CVEbaza.plSłownik CWECWE-244
Common Weakness Enumeration

CWE-244

Improper Clearing of Heap Memory Before Release ('Heap Inspection')

Kategoria: VariantCVE: 21
Opis

Użycie funkcji realloc() do zmiany rozmiaru buforów przechowujących wrażliwe informacje może pozostawić te informacje narażone na ataki, ponieważ nie są usuwane z pamięci. Wrażliwe dane mogą być dostępne dla atakujących, którzy uzyskają dostęp do zwolnionej pamięci sterty.

Description (EN)

Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.

Podatności CVE z CWE-244 (21)
8.6
CVSS
HIGH
CVE-2026-20349

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

pub. 2026-08-11🚩 CISA KEV⚡ EXPLOIT
8.6
CVSS
HIGH
CVE-2026-20039

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to ineffective memory management of the VPN web server. An attacker could exploit this vulnerability by sending a large number of crafted HTTP requests to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

pub. 2026-03-04
8.2
CVSS
HIGH
CVE-2025-26304

A memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8.

pub. 2025-02-20
8.2
CVSS
HIGH
CVE-2025-26305

A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.

pub. 2025-02-20
7.5
CVSS
HIGH
CVE-2025-70873

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

pub. 2026-03-12
7.5
CVSS
HIGH
CVE-2025-36118

IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request.

pub. 2025-11-17
6.9
CVSS
MEDIUM
CVE-2026-48025

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, internal/pki/resolver.go:36-64 constructs a CAManager with the plaintext ed25519.PrivateKey after unwrapping via the master key; internal/pki/ca.go:13-16 stores it. Callers at internal/api/enroll.go:116, internal/api/updates.go:297, and internal/api/mobile_bundle.go:40 use the manager for one Sign() and drop the reference on function return — but the underlying slice contents are not wiped before release. The keystore package's contract (internal/keystore/keystore.go doc: "Callers MUST zeroise the returned plaintext DEK as soon as it is no longer needed") is not met by the CAManager consumer. Decrypted CA private keys persist in process heap until Go's GC scavenges the underlying slice — minutes to hours under load, indefinitely on idle servers. This issue has been patched in version 0.3.7.

pub. 2026-07-28
6.9
CVSS
MEDIUM
CVE-2025-5105

A vulnerability was found in TOZED ZLT W51 up to 1.4.2 and classified as critical. Affected by this issue is some unknown functionality of the component Service Port 7777. The manipulation leads to improper clearing of heap memory before release. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

pub. 2025-05-23
6.5
CVSS
MEDIUM
CVE-2025-45663

An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.

pub. 2025-11-03
6.2
CVSS
MEDIUM
CVE-2025-36083

IBM Concert Software 1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release.

pub. 2025-10-28
6.2
CVSS
MEDIUM
CVE-2025-33013

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Container could disclose sensitive information to a local user due to improper clearing of heap memory before release.

pub. 2025-07-24
5.9
CVSS
MEDIUM
CVE-2025-33101

IBM Concert w wersji 1.0.0 do 2.1.0 pozwala atakującemu uzyskać informacje poufne za pomocą technik man in the middle ze względu na niewłaściwe czyszczenie pamięci heap.

pub. 2026-02-17
5.9
CVSS
MEDIUM
CVE-2025-1719

IBM Concert w wersjach od 1.0.0 do 2.1.0 pozwala atakującemu ze zdalnym dostępem uzyskać poufne informacje z przydzielonej pamięci z powodu niewłaściwego czyszczenia heap memory.

pub. 2026-01-20
5.9
CVSS
MEDIUM
CVE-2025-1722

IBM Concert w wersjach od 1.0.0 do 2.1.0 może pozwolić zdalnym atakującym na uzyskanie wrażliwych informacji z przydzielonej pamięci ze względu na nieprawidłowe czyszczenie heap memory.

pub. 2026-01-20
5.9
CVSS
MEDIUM
CVE-2025-1721

IBM Concert w wersjach 1.0.0 do 2.1.0 umożliwia atakującemu z dostępem zdalnym uzyskanie poufnych informacji z przydzielonej pamięci z powodu nieprawidłowego czyszczenia heap memory.

pub. 2025-12-26
5.9
CVSS
MEDIUM
CVE-2025-1759

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

pub. 2025-08-18
5.8
CVSS
MEDIUM
CVE-2022-20922

Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to improper management of system resources when the Snort detection engine is processing SMB2 traffic. An attacker could exploit these vulnerabilities by sending a high rate of certain types of SMB2 packets through an affected device. A successful exploit could allow the attacker to trigger a reload of the Snort process, resulting in a DoS condition. Note: When the snort preserve-connection option is enabled for the Snort detection engine, a successful exploit could also allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network. The snort preserve-connection setting is enabled by default. See the Details ["#details"] section of this advisory for more information. Note: Only products that have Snort 3 configured are affected. Products that are configured with Snort 2 are not affected.

pub. 2022-11-15
5.8
CVSS
MEDIUM
CVE-2022-20943

Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to improper management of system resources when the Snort detection engine is processing SMB2 traffic. An attacker could exploit these vulnerabilities by sending a high rate of certain types of SMB2 packets through an affected device. A successful exploit could allow the attacker to trigger a reload of the Snort process, resulting in a DoS condition. Note: When the snort preserve-connection option is enabled for the Snort detection engine, a successful exploit could also allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network. The snort preserve-connection setting is enabled by default. See the Details ["#details"] section of this advisory for more information. Note: Only products that have Snort 3 configured are affected. Products that are configured with Snort 2 are not affected.

pub. 2022-11-15
4.0
CVSS
MEDIUM
CVE-2023-20031

A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart. This vulnerability is due to a logic error that occurs when an SSL/TLS certificate that is under load is accessed when it is initiating an SSL connection. Under specific, time-based constraints, an attacker could exploit this vulnerability by sending a high rate of SSL/TLS connection requests to be inspected by the Snort 3 detection engine on an affected device. A successful exploit could allow the attacker to cause the Snort 3 detection engine to reload, resulting in either a bypass or a denial of service (DoS) condition, depending on device configuration. The Snort detection engine will restart automatically. No manual intervention is required.

pub. 2023-11-01
4.0
CVSS
MEDIUM
CVE-2023-20070

A vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart. This vulnerability is due to a logic error in how memory allocations are handled during a TLS 1.3 session. Under specific, time-based constraints, an attacker could exploit this vulnerability by sending a crafted TLS 1.3 message sequence through an affected device. A successful exploit could allow the attacker to cause the Snort 3 detection engine to reload, resulting in a denial of service (DoS) condition. While the Snort detection engine reloads, packets going through the FTD device that are sent to the Snort detection engine will be dropped. The Snort detection engine will restart automatically. No manual intervention is required.

pub. 2023-11-01
Pokazano 20 z 21 podatności
Informacje
ID: CWE-244
Typ: Variant
Podatności: 21
MITRE CWE ↗
← Słownik CWE