CWE-401: CWE-401

548
Total CVEs
0
Critical
80
High
5.8
Avg CVSS

Yearly Trend

2026
23
2025
343
2024
135
2023
12
2022
16

Top Affected Vendors

1 Linux 437
2 Debian 30
3 Juniper 10
4 Qualcomm 4
5 F5 4
6 Fedoraproject 4
7 Libming 4
8 Imagemagick 4
9 Privoxy 4
10 Huawei 3

All CWE-401 CVEs (548)

CVE-2024-25450
8.8

CVE-2024-25450 is a memory allocation vulnerability in imlib2 v1.9.1's init_imlib_fonts() function that could lead to denial of service or arbitrary c...

Feb 9, 2024
CVE-2021-40633
8.8

CVE-2021-40633 is a memory leak vulnerability in gif2rgb, a utility in giflib 5.1.4, allowing remote attackers to cause denial of service by triggerin...

Jun 14, 2022
CVE-2021-3492
8.8

CVE-2021-3492 is a kernel vulnerability in Ubuntu's Shiftfs filesystem where improper error handling during copy_from_user() operations can cause memo...

Apr 17, 2021
CVE-2025-20239
8.6

An unauthenticated remote attacker can send crafted IKEv2 packets to trigger a memory leak in affected Cisco devices, causing denial of service. Cisco...

Aug 14, 2025
CVE-2025-20133
8.6

An unauthenticated remote attacker can cause Cisco Secure Firewall ASA and FTD devices to stop responding to Remote Access SSL VPN authentication requ...

Aug 14, 2025
CVE-2024-20304
8.6

This vulnerability in Cisco IOS XR Software allows unauthenticated remote attackers to send crafted Mtrace2 packets that exhaust UDP packet memory, ca...

Sep 11, 2024
CVE-2023-21666
8.4

CVE-2023-21666 is a memory corruption vulnerability in Qualcomm's Adreno GPU driver (KGSL) that allows attackers to access sensitive data from graphic...

May 2, 2023
CVE-2023-34451
8.2

CVE-2023-34451 is a memory exhaustion vulnerability in CometBFT where desynchronization between mempool data structures allows attackers to flood node...

Jul 3, 2023
CVE-2025-29828
8.1

This memory leak vulnerability in Windows Cryptographic Services allows remote attackers to execute arbitrary code on affected systems. Attackers can ...

Jun 10, 2025
CVE-2023-41484
8.1

CVE-2023-41484 is a memory leak vulnerability in Cimg Library v2.9.3 that allows attackers to extract sensitive information by processing a specially ...

Sep 20, 2023
CVE-2023-53577
7.8

This CVE-2023-53577 is a race condition vulnerability in the Linux kernel's BPF CPU map subsystem where a kernel thread could be stopped prematurely b...

Oct 4, 2025
CVE-2024-56775
7.8

A memory management vulnerability in the AMD display driver component of the Linux kernel could lead to memory leaks or double-free conditions when ha...

Jan 8, 2025
CVE-2024-56669
7.8

A use-after-free vulnerability in the Linux kernel's Intel IOMMU driver (VT-d) can cause kernel crashes when cache tags aren't properly cleaned before...

Dec 27, 2024
CVE-2024-44964
7.8

A use-after-free vulnerability in the Linux kernel's idpf driver allows attackers to cause system crashes or potentially execute arbitrary code with k...

Sep 4, 2024
CVE-2024-26734
7.8

This CVE describes a use-after-free and memory leak vulnerability in the Linux kernel's devlink subsystem initialization function. Attackers could pot...

Apr 3, 2024
CVE-2021-31240
7.8

CVE-2021-31240 is a memory corruption vulnerability in libming v0.4.8 that allows local attackers to execute arbitrary code via the parseSWF_IMPORTASS...

May 9, 2023
CVE-2021-42197
7.8

CVE-2021-42197 is a memory leak vulnerability in swftools' swfdump utility that can lead to remote code execution. Attackers can exploit this by provi...

Jun 2, 2022
CVE-2026-20014
7.7

This vulnerability in Cisco Secure Firewall ASA and FTD software allows authenticated VPN users to send specially crafted IKEv2 packets that cause mem...

Mar 4, 2026
CVE-2025-0241
7.7

A memory corruption vulnerability in text segmentation components of Mozilla products could allow attackers to cause crashes or potentially execute ar...

Jan 7, 2025
CVE-2026-24828
7.5

This is a memory leak vulnerability (CWE-401) in Is-Daouda is-Engine software where memory is not properly released after use. This allows attackers t...

Jan 27, 2026
CVE-2025-56353
7.5

A memory leak vulnerability in tinyMQTT allows attackers to cause denial of service by sending malformed UTF-8 strings in topic filters. Each malforme...

Jan 20, 2026
CVE-2025-46784
7.5

A denial-of-service vulnerability in Entr'ouvert Lasso's SAML processing allows attackers to crash the service by sending specially crafted SAML respo...

Nov 5, 2025
CVE-2025-53020
7.5

This vulnerability in Apache HTTP Server involves improper memory management where memory is released later than intended after its effective lifetime...

Jul 10, 2025
CVE-2025-47935
7.5

Multer versions before 2.0.0 have a memory leak vulnerability where HTTP request stream errors cause internal busboy streams to remain open, accumulat...

May 19, 2025
CVE-2025-30658
7.5

An unauthenticated attacker can cause a denial-of-service on Juniper SRX Series firewalls by sending specific HTTP content that triggers a memory leak...

Apr 9, 2025
CVE-2025-1634
7.5

A memory leak vulnerability in the quarkus-resteasy extension occurs when client requests timeout, causing buffers to not be properly released. This l...

Feb 26, 2025
CVE-2025-21091
7.5

This vulnerability in F5 BIG-IP systems allows attackers to cause memory exhaustion through undisclosed SNMP requests when SNMP v1/v2c is disabled. Th...

Feb 5, 2025
CVE-2025-21599
7.5

This CVE describes a memory leak vulnerability in Juniper's Tunnel Driver (jtd) on Junos OS Evolved. Unauthenticated attackers can send specially craf...

Jan 9, 2025
CVE-2024-8376
7.5

This vulnerability in Eclipse Mosquitto allows attackers to cause memory corruption through specific MQTT packet sequences, potentially leading to cra...

Oct 11, 2024
CVE-2024-7884
7.5

A memory leak vulnerability in Rust-based Internet Computer canisters using ic_cdk and ic_cdk_timers allows unaccounted references to persist in heap ...

Sep 5, 2024
CVE-2024-41172
7.5

This memory leak vulnerability in Apache CXF HTTP client conduit prevents proper garbage collection of HTTPClient instances, causing continuous memory...

Jul 19, 2024
CVE-2023-33084
7.5

This vulnerability allows attackers to cause a denial-of-service (DoS) condition by sending malformed IE fragments during DTLS handshake negotiations....

Mar 4, 2024
CVE-2024-24148
7.5

A memory leak vulnerability in libming's SWF parsing function allows attackers to cause denial of service by submitting specially crafted SWF files. T...

Feb 28, 2024
CVE-2024-27508
7.5

Atheme 7.2.12 contains a memory leak vulnerability in its crypto-benchmark component that allows attackers to gradually exhaust system memory through ...

Feb 27, 2024
CVE-2023-33049
7.5

CVE-2023-33049 is a heap memory leak vulnerability in Qualcomm's Multi-Mode Call Processor that can cause a denial of service (DoS) when user equipmen...

Feb 6, 2024
CVE-2024-24259
7.5

CVE-2024-24259 is a memory leak vulnerability in freeglut library versions through 3.4.0. The vulnerability occurs in the glutAddMenuEntry function an...

Feb 5, 2024
CVE-2024-24265
7.5

CVE-2024-24265 is a memory leak vulnerability in gpac v2.2.1 that occurs via the dst_props variable in the gf_filter_pid_merge_properties_internal fun...

Feb 5, 2024
CVE-2024-24267
7.5

This vulnerability in GPAC multimedia framework allows memory exhaustion through a memory leak in the gf_fileio_from_blob function. Attackers could ca...

Feb 5, 2024
CVE-2024-21611
7.5

A memory leak vulnerability in Juniper's Routing Protocol Daemon (rpd) allows unauthenticated network attackers to cause denial of service. When BGP n...

Jan 12, 2024
CVE-2023-38380
7.5

A memory leak vulnerability in the webserver of multiple Siemens SIMATIC and SIPLUS industrial communication products allows attackers with network ac...

Dec 12, 2023
CVE-2023-40534
7.5

This vulnerability allows attackers to cause denial of service by sending specially crafted HTTP/2 requests to F5 BIG-IP systems with specific configu...

Oct 10, 2023
CVE-2023-5156
7.5

CVE-2023-5156 is a memory leak vulnerability in the GNU C Library (glibc) introduced by a previous fix for CVE-2023-4806. This flaw can cause applicat...

Sep 25, 2023
CVE-2023-32247
7.5

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to cause denial-of-service by exploiting improper resource consumption hand...

Jul 24, 2023
CVE-2023-28982
7.5

This vulnerability allows an unauthenticated network attacker to cause a memory leak in Juniper's routing protocol daemon (rpd) during BGP rib shardin...

Apr 17, 2023
CVE-2022-22205
7.5

This CVE describes a memory leak vulnerability in Juniper SRX Series firewalls running Junos OS. An unauthenticated attacker can send specific network...

Jul 20, 2022
CVE-2021-41690
7.5

CVE-2021-41690 is a memory leak vulnerability in DCMTK's dcmqrdb program where allocated memory for file information isn't properly freed. Attackers c...

Jun 28, 2022
CVE-2022-33105
7.5

CVE-2022-33105 is a memory leak vulnerability in Redis v7.0's streamGetEdgeID component that allows attackers to cause denial of service by exhausting...

Jun 23, 2022
CVE-2018-17240
7.5

CVE-2018-17240 is a memory dump vulnerability in Netwave IP camera devices that allows unauthenticated attackers to access the /proc/kcore file, expos...

Jun 10, 2022
CVE-2022-29693
7.5

CVE-2022-29693 is a memory leak vulnerability in Unicorn Engine's uc_close function that allows attackers to cause denial of service through resource ...

Jun 2, 2022
CVE-2022-28487
7.5

CVE-2022-28487 is a memory leak vulnerability in Tcpreplay 4.4.1's fix_ipv6_checksums() function that can lead to resource exhaustion and potential da...

May 4, 2022

About CWE-401 (CWE-401)

Our database tracks 548 CVEs classified as CWE-401, with 0 rated critical and 80 rated high severity. The average CVSS score for CWE-401 vulnerabilities is 5.8.

External reference: View CWE-401 on MITRE CWE →

Monitor CWE-401 Vulnerabilities

Get alerted when new CWE-401 CVEs affect your infrastructure.

Start Monitoring Free