CWE-401— Missing Release of Memory after Effective Lifetime (Memory Leak)
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.— MITRE CWE catalog
1,960 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-401page 34 of 40
- CVE-2023-48958MEDIUMCVSS 5.5EG 5.52023-12-07
gpac 2.3-DEV-rev617-g671976fcc-master contains memory leaks in gf_mpd_resolve_url media_tools/mpd.c:4589.
- CVE-2023-48039MEDIUMCVSS 5.5EG 5.52023-11-20
GPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leak in gf_mpd_parse_string media_tools/mpd.c:75.
- CVE-2023-47384MEDIUMCVSS 5.5EG 5.52023-11-14
MP4Box GPAC v2.3-DEV-rev617-g671976fcc-master was discovered to contain a memory leak in the function gf_isom_add_chapter at /isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 f…
- CVE-2023-44193MEDIUMCVSS 5.5EG 5.52023-10-13
An Improper Release of Memory Before Removing Last Reference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a local, low privileged attacker to cause an FPC crash, leading to Denial of Service (DoS). …
- CVE-2023-45511MEDIUMCVSS 5.5EG 5.52023-10-12
A memory leak in tsMuxer version git-2539d07 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
- CVE-2023-44821MEDIUMCVSS 5.5EG 5.52023-10-09
Gifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service (memory consumption). NOTE: this has been disputed by multiple parties because the Gifsicle code is not co…
- CVE-2023-3576MEDIUMCVSS 5.5EG 5.52023-10-04
A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, res…
- CVE-2023-4569MEDIUMCVSS 5.5EG 5.52023-08-28
A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.
- CVE-2022-48065MEDIUMCVSS 5.5EG 5.52023-08-22
GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c.
- CVE-2022-47011MEDIUMCVSS 5.5EG 5.52023-08-22
An issue was discovered function parse_stab_struct_fields in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
- CVE-2022-47010MEDIUMCVSS 5.5EG 5.52023-08-22
An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
- CVE-2022-47008MEDIUMCVSS 5.5EG 5.52023-08-22
An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
- CVE-2022-47007MEDIUMCVSS 5.5EG 5.52023-08-22
An issue was discovered function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
- CVE-2020-26683MEDIUMCVSS 5.5EG 5.52023-08-22
A memory leak issue discovered in /pdf/pdf-font-add.c in Artifex Software MuPDF 1.17.0 allows attackers to obtain sensitive information.
- CVE-2020-21490MEDIUMCVSS 5.5EG 5.52023-08-22
An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled.
- CVE-2020-19724MEDIUMCVSS 5.5EG 5.52023-08-22
A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command.
- CVE-2023-25399MEDIUMCVSS 5.5EG 5.52023-07-05
A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function. Note: This is disputed as a bug and not a vulnerability. SciPy is not designed to be exposed to untrusted user…
- CVE-2023-33717MEDIUMCVSS 5.5EG 5.52023-06-02
mp4v2 v2.1.3 was discovered to contain a memory leak when a method calling MP4File::ReadBytes() had allocated memory but did not catch exceptions thrown by ReadBytes()
- CVE-2023-33719MEDIUMCVSS 5.5EG 5.52023-06-01
mp4v2 v2.1.3 was discovered to contain a memory leak via MP4SdpAtom::Read() at atom_sdp.cpp
- CVE-2023-33716MEDIUMCVSS 5.5EG 5.52023-06-01
mp4v2 v2.1.3 was discovered to contain a memory leak via the class MP4StringProperty at mp4property.cpp.
- CVE-2023-2700MEDIUMCVSS 5.5EG 5.52023-05-15
A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct…
- CVE-2023-31973MEDIUMCVSS 5.5EG 5.52023-05-09
yasm v1.3.0 was discovered to contain a use after free via the function expand_mmac_params at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy.
- CVE-2023-1074MEDIUMCVSS 5.5EG 5.52023-03-27
A memory leak flaw was found in the Linux kernel's Stream Control Transmission Protocol. This issue may occur when a user starts a malicious networking service and someone connects to this service. This could allow a local user to starve r…
- CVE-2023-23205MEDIUMCVSS 5.5EG 5.52023-02-24
An issue was discovered in lib60870 v2.3.2. There is a memory leak in lib60870/lib60870-C/examples/multi_client_server/multi_client_server.c.
- CVE-2023-0597MEDIUMCVSS 5.5EG 5.52023-02-23
A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location of exception stack(s) or other important data. A local user could use this flaw to get acce…
- CVE-2023-0615MEDIUMCVSS 5.5EG 5.52023-02-06
A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test code functionality. This issue occurs when a user triggers ioctls, such as VIDIOC_S_DV_TIMINGS ioctl. This could allow a…
- CVE-2022-46490MEDIUMCVSS 5.5EG 5.52023-01-05
GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the afrt_box_read function at box_code_adobe.c.
- CVE-2022-46489MEDIUMCVSS 5.5EG 5.52023-01-05
GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the gf_isom_box_parse_ex function at box_funcs.c.
- CVE-2022-45204MEDIUMCVSS 5.5EG 5.52022-11-29
GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a memory leak via the function dimC_box_read at isomedia/box_code_3gpp.c.
- CVE-2021-26393MEDIUMCVSS 5.5EG 5.52022-11-09
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory w…
- CVE-2022-43255MEDIUMCVSS 5.5EG 5.52022-11-02
GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_odf_new_iod at odf/odf_code.c.
- CVE-2022-43254MEDIUMCVSS 5.5EG 5.52022-11-02
GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_list_new at utils/list.c.
- CVE-2022-42326MEDIUMCVSS 5.5EG 5.52022-11-01
Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a tr…
- CVE-2022-42325MEDIUMCVSS 5.5EG 5.52022-11-01
Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a tr…
- CVE-2022-42323MEDIUMCVSS 5.5EG 5.52022-11-01
Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node …
- CVE-2022-42322MEDIUMCVSS 5.5EG 5.52022-11-01
Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node …
- CVE-2022-43151MEDIUMCVSS 5.5EG 5.52022-10-31
timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-query.cc.
- CVE-2022-40884MEDIUMCVSS 5.5EG 5.52022-10-19
Bento4 1.6.0 has memory leaks via the mp4fragment.
- CVE-2022-22240MEDIUMCVSS 5.5EG 5.52022-10-18
An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenti…
- CVE-2022-41847MEDIUMCVSS 5.5EG 5.52022-09-30
An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp.
- CVE-2022-35085MEDIUMCVSS 5.5EG 5.52022-09-21
SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.
- CVE-2022-38600MEDIUMCVSS 5.5EG 5.52022-09-15
Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vf_vo.c.
- CVE-2021-3764MEDIUMCVSS 5.5EG 5.52022-08-23
A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The vulnerability is similar to the older CVE-2019-18808. The highest threat from this vulnerability is…
- CVE-2021-3736MEDIUMCVSS 5.5EG 5.52022-08-23
A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O (VFIO) Mediated devices. This flaw could allow a local attacker to leak internal kernel information.
- CVE-2022-36152MEDIUMCVSS 5.5EG 5.52022-08-16
tifig v0.2.2 was discovered to contain a memory leak via operator new[](unsigned long) at /asan/asan_new_delete.cpp.
- CVE-2022-35110MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.
- CVE-2021-33452MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c.
- CVE-2021-33451MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.
- CVE-2021-33450MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c.
- CVE-2021-33437MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in mjs.c.
Map vulnerabilities like CWE-401 to your infrastructure
EchelonGraph correlates every CVE — across CWE-401 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →