Skip to main content

CWE archive

CWE-401 CVEs

Programmatic archive

1,849 CVEs tagged with CWE-4012 Critical, 331 High, 1,445 Medium, 71 Low, 0 Unrated.

CVE-2020-36312

Published Apr 7, 2021

An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory leak upon a kmalloc failure, aka CID-f65886606c2d.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30141

Published Apr 5, 2021

Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as demonstrated by an attempted access to an array offset on…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-30002

Published Apr 2, 2021

An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20234

Published Apr 1, 2021

An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp. This issue causes a client that connects to multip…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29649

Published Mar 30, 2021

An issue was discovered in the Linux kernel before 5.11.11. The user mode driver (UMD) has a copy_process() memory leak, related to a lack of cleanup steps in kernel/usermode_driv…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20193

Published Mar 26, 2021

A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. Th…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-20216

Published Mar 25, 2021

A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from thi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20215

Published Mar 25, 2021

A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20214

Published Mar 25, 2021

A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail can lead to a system…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20212

Published Mar 25, 2021

A flaw was found in Privoxy in versions before 3.0.29. Memory leak if multiple filters are executed and the last one is skipped due to a pcre error leading to a system crash.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20211

Published Mar 25, 2021

A flaw was found in Privoxy in versions before 3.0.29. Memory leak when client tags are active can cause a system crash.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20210

Published Mar 25, 2021

A flaw was found in Privoxy in versions before 3.0.29. Memory leak in the show-status CGI handler when no filter files are configured can lead to a system crash.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35502

Published Mar 25, 2021

A flaw was found in Privoxy in versions before 3.0.29. Memory leaks when a response is buffered and the buffer limit is reached or Privoxy is running out of memory can lead to a s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21724

Published Feb 26, 2021

A ZTE product has a memory leak vulnerability. Due to the product's improper handling of memory release in certain scenarios, a local attacker with device permissions repeatedly a…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25340

Published Feb 16, 2021

An issue was discovered in NFStream 5.2.0. Because some allocated modules are not correctly freed, if the nfstream object is directly destroyed without being used after it is crea…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1313

Published Feb 4, 2021

Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) cond…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort
Showing 1,576-1,600 of 1,849 CVEsPage 64 of 74