CWE-401: CWE-401
Yearly Trend
Top Affected Vendors
All CWE-401 CVEs (549)
This CVE describes a memory leak vulnerability in the Linux kernel's AMDKFD (Kernel Fusion Driver) component. When user-space memory is mapped for DMA...
May 21, 2024This CVE describes a memory leak vulnerability in the Linux kernel's Nouveau graphics driver. When specific file operations are performed, the driver ...
May 21, 2024This vulnerability in the Linux kernel's RDMA/CMA subsystem causes a resource leak and potential deadlock when rdma_cma_listen_on_all() fails. It affe...
May 21, 2024A memory leak vulnerability exists in the Linux kernel's RDMA/CMA subsystem when rdma_resolve_route() is called multiple times on the same rdma_cm_id....
May 21, 2024This CVE describes a memory leak vulnerability in the Linux kernel's NFS (Network File System) implementation. When the posix_acl_create() function fa...
May 21, 2024This CVE describes a memory leak vulnerability in the Linux kernel's AMD display driver (drm/amd/display). During system suspend/resume cycles, the DM...
May 21, 2024This CVE describes a memory leak vulnerability in the Linux kernel's SCSI subsystem. When scsi_host_alloc() fails during device initialization, improp...
May 21, 2024This vulnerability is a memory leak in the Linux kernel's RDS (Reliable Datagram Sockets) implementation. When rds_cmsg_recv() fails during message pr...
May 21, 2024A memory leak vulnerability exists in the Linux kernel's IAA crypto driver where descriptors aren't properly freed during async_disable operations. Th...
May 19, 2024This CVE describes a memory leak vulnerability in the Linux kernel's device tree (OF) subsystem during overlay removal operations. It affects systems ...
May 19, 2024A memory leak vulnerability in the Linux kernel's SUNRPC implementation allows unprivileged remote attackers to cause memory exhaustion on NFS servers...
May 19, 2024A memory management vulnerability in the Linux kernel's x86 Page Attribute Table (PAT) handling for Copy-On-Write (COW) mappings. This can cause kerne...
May 19, 2024A memory leak vulnerability in the Linux kernel's Broadcom ASP network driver allows attackers to cause denial of service through resource exhaustion....
May 17, 2024A memory leak vulnerability exists in the Linux kernel's CALIPSO/IPv6 labeling subsystem when IPv6 support is disabled at boot. This causes kernel mem...
May 17, 2024This CVE describes a memory leak vulnerability in the Linux kernel's efivarfs filesystem where the s_fs_info structure isn't properly freed during unm...
May 17, 2024This CVE describes a memory leak vulnerability in the Linux kernel's QSEECOM driver for Qualcomm Secure Execution Environment (QSEE). When error condi...
May 17, 2024A memory leak vulnerability in the Linux kernel's fsl-qdma DMA engine driver allows attackers to cause resource exhaustion by repeatedly triggering th...
May 17, 2024This CVE describes a memory leak vulnerability in the Linux kernel's Lima graphics driver. When lima_vm_map_bo fails during memory allocation, resourc...
May 17, 2024A memory management vulnerability in the Linux kernel's io_uring subsystem where pinned memory pages are not properly released when the __io_uaddr_map...
May 17, 2024This CVE describes a memory leak vulnerability in the Linux kernel's firewire ohci driver where interrupt request (IRQ) resources are not properly fre...
May 17, 2024This CVE describes a memory leak vulnerability in the Linux kernel's VMware graphics driver (vmwgfx). When the driver fails to allocate memory for gra...
May 17, 2024This CVE describes a memory leak vulnerability in the Linux kernel's IPv6 implementation. When userspace provides specific network namespace attribute...
May 17, 2024This CVE describes a memory leak vulnerability in the Linux kernel's go7007 media driver. When the go7007_load_encoder function is called, it allocate...
May 1, 2024This CVE describes a memory leak vulnerability in the Linux kernel's V4L2 video framework. When the v4l2_m2m_register_entity function fails during dev...
May 1, 2024This CVE describes a memory leak vulnerability in the Linux kernel's SUNRPC subsystem within the gssx_dec_option_array function. When triggered, it ca...
May 1, 2024This is a memory leak vulnerability in the Linux kernel's powerpc/pseries subsystem. When krealloc() fails in papr_get_attr(), the originally allocate...
May 1, 2024A memory leak vulnerability in the Linux kernel's netfilter nf_tables subsystem occurs when deleting a set fails during transaction abort. This affect...
May 1, 2024This CVE describes a memory leak vulnerability in the Linux kernel's Xe graphics driver. When the intel_fb_bo_framebuffer_init function fails, it does...
May 1, 2024A memory leak vulnerability exists in the Linux kernel's posix_clock_open() function where allocated memory isn't properly released when the clock's o...
Apr 1, 2024An unauthenticated remote attacker can send crafted packets to Cisco ASA/FTD Remote Access SSL VPN, HTTP management, or MUS services to exhaust device...
Mar 4, 2026A memory leak vulnerability exists in ImageMagick's ASHLAR image coder when processing certain images. This could allow attackers to cause denial of s...
Feb 24, 2026This CVE describes a memory leak vulnerability in ImageMagick's STEGANO image decoder. When processing specially crafted steganographic images, the so...
Feb 24, 2026A memory leak vulnerability in ImageMagick's ASHLAR image writer allows attackers to cause denial of service by exhausting process memory through craf...
Feb 24, 2026Libsndfile versions up to 1.2.2 contain a memory leak vulnerability in the MPEG Layer 3 encoder initialization function. This vulnerability allows att...
Jan 14, 2026The Okta Java Management SDK versions 21.0.0 through 24.0.0 have a memory management vulnerability in multithreaded implementations where threads are ...
Dec 10, 2025This vulnerability in IBM Db2 allows authenticated users in a federation environment to cause a denial of service by exploiting insufficient memory re...
May 5, 2025A memory leak vulnerability in Node.js HTTP/2 server occurs when remote peers abruptly close connections without proper GOAWAY notifications or when i...
Feb 7, 2025A memory leak vulnerability in Juniper's Periodic Packet Management Daemon (ppmd) allows unauthenticated adjacent attackers to cause denial-of-service...
Jul 11, 2024This CVE describes a vulnerability in Undertow's learning-push handler when enabled with default configuration. Attackers can exploit this via HTTP re...
Jul 8, 2024This CVE describes a memory leak vulnerability in the AMD display driver component of the Linux kernel. When debugfs_lookup() is called without proper...
May 3, 2024This CVE describes a memory leak vulnerability in the Linux kernel's SMB client implementation. When a lease break races with opening a cached directo...
Dec 29, 2024A memory exhaustion vulnerability in Cisco ASA and FTD DHCP clients allows adjacent attackers to cause denial of service by sending crafted DHCPv4 pac...
Aug 14, 2025A memory leak vulnerability in FFmpeg's IAMF file handler allows remote attackers to cause resource exhaustion by manipulating audio parameters. This ...
Mar 2, 2025This vulnerability in Nanopb's Protocol Buffers implementation causes a memory leak when specific conditions are met during message decoding. It affec...
Dec 2, 2024CVE-2025-61146 is a memory leak vulnerability in saitoha libsixel's malloc_stub.c component. This vulnerability allows attackers to cause gradual memo...
Feb 23, 2026A memory leak vulnerability exists in wasm3 WebAssembly interpreter versions up to 0.5.0 in the NewCodePage function. This allows local attackers to g...
Feb 10, 2026CVE-2026-21674 is a memory leak vulnerability in iccDEV's XML parsing functionality (iccFromXml) that allows attackers to cause gradual memory exhaust...
Jan 6, 2026Undici HTTP client for Node.js versions before 5.29.0, 6.21.2, and 7.5.0 have a memory leak vulnerability when repeatedly calling webhooks to servers ...
May 15, 2025This CVE describes a memory leak vulnerability in ydb-platform's ydb software, specifically in the yajl modules within yail_tree.C. Attackers could ex...
Jan 27, 2026About CWE-401 (CWE-401)
Our database tracks 549 CVEs classified as CWE-401, with 0 rated critical and 81 rated high severity. The average CVSS score for CWE-401 vulnerabilities is 5.8.
External reference: View CWE-401 on MITRE CWE →
Monitor CWE-401 Vulnerabilities
Get alerted when new CWE-401 CVEs affect your infrastructure.
Start Monitoring Free