CWE-401— Missing Release of Memory after Effective Lifetime (Memory Leak)
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.— MITRE CWE catalog
1,959 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-401page 5 of 40
- CVE-2022-43272HIGHCVSS 7.5EG 7.52022-12-02
DCMTK v3.6.7 was discovered to contain a memory leak via the T_ASC_Association object.
- CVE-2021-46854HIGHCVSS 7.5EG 7.52022-11-23
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
- CVE-2022-43223HIGHCVSS 7.5EG 7.52022-11-01
open5gs v2.4.11 was discovered to contain a memory leak in the component ngap-handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted UE attachment.
- CVE-2022-43222HIGHCVSS 7.5EG 7.52022-11-01
open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.
- CVE-2022-43221HIGHCVSS 7.5EG 7.52022-11-01
open5gs v2.4.11 was discovered to contain a memory leak in the component src/upf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.
- CVE-2022-41832HIGHCVSS 7.5EG 7.52022-10-19
In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when a SIP profile is configured on a virtual server, undisclosed messages can cause an increase…
- CVE-2022-41624HIGHCVSS 7.5EG 7.52022-10-19
In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.2, 15.1.x before 15.1.7, 14.1.x before 14.1.5.2, and 13.1.x before 13.1.5.1, when a sideband iRule is configured on a virtual server, undisclosed traffic can cause an increase…
- CVE-2022-2963HIGHCVSS 7.5EG 7.52022-10-14
A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
- CVE-2022-38371HIGHCVSS 7.5EG 7.52022-10-11
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BA…
- CVE-2022-41556HIGHCVSS 7.5EG 7.52022-10-06
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/…
- CVE-2022-38178HIGHCVSS 7.5EG 7.52022-09-21
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
- CVE-2022-38177HIGHCVSS 7.5EG 7.52022-09-21
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
- CVE-2022-2906HIGHCVSS 7.5EG 7.52022-09-21
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.
- CVE-2022-39005HIGHCVSS 7.5EG 7.52022-09-16
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
- CVE-2022-39004HIGHCVSS 7.5EG 7.52022-09-16
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
- CVE-2022-40281HIGHCVSS 7.5EG 7.52022-09-08
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.
- CVE-2021-42523HIGHCVSS 7.5EG 7.52022-08-25
There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use, while libxm…
- CVE-2021-42522HIGHCVSS 7.5EG 7.52022-08-25
There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was caused by the incorrect use of libxml2 API. The vendor forgot to call 'g_free()' to release the return value of 'xmlGetPr…
- CVE-2021-4213HIGHCVSS 7.5EG 7.52022-08-24
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory pro…
- CVE-2021-3905HIGHCVSS 7.5EG 7.52022-08-23
A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.
- CVE-2021-3690HIGHCVSS 7.5EG 7.52022-08-23
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
- CVE-2021-33646HIGHCVSS 7.5EG 7.52022-08-10
The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.
- CVE-2021-33645HIGHCVSS 7.5EG 7.52022-08-10
The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.
- CVE-2022-34568HIGHCVSS 7.5EG 7.52022-07-28
SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c.
- CVE-2022-22209HIGHCVSS 7.5EG 7.52022-07-20
A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a Denial of Service (DoS). On all Junos platforms, the Kernel Routing T…
- CVE-2022-22205HIGHCVSS 7.5EG 7.52022-07-20
A Missing Release of Memory after Effective Lifetime vulnerability in the Application Quality of Experience (appqoe) subsystem of the PFE of Juniper Networks Junos OS on SRX Series allows an unauthenticated network based attacker to cause …
- CVE-2021-41690HIGHCVSS 7.5EG 7.52022-06-28
DCMTK through 3.6.6 does not handle memory free properly. The malloced memory for storing all file information are recorded in a global variable LST and are not freed properly. Sending specific requests to the dcmqrdb program can incur a m…
- CVE-2021-41687HIGHCVSS 7.5EG 7.52022-06-28
DCMTK through 3.6.6 does not handle memory free properly. The program malloc a heap memory for parsing data, but does not free it when error in parsing. Sending specific requests to the dcmqrdb program incur the memory leak. An attacker ca…
- CVE-2022-33105HIGHCVSS 7.5EG 7.52022-06-23
Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.
- CVE-2021-41490HIGHCVSS 7.5EG 7.52022-06-17
Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior.
- CVE-2021-35078HIGHCVSS 7.5EG 7.52022-06-14
Possible memory leak due to improper validation of certificate chain length while parsing server certificate chain in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdra…
- CVE-2018-17240HIGHCVSS 7.5EG 7.52022-06-10
There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password).
- CVE-2022-29693HIGHCVSS 7.5EG 7.52022-06-02
Unicorn Engine v2.0.0-rc7 and below was discovered to contain a memory leak via the function uc_close at /my/unicorn/uc.c.
- CVE-2022-29932HIGHCVSS 7.5EG 7.52022-05-11
The HTTP Server in PRIMEUR SPAZIO 2.5.1.954 (File Transfer) allows an unauthenticated attacker to obtain sensitive data (related to the content of transferred files) via a crafted HTTP request.
- CVE-2022-20785HIGHCVSS 7.5EG 7.52022-05-04
On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in HTML file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104…
- CVE-2022-28487HIGHCVSS 7.5EG 7.52022-05-04
Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality.
- CVE-2021-42218HIGHCVSS 7.5EG 7.52022-05-03
OMPL v1.5.2 contains a memory leak in VFRRT.cpp
- CVE-2021-41959HIGHCVSS 7.5EG 7.52022-05-03
JerryScript Git version 14ff5bf does not sufficiently track and release allocated memory via jerry-core/ecma/operations/ecma-regexp-object.c after RegExp, which causes a memory leak.
- CVE-2022-24756HIGHCVSS 7.5EG 7.52022-03-15
Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and configured for PAM authentication, a failed PAM authentica…
- CVE-2022-0853HIGHCVSS 7.5EG 7.52022-03-11
A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.
- CVE-2021-40047HIGHCVSS 7.5EG 7.52022-03-10
There is a vulnerability of memory not being released after effective lifetime in the Bastet module. Successful exploitation of this vulnerability may affect integrity.
- CVE-2020-22844HIGHCVSS 7.5EG 7.52022-02-28
A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests.
- CVE-2022-22336HIGHCVSS 7.5EG 7.52022-02-23
IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395.
- CVE-2021-46082HIGHCVSS 7.5EG 7.52022-02-18
Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol gateways were discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via crafted …
- CVE-2021-37205HIGHCVSS 7.5EG 7.52022-02-09
A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC S7-1200 CPU family…
- CVE-2022-22174HIGHCVSS 7.5EG 7.52022-01-19
A vulnerability in the processing of inbound IPv6 packets in Juniper Networks Junos OS on QFX5000 Series and EX4600 switches may cause the memory to not be freed, leading to a packet DMA memory leak, and eventual Denial of Service (DoS) co…
- CVE-2022-22173HIGHCVSS 7.5EG 7.52022-01-19
A Missing Release of Memory after Effective Lifetime vulnerability in the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause Denial of Service (DoS). In a scenario whe…
- CVE-2021-44542HIGHCVSS 7.5EG 7.52021-12-23
A memory leak vulnerability was found in Privoxy when handling errors.
- CVE-2021-44541HIGHCVSS 7.5EG 7.52021-12-23
A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination.
- CVE-2021-44540HIGHCVSS 7.5EG 7.52021-12-23
A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing.
Map vulnerabilities like CWE-401 to your infrastructure
EchelonGraph correlates every CVE — across CWE-401 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →