective Lifetime vulnerability in ISC KEA 1.4.0/1.5.0/1.6.0
A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are rejected as invalid when the server tries to load leases from storage on restart.
low complexity
isc CWE-772
6.5
2019-10-11 CVE-2018-21028 Missing Release of Resource after Effective Lifetime vulnerability in BOA
Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.
network
low complexity
boa CWE-772
7.5
2019-10-09 CVE-2018-5744 Missing Release of Resource after Effective Lifetime vulnerability in ISC Bind
A failure to free memory can occur when processing messages having a specific combination of EDNS options.
network
low complexity
isc CWE-772
7.5
2019-10-04 CVE-2019-17183 Missing Release of Resource after Effective Lifetime vulnerability in Foxitsoftware Reader
Foxit Reader before 9.7 allows an Access Violation and crash if insufficient memory exists.
network
low complexity
foxitsoftware CWE-772
7.5
2019-08-28 CVE-2019-1965 Missing Release of Resource after Effective Lifetime vulnerability in Cisco Nx-Os
A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, remote attacker to cause a VSH process to fail to delete upon termination.
network
low complexity
cisco CWE-772
7.7
2019-04-26 CVE-2018-5179 Missing Release of Resource after Effective Lifetime vulnerability in Mozilla Firefox
A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users.
network
low complexity
mozilla CWE-772
7.5
2019-04-17 CVE-2019-3883 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads.
network
low complexity
fedoraproject debian redhat CWE-772
7.5
2019-03-27 CVE-2019-3821 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled.
network
low complexity
ceph canonical CWE-772
7.5
2019-03-21 CVE-2017-16232 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c.
network
low complexity
libtiff opensuse suse CWE-772
7.5