CWE-401— Missing Release of Memory after Effective Lifetime (Memory Leak)
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.— MITRE CWE catalog
1,959 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-401page 9 of 40
- CVE-2026-56366MEDIUMCVSS 6.5EG 6.52026-07-10
ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service…
- CVE-2026-57027MEDIUMCVSS 6.5EG 6.52026-07-09
A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated adjacent attacker to cause a Denial-of-Service (D…
- CVE-2026-48987MEDIUMCVSS 6.5EG 6.52026-07-09
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list for each unique uuid submitted to the authe…
- CVE-2026-13593MEDIUMCVSS 6.5EG 6.52026-06-29
CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. The minify function has a memory leak when processing a document containing only characters to be removed, such as comments and …
- CVE-2026-56116MEDIUMCVSS 6.5EG 6.52026-06-23
dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of service by sending crafte…
- CVE-2026-33782MEDIUMCVSS 6.5EG 6.52026-04-09
A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to cause a memory leak, that will eventually cause a com…
- CVE-2026-33780MEDIUMCVSS 6.5EG 6.52026-04-09
A Missing Release of Memory after Effective Lifetime vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a memory leak ultima…
- CVE-2026-33775MEDIUMCVSS 6.5EG 6.52026-04-09
A Missing Release of Memory after Effective Lifetime vulnerability in the BroadBand Edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an adjacent, unauthenticated attacker to cause a Denial of Se…
- CVE-2026-21909MEDIUMCVSS 6.5EG 6.52026-01-15
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send a spec…
- CVE-2025-50949MEDIUMCVSS 6.5EG 6.52025-10-23
FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.
- CVE-2025-54805MEDIUMCVSS 6.5EG 6.52025-10-15
When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization. Note: Software versions wh…
- CVE-2025-47150MEDIUMCVSS 6.5EG 6.52025-10-15
When SNMP is configured on F5OS Appliance and Chassis systems, undisclosed requests can cause an increase in SNMP memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2024-42649MEDIUMCVSS 6.5EG 6.52025-07-14
NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.
- CVE-2025-46420MEDIUMCVSS 6.5EG 6.52025-04-24
A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.
- CVE-2025-30647MEDIUMCVSS 6.5EG 6.52025-04-09
A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS). In a subscr…
- CVE-2025-21595MEDIUMCVSS 6.5EG 6.52025-04-09
A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause an FPC to crash, leading to D…
- CVE-2024-6875MEDIUMCVSS 6.5EG 6.52025-03-28
A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak and an out of memory error can occur when sending continual requests with large POST data to the REST API.
- CVE-2025-29483MEDIUMCVSS 6.5EG 6.52025-03-27
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_ENABLEDEBUGGER2 function.
- CVE-2025-26311MEDIUMCVSS 6.5EG 6.52025-02-20
Multiple memory leaks have been identified in the clip actions parsing functions (parseSWF_CLIPACTIONS and parseSWF_CLIPACTIONRECORD) in util/parser.c of libming v0.4.8, which allow attackers to cause a denial of service via a crafted SWF …
- CVE-2025-26308MEDIUMCVSS 6.5EG 6.52025-02-20
A memory leak has been identified in the parseSWF_FILTERLIST function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.
- CVE-2025-26307MEDIUMCVSS 6.5EG 6.52025-02-20
A memory leak has been identified in the parseSWF_IMPORTASSETS2 function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.
- CVE-2025-26306MEDIUMCVSS 6.5EG 6.52025-02-20
A memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted file.
- CVE-2025-25469MEDIUMCVSS 6.5EG 6.52025-02-18
FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/iamf.c.
- CVE-2024-47493MEDIUMCVSS 6.5EG 6.52024-10-11
A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of the Juniper Networks Junos OS on the MX Series platforms with Trio-based FPCs allows an unauthenticated, adjacent attacker to cause…
- CVE-2024-39550MEDIUMCVSS 6.5EG 6.52024-07-11
A Missing Release of Memory after Effective Lifetime vulnerability in the rtlogd process of Juniper Networks Junos OS on MX Series with SPC3 allows an unauthenticated, adjacent attacker to trigger internal events cause ( which can be done…
- CVE-2024-5294MEDIUMCVSS 6.5EG 6.52024-05-23
D-Link DIR-3040 prog.cgi websSecurityHandler Memory Leak Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of D-Link DIR-3040 routers. Au…
- CVE-2024-21609MEDIUMCVSS 6.5EG 6.52024-04-12
A Missing Release of Memory after Effective Lifetime vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an administratively adjacent attacker which is able to successfully esta…
- CVE-2024-1023MEDIUMCVSS 6.5EG 6.52024-03-27
A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. Th…
- CVE-2024-24155MEDIUMCVSS 6.5EG 6.52024-02-29
Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a De…
- CVE-2024-24150MEDIUMCVSS 6.5EG 6.52024-02-29
A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
- CVE-2024-24149MEDIUMCVSS 6.5EG 6.52024-02-29
A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
- CVE-2024-24147MEDIUMCVSS 6.5EG 6.52024-02-29
A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.
- CVE-2024-24146MEDIUMCVSS 6.5EG 6.52024-02-29
A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.
- CVE-2024-24750MEDIUMCVSS 6.5EG 6.52024-02-16
Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in vers…
- CVE-2024-0240MEDIUMCVSS 6.5EG 6.52024-02-15
A memory leak in the Silicon Labs' Bluetooth stack for EFR32 products may cause memory to be exhausted when sending notifications to multiple clients, this results in all Bluetooth operations, such as advertising and scanning, to stop.
- CVE-2023-4969MEDIUMCVSS 6.5EG 6.52024-01-16
A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.
- CVE-2024-21613MEDIUMCVSS 6.5EG 6.52024-01-12
A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause an rpd crash, leading to Denial of…
- CVE-2024-21599MEDIUMCVSS 6.5EG 6.52024-01-12
A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). If an MX …
- CVE-2023-6299MEDIUMCVSS 6.5EG 6.52023-11-26
A vulnerability, which was classified as problematic, has been found in Apryse iText 8.0.1. This issue affects some unknown processing of the file PdfDocument.java of the component Reference Table Handler. The manipulation leads to memory …
- CVE-2023-43076MEDIUMCVSS 6.5EG 6.52023-11-02
Dell PowerScale OneFS 8.2.x,9.0.0.x-9.5.0.x contains a denial-of-service vulnerability. A low privilege remote attacker could potentially exploit this vulnerability to cause an out of memory (OOM) condition.
- CVE-2023-22392MEDIUMCVSS 6.5EG 6.52023-10-12
A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). PTX3000, PTX5000, QFX1…
- CVE-2023-33460MEDIUMCVSS 6.5EG 6.52023-06-06
There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.
- CVE-2023-22414MEDIUMCVSS 6.5EG 6.52023-01-13
A Missing Release of Memory after Effective Lifetime vulnerability in Flexible PIC Concentrator (FPC) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker from the same shared physical or logical network, to cause a he…
- CVE-2023-22406MEDIUMCVSS 6.5EG 6.52023-01-13
A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). In a segment-routing scenar…
- CVE-2023-22395MEDIUMCVSS 6.5EG 6.52023-01-13
A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). In an MPLS scenario specific packets destined to…
- CVE-2022-43037MEDIUMCVSS 6.5EG 6.52022-10-19
An issue was discovered in Bento4 1.6.0-639. There is a memory leak in the function AP4_File::ParseStream in /Core/Ap4File.cpp.
- CVE-2022-43032MEDIUMCVSS 6.5EG 6.52022-10-19
An issue was discovered in Bento4 v1.6.0-639. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42aac.
- CVE-2022-41427MEDIUMCVSS 6.5EG 6.52022-10-03
Bento4 v1.6.0-639 was discovered to contain a memory leak in the AP4_AvcFrameParser::Feed function in mp4mux.
- CVE-2022-41426MEDIUMCVSS 6.5EG 6.52022-10-03
Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_AtomFactory::CreateAtomFromStream function in mp4split.
- CVE-2022-41424MEDIUMCVSS 6.5EG 6.52022-10-03
Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_SttsAtom::Create function in mp42hls.
Map vulnerabilities like CWE-401 to your infrastructure
EchelonGraph correlates every CVE — across CWE-401 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →