CWE-401: CWE-401

549
Total CVEs
0
Critical
81
High
5.8
Avg CVSS

Yearly Trend

2026
23
2025
343
2024
135
2023
12
2022
16

Top Affected Vendors

1 Linux 437
2 Debian 30
3 Juniper 10
4 Qualcomm 4
5 F5 4
6 Fedoraproject 4
7 Libming 4
8 Imagemagick 4
9 Privoxy 4
10 Huawei 3

All CWE-401 CVEs (549)

CVE-2021-47420
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's AMDKFD (Kernel Fusion Driver) component. When user-space memory is mapped for DMA...

May 21, 2024
CVE-2021-47422
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's Nouveau graphics driver. When specific file operations are performed, the driver ...

May 21, 2024
CVE-2021-47392
5.5

This vulnerability in the Linux kernel's RDMA/CMA subsystem causes a resource leak and potential deadlock when rdma_cma_listen_on_all() fails. It affe...

May 21, 2024
CVE-2021-47345
5.5

A memory leak vulnerability exists in the Linux kernel's RDMA/CMA subsystem when rdma_resolve_route() is called multiple times on the same rdma_cm_id....

May 21, 2024
CVE-2021-47320
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's NFS (Network File System) implementation. When the posix_acl_create() function fa...

May 21, 2024
CVE-2021-47253
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's AMD display driver (drm/amd/display). During system suspend/resume cycles, the DM...

May 21, 2024
CVE-2021-47258
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's SCSI subsystem. When scsi_host_alloc() fails during device initialization, improp...

May 21, 2024
CVE-2021-47249
5.5

This vulnerability is a memory leak in the Linux kernel's RDS (Reliable Datagram Sockets) implementation. When rds_cmsg_recv() fails during message pr...

May 21, 2024
CVE-2024-35926
5.5

A memory leak vulnerability exists in the Linux kernel's IAA crypto driver where descriptors aren't properly freed during async_disable operations. Th...

May 19, 2024
CVE-2024-35879
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's device tree (OF) subsystem during overlay removal operations. It affects systems ...

May 19, 2024
CVE-2024-35882
5.5

A memory leak vulnerability in the Linux kernel's SUNRPC implementation allows unprivileged remote attackers to cause memory exhaustion on NFS servers...

May 19, 2024
CVE-2024-35877
5.5

A memory management vulnerability in the Linux kernel's x86 Page Attribute Table (PAT) handling for Copy-On-Write (COW) mappings. This can cause kerne...

May 19, 2024
CVE-2024-35858
5.5

A memory leak vulnerability in the Linux kernel's Broadcom ASP network driver allows attackers to cause denial of service through resource exhaustion....

May 17, 2024
CVE-2023-52698
5.5

A memory leak vulnerability exists in the Linux kernel's CALIPSO/IPv6 labeling subsystem when IPv6 support is disabled at boot. This causes kernel mem...

May 17, 2024
CVE-2023-52681
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's efivarfs filesystem where the s_fs_info structure isn't properly freed during unm...

May 17, 2024
CVE-2023-52684
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's QSEECOM driver for Qualcomm Secure Execution Environment (QSEE). When error condi...

May 17, 2024
CVE-2024-35833
5.5

A memory leak vulnerability in the Linux kernel's fsl-qdma DMA engine driver allows attackers to cause resource exhaustion by repeatedly triggering th...

May 17, 2024
CVE-2024-35829
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's Lima graphics driver. When lima_vm_map_bo fails during memory allocation, resourc...

May 17, 2024
CVE-2024-35831
5.5

A memory management vulnerability in the Linux kernel's io_uring subsystem where pinned memory pages are not properly released when the __io_uaddr_map...

May 17, 2024
CVE-2024-35816
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's firewire ohci driver where interrupt request (IRQ) resources are not properly fre...

May 17, 2024
CVE-2023-52662
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's VMware graphics driver (vmwgfx). When the driver fails to allocate memory for gra...

May 17, 2024
CVE-2024-27417
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's IPv6 implementation. When userspace provides specific network namespace attribute...

May 17, 2024
CVE-2024-27074
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's go7007 media driver. When the go7007_load_encoder function is called, it allocate...

May 1, 2024
CVE-2024-27077
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's V4L2 video framework. When the v4l2_m2m_register_entity function fails during dev...

May 1, 2024
CVE-2024-27388
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's SUNRPC subsystem within the gssx_dec_option_array function. When triggered, it ca...

May 1, 2024
CVE-2022-48669
5.5

This is a memory leak vulnerability in the Linux kernel's powerpc/pseries subsystem. When krealloc() fails in papr_get_attr(), the originally allocate...

May 1, 2024
CVE-2024-27012
5.5

A memory leak vulnerability in the Linux kernel's netfilter nf_tables subsystem occurs when deleting a set fails during transaction abort. This affect...

May 1, 2024
CVE-2024-26985
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's Xe graphics driver. When the intel_fb_bo_framebuffer_init function fails, it does...

May 1, 2024
CVE-2024-26655
5.5

A memory leak vulnerability exists in the Linux kernel's posix_clock_open() function where allocated memory isn't properly released when the clock's o...

Apr 1, 2024
CVE-2026-20106
5.3

An unauthenticated remote attacker can send crafted packets to Cisco ASA/FTD Remote Access SSL VPN, HTTP management, or MUS services to exhaust device...

Mar 4, 2026
CVE-2026-25969
5.3

A memory leak vulnerability exists in ImageMagick's ASHLAR image coder when processing certain images. This could allow attackers to cause denial of s...

Feb 24, 2026
CVE-2026-25796
5.3

This CVE describes a memory leak vulnerability in ImageMagick's STEGANO image decoder. When processing specially crafted steganographic images, the so...

Feb 24, 2026
CVE-2026-25637
5.3

A memory leak vulnerability in ImageMagick's ASHLAR image writer allows attackers to cause denial of service by exhausting process memory through craf...

Feb 24, 2026
CVE-2025-56226
5.3

Libsndfile versions up to 1.2.2 contain a memory leak vulnerability in the MPEG Layer 3 encoder initialization function. This vulnerability allows att...

Jan 14, 2026
CVE-2025-66033
5.3

The Okta Java Management SDK versions 21.0.0 through 24.0.0 have a memory management vulnerability in multithreaded implementations where threads are ...

Dec 10, 2025
CVE-2025-1992
5.3

This vulnerability in IBM Db2 allows authenticated users in a federation environment to cause a denial of service by exploiting insufficient memory re...

May 5, 2025
CVE-2025-23085
5.3

A memory leak vulnerability in Node.js HTTP/2 server occurs when remote peers abruptly close connections without proper GOAWAY notifications or when i...

Feb 7, 2025
CVE-2024-39536
5.3

A memory leak vulnerability in Juniper's Periodic Packet Management Daemon (ppmd) allows unauthenticated adjacent attackers to cause denial-of-service...

Jul 11, 2024
CVE-2024-3653
5.3

This CVE describes a vulnerability in Undertow's learning-push handler when enabled with default configuration. Attackers can exploit this via HTTP re...

Jul 8, 2024
CVE-2022-48698
5.3

This CVE describes a memory leak vulnerability in the AMD display driver component of the Linux kernel. When debugfs_lookup() is called without proper...

May 3, 2024
CVE-2024-56729
4.7

This CVE describes a memory leak vulnerability in the Linux kernel's SMB client implementation. When a lease break races with opening a cached directo...

Dec 29, 2024
CVE-2025-20135
4.3

A memory exhaustion vulnerability in Cisco ASA and FTD DHCP clients allows adjacent attackers to cause denial of service by sending crafted DHCPv4 pac...

Aug 14, 2025
CVE-2025-1816
4.3

A memory leak vulnerability in FFmpeg's IAMF file handler allows remote attackers to cause resource exhaustion by manipulating audio parameters. This ...

Mar 2, 2025
CVE-2024-53984
4.3

This vulnerability in Nanopb's Protocol Buffers implementation causes a memory leak when specific conditions are met during message decoding. It affec...

Dec 2, 2024
CVE-2025-61146
4.0

CVE-2025-61146 is a memory leak vulnerability in saitoha libsixel's malloc_stub.c component. This vulnerability allows attackers to cause gradual memo...

Feb 23, 2026
CVE-2025-15572
3.3

A memory leak vulnerability exists in wasm3 WebAssembly interpreter versions up to 0.5.0 in the NewCodePage function. This allows local attackers to g...

Feb 10, 2026
CVE-2026-21674
3.3

CVE-2026-21674 is a memory leak vulnerability in iccDEV's XML parsing functionality (iccFromXml) that allows attackers to cause gradual memory exhaust...

Jan 6, 2026
CVE-2025-47279
3.1

Undici HTTP client for Node.js versions before 5.29.0, 6.21.2, and 7.5.0 have a memory leak vulnerability when repeatedly calling webhooks to servers ...

May 15, 2025
CVE-2026-24825
N/A

This CVE describes a memory leak vulnerability in ydb-platform's ydb software, specifically in the yajl modules within yail_tree.C. Attackers could ex...

Jan 27, 2026

About CWE-401 (CWE-401)

Our database tracks 549 CVEs classified as CWE-401, with 0 rated critical and 81 rated high severity. The average CVSS score for CWE-401 vulnerabilities is 5.8.

External reference: View CWE-401 on MITRE CWE →

Monitor CWE-401 Vulnerabilities

Get alerted when new CWE-401 CVEs affect your infrastructure.

Start Monitoring Free