CWE-401— Missing Release of Memory after Effective Lifetime (Memory Leak)
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.— MITRE CWE catalog
1,959 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-401page 6 of 40
- CVE-2021-37046HIGHCVSS 7.5EG 7.52021-12-07
There is a Memory leak vulnerability with the codec detection module in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart due to memory exhaustion.
- CVE-2020-23876HIGHCVSS 7.5EG 7.52021-11-10
pdf2xml v2.0 was discovered to contain a memory leak in the function TextPage::testLinkedText.
- CVE-2021-34598HIGHCVSS 7.5EG 7.52021-11-10
In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active
- CVE-2021-36993HIGHCVSS 7.5EG 7.52021-10-28
There is a Memory leaks vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.
- CVE-2021-40114HIGHCVSS 7.5EG 7.52021-10-27
Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. T…
- CVE-2021-34792HIGHCVSS 7.5EG 7.52021-10-27
A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an aff…
- CVE-2021-30844HIGHCVSS 7.5EG 7.52021-10-19
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A remote attacker may be able to leak memory.
- CVE-2020-20665HIGHCVSS 7.5EG 7.52021-09-30
rudp v0.6 was discovered to contain a memory leak in the component main.c.
- CVE-2021-39176HIGHCVSS 7.5EG 7.52021-08-31
detect-character-encoding is a package for detecting character encoding using ICU. In detect-character-encoding v0.3.0 and earlier, allocated memory is not released. The problem has been patched in detect-character-encoding v0.3.1.
- CVE-2021-39282HIGHCVSS 7.5EG 7.52021-08-18
Live555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files.
- CVE-2020-22650HIGHCVSS 7.5EG 7.52021-07-19
A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the occurrence of a large number of alarm events.
- CVE-2021-20108HIGHCVSS 7.5EG 7.52021-07-19
Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send commands over port 90…
- CVE-2021-20237HIGHCVSS 7.5EG 7.52021-05-28
An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remote unauthenticated attacker to send crafted PUB messages that consume excessive memory if the CURVE…
- CVE-2021-28651HIGHCVSS 7.5EG 7.52021-05-27
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is a…
- CVE-2021-20209HIGHCVSS 7.5EG 7.52021-05-25
A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are configured.
- CVE-2020-25672HIGHCVSS 7.5EG 7.52021-05-25
A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
- CVE-2020-20451HIGHCVSS 7.5EG 7.52021-05-25
Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.
- CVE-2021-32032HIGHCVSS 7.5EG 7.52021-05-21
In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the event of a failure) can prevent the abort() operation in the associated cryptographic library from freeing internal reso…
- CVE-2021-27386HIGHCVSS 7.5EG 7.52021-05-12
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16…
- CVE-2021-28665HIGHCVSS 7.5EG 7.52021-05-06
Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.
- CVE-2021-0230HIGHCVSS 7.5EG 7.52021-04-22
On Juniper Networks SRX Series devices with link aggregation (lag) configured, executing any operation that fetches Aggregated Ethernet (AE) interface statistics, including but not limited to SNMP GET requests, causes a slow kernel memory …
- CVE-2020-11255HIGHCVSS 7.5EG 7.52021-04-07
Denial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is freed and rest of the memory is leaked in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consu…
- CVE-2021-30141HIGHCVSS 7.5EG 7.52021-04-05
Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as demonstrated by an attempted access to an array offset on a value of type null, and excessive memory consumption. NOTE…
- CVE-2021-20216HIGHCVSS 7.5EG 7.52021-03-25
A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability.
- CVE-2021-20215HIGHCVSS 7.5EG 7.52021-03-25
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash.
- CVE-2021-20214HIGHCVSS 7.5EG 7.52021-03-25
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail can lead to a system crash.
- CVE-2021-20212HIGHCVSS 7.5EG 7.52021-03-25
A flaw was found in Privoxy in versions before 3.0.29. Memory leak if multiple filters are executed and the last one is skipped due to a pcre error leading to a system crash.
- CVE-2021-20211HIGHCVSS 7.5EG 7.52021-03-25
A flaw was found in Privoxy in versions before 3.0.29. Memory leak when client tags are active can cause a system crash.
- CVE-2021-20210HIGHCVSS 7.5EG 7.52021-03-25
A flaw was found in Privoxy in versions before 3.0.29. Memory leak in the show-status CGI handler when no filter files are configured can lead to a system crash.
- CVE-2020-35502HIGHCVSS 7.5EG 7.52021-03-25
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks when a response is buffered and the buffer limit is reached or Privoxy is running out of memory can lead to a system crash.
- CVE-2021-21723HIGHCVSS 7.5EG 7.52021-01-26
Some ZTE products have a DoS vulnerability. Due to the improper handling of memory release in some specific scenarios, a remote attacker can trigger the vulnerability by performing a series of operations, resulting in memory leak, which ma…
- CVE-2021-0202HIGHCVSS 7.5EG 7.52021-01-15
On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPC (Modular Port Concentrator) where Integrated Routing and Bridging (IRB) interface is configured and it is mapped to a VPLS instance or a Bridge-Domain, certain n…
- CVE-2018-11246HIGHCVSS 7.5EG 7.52021-01-11
K7TSMngr.exe in K7Computing K7AntiVirus Premium 15.1.0.53 has a Memory Leak.
- CVE-2020-35893HIGHCVSS 7.5EG 7.52020-12-31
An issue was discovered in the simple-slab crate before 0.3.3 for Rust. remove() has an off-by-one error, causing memory leakage and a drop of uninitialized memory.
- CVE-2020-9124HIGHCVSS 7.5EG 7.52020-12-29
There is a memory leak vulnerability in some versions of Huawei CloudEngine product. An unauthenticated, remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated m…
- CVE-2020-35679HIGHCVSS 7.5EG 7.52020-12-24
smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups.
- CVE-2020-27713HIGHCVSS 7.5EG 7.52020-12-11
In certain configurations on version 13.1.3.4, when a BIG-IP AFM HTTP security profile is applied to a virtual server and the BIG-IP system receives a request with specific characteristics, the connection is reset and the Traffic Managemen…
- CVE-2019-14559HIGHCVSS 7.5EG 7.52020-11-23
Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.
- CVE-2020-28723HIGHCVSS 7.5EG 7.52020-11-16
Memory leak in IPv6Param::setAddress in CloudAvid PParam 1.3.1.
- CVE-2020-1683HIGHCVSS 7.5EG 7.52020-10-16
On Juniper Networks Junos OS devices, a specific SNMP OID poll causes a memory leak which over time leads to a kernel crash (vmcore). Prior to the kernel crash other processes might be impacted, such as failure to establish SSH connection …
- CVE-2020-27174HIGHCVSS 7.5EG 7.52020-10-16
In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread,…
- CVE-2020-25644HIGHCVSS 7.5EG 7.52020-10-06
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to sys…
- CVE-2020-25795HIGHCVSS 7.5EG 7.52020-09-19
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, insert_from can have a memory-safety issue upon a panic.
- CVE-2020-25794HIGHCVSS 7.5EG 7.52020-09-19
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, clone can have a memory-safety issue upon a panic.
- CVE-2020-4375HIGHCVSS 7.5EG 7.52020-07-28
IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to cause a denial of service due to a memory leak caused by an error creating a dynamic queue. IBM X-Force ID: 179080.
- CVE-2020-15806HIGHCVSS 7.5EG 7.52020-07-22
CODESYS Control runtime system before 3.5.16.10 allows Uncontrolled Memory Allocation.
- CVE-2020-12604HIGHCVSS 7.5EG 7.52020-07-01
Envoy version 1.14.2, 1.13.2, 1.12.4 or earlier is susceptible to increased memory usage in the case where an HTTP/2 client requests a large payload but does not send enough window updates to consume the entire stream and does not reset th…
- CVE-2019-20888HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial of service (memory consumption) via an outgoing webhook or a slash command integration.
- CVE-2020-12887HIGHCVSS 7.5EG 7.52020-06-18
Memory leaks were discovered in the CoAP library in Arm Mbed OS 5.15.3 when using the Arm mbed-coap library 5.1.5. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses the CoA…
- CVE-2020-3195HIGHCVSS 7.5EG 7.52020-05-06
A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory l…
Map vulnerabilities like CWE-401 to your infrastructure
EchelonGraph correlates every CVE — across CWE-401 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →