CWE-401— Missing Release of Memory after Effective Lifetime (Memory Leak)
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.— MITRE CWE catalog
1,959 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-401page 11 of 40
- CVE-2019-20023MEDIUMCVSS 6.5EG 6.52019-12-27
A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.
- CVE-2019-19046MEDIUMCVSS 6.5EG 6.52019-11-18
A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering ida_simple_get() failure, aka CI…
- CVE-2019-5293MEDIUMCVSS 6.5EG 6.52019-11-13
Some Huawei products have a memory leak vulnerability when handling some messages. A remote attacker with operation privilege could exploit the vulnerability by sending specific messages continuously. Successful exploit may cause some serv…
- CVE-2019-17371MEDIUMCVSS 6.5EG 6.52019-10-09
gif2png 2.5.13 has a memory leak in the writefile function.
- CVE-2019-4141MEDIUMCVSS 6.5EG 6.52019-09-27
IBM MQ 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.9, 8.0.0.0 - 8.0.0.11, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.1 - 9.1.2 is vulnerable to a denial of service attack caused by a memory leak in the clustering code. IBM X-Force ID: 158337.
- CVE-2019-16713MEDIUMCVSS 6.5EG 6.52019-09-23
ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c.
- CVE-2019-16712MEDIUMCVSS 6.5EG 6.52019-09-23
ImageMagick 7.0.8-43 has a memory leak in Huffman2DEncodeImage in coders/ps3.c, as demonstrated by WritePS3Image.
- CVE-2019-16711MEDIUMCVSS 6.5EG 6.52019-09-23
ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.
- CVE-2019-16710MEDIUMCVSS 6.5EG 6.52019-09-23
ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.
- CVE-2019-16709MEDIUMCVSS 6.5EG 6.52019-09-23
ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.
- CVE-2019-16708MEDIUMCVSS 6.5EG 6.52019-09-23
ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.
- CVE-2018-21017MEDIUMCVSS 6.5EG 6.52019-09-16
GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c.
- CVE-2019-13311MEDIUMCVSS 6.5EG 6.52019-07-05
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.
- CVE-2019-13310MEDIUMCVSS 6.5EG 6.52019-07-05
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.
- CVE-2019-13309MEDIUMCVSS 6.5EG 6.52019-07-05
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchImage error in CLIListOperatorImages in MagickWand/operation.c.
- CVE-2019-13301MEDIUMCVSS 6.5EG 6.52019-07-05
ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error.
- CVE-2019-13296MEDIUMCVSS 6.5EG 6.52019-07-05
ImageMagick 7.0.8-50 Q16 has direct memory leaks in AcquireMagickMemory because of an error in CLIListOperatorImages in MagickWand/operation.c for a NULL value.
- CVE-2019-13137MEDIUMCVSS 6.5EG 6.52019-07-01
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps.c.
- CVE-2019-11010MEDIUMCVSS 6.5EG 6.52019-04-08
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.
- CVE-2019-6459MEDIUMCVSS 6.5EG 6.52019-01-16
An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_extract_type in rec-utils.c in librec.a.
- CVE-2019-6458MEDIUMCVSS 6.5EG 6.52019-01-16
An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_buf_new in rec-buf.c when called from rec_parse_rset in rec-parser.c in librec.a.
- CVE-2019-6457MEDIUMCVSS 6.5EG 6.52019-01-16
An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_aggregate_reg_new in rec-aggregate.c in librec.a.
- CVE-2019-6129MEDIUMCVSS 6.5EG 6.52019-01-11
png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.
- CVE-2017-5857MEDIUMCVSS 6.5EG 6.52017-03-16
Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURC…
- CVE-2017-5856MEDIUMCVSS 6.5EG 6.52017-03-16
Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands …
- CVE-2017-5579MEDIUMCVSS 6.5EG 6.52017-03-15
Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device…
- CVE-2017-5578MEDIUMCVSS 6.5EG 6.52017-03-15
Memory leak in the virtio_gpu_resource_attach_backing function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_…
- CVE-2017-5552MEDIUMCVSS 6.5EG 6.52017-03-15
Memory leak in the virgl_resource_attach_backing function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RE…
- CVE-2017-5526MEDIUMCVSS 6.5EG 6.52017-03-15
Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
- CVE-2017-5525MEDIUMCVSS 6.5EG 6.52017-03-15
Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
- CVE-2016-9916MEDIUMCVSS 6.5EG 6.52016-12-29
Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the p…
- CVE-2016-9915MEDIUMCVSS 6.5EG 6.52016-12-29
Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the …
- CVE-2016-9914MEDIUMCVSS 6.5EG 6.52016-12-29
Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperati…
- CVE-2016-9913MEDIUMCVSS 6.5EG 6.52016-12-29
Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) via vectors…
- CVE-2010-2249MEDIUMCVSS 6.5EG 6.52010-06-30
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunk…
- CVE-2019-10649MEDIUMCVSS 5.5EG 6.52019-03-30
In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a denial of service via a crafted image file.
- CVE-2023-44183MEDIUMCVSS 5.3EG 6.52023-10-13
An Improper Input Validation vulnerability in the VxLAN packet forwarding engine (PFE) of Juniper Networks Junos OS on QFX5000 Series, EX4600 Series devices allows an unauthenticated, adjacent attacker, sending two or more genuine packets…
- CVE-2022-23159MEDIUMCVSS 4.8EG 6.52022-04-12
Dell PowerScale OneFS, 8.2.2 - 9.3.0.x, contain a missing release of memory after effective lifetime vulnerability. An authenticated user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE and ISI_PRIV_AUTH_PROVIDERS privileges could ex…
- CVE-2022-3957MEDIUMCVSS 4.3EG 6.52022-11-11
A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory…
- CVE-2022-3812MEDIUMCVSS 4.3EG 6.52022-11-01
A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is the function AP4_ContainerAtom::AP4_ContainerAtom of the component mp4encrypt. The manipulation leads to memory leak. The attack may…
- CVE-2021-45346MEDIUMCVSS 4.3EG 6.52022-02-14
A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyo…
- CVE-2024-35853MEDIUMCVSS 6.4EG 6.42024-05-17
In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix memory leak during rehash The rehash delayed work migrates filters from one region to another. This is done by iterating over all chunks (a…
- CVE-2026-94652MEDIUMCVSS 6.3EG 6.32026-10-02
Missing release of memory after effective lifetime vulnerability in Apache Thrift c++ bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
- CVE-2026-13148MEDIUMCVSS 6.3EG 6.32026-09-04
Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure. This issue affects smartLink HW-PN: from 1.04 before 1.10.
- CVE-2026-20746MEDIUMCVSS 6.3EG 6.32026-06-12
Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name v…
- CVE-2023-52581MEDIUMCVSS 6.3EG 6.32024-03-02
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix memleak when more than 255 elements expired When more than 255 elements expired we're supposed to switch to a new gc container structure. This…
- CVE-2026-1757MEDIUMCVSS 6.2EG 6.22026-02-02
A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of white…
- CVE-2024-39490MEDIUMCVSS 6.2EG 6.22024-07-10
In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix missing sk_buff release in seg6_input_core The seg6_input() function is responsible for adding the SRH into a packet, delegating the operation to the seg6_…
- CVE-2024-3860MEDIUMCVSS 6.2EG 6.22024-04-16
An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash. This vulnerability affects Firefox < 125.
- CVE-2021-47147MEDIUMCVSS 6.2EG 6.22024-03-25
In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Fix a resource leak in an error handling path If an error occurs after a successful 'pci_ioremap_bar()' call, it must be undone by a corresponding 'pci_iounmap…
Map vulnerabilities like CWE-401 to your infrastructure
EchelonGraph correlates every CVE — across CWE-401 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →