CWE-401: CWE-401

544
Total CVEs
0
Critical
76
High
5.8
Avg CVSS

Yearly Trend

2026
23
2025
343
2024
135
2023
12
2022
16

Top Affected Vendors

1 Linux 437
2 Debian 30
3 Juniper 10
4 Qualcomm 4
5 F5 4
6 Libming 4
7 Fedoraproject 4
8 Imagemagick 4
9 Huawei 3
10 Radare 3

All CWE-401 CVEs (544)

CVE-2021-42218
7.5

CVE-2021-42218 is a memory leak vulnerability in OMPL (Open Motion Planning Library) version 1.5.2's VFRRT.cpp component. This vulnerability allows at...

May 3, 2022
CVE-2022-24756
7.5

CVE-2022-24756 is a memory leak vulnerability in Bareos Director when using PAM authentication, allowing attackers with access to the PAM Console (via...

Mar 15, 2022
CVE-2022-0853
7.5

CVE-2022-0853 is a memory leak vulnerability in JBoss client applications that repeatedly use UserTransaction. This allows attackers to cause informat...

Mar 11, 2022
CVE-2021-40047
7.5

CVE-2021-40047 is a memory leak vulnerability in Huawei's Bastet module where memory isn't properly released after its effective lifetime. This vulner...

Mar 10, 2022
CVE-2020-22844
7.5

A buffer overflow vulnerability in Mikrotik RouterOS 6.47 allows unauthenticated attackers to send crafted SMB requests that cause a denial of service...

Feb 28, 2022
CVE-2022-22336
7.5

This vulnerability in IBM Sterling External Authentication Server and IBM Sterling Secure Proxy allows a remote attacker to cause a denial of service ...

Feb 23, 2022
CVE-2022-22173
7.5

This CVE describes a memory leak vulnerability in Juniper Networks Junos OS PKI daemon (pkid) that occurs when Certificate Revocation List (CRL) downl...

Jan 19, 2022
CVE-2021-44541
7.5

This vulnerability in Privoxy is a memory management flaw in the process_encrypted_request_headers() function where header memory isn't properly freed...

Dec 23, 2021
CVE-2021-37046
7.5

This vulnerability in Huawei smartphones allows attackers to trigger memory exhaustion through the codec detection module, causing device restarts. It...

Dec 7, 2021
CVE-2020-23876
7.5

CVE-2020-23876 is a memory leak vulnerability in pdf2xml v2.0's TextPage::testLinkedText function that allows attackers to cause denial of service thr...

Nov 10, 2021
CVE-2021-34598
7.5

This vulnerability affects Phoenix Contact FL MGUARD 1102 and 1105 devices when remote logging is enabled. It causes memory exhaustion due to improper...

Nov 10, 2021
CVE-2021-36993
7.5

This CVE describes a memory leak vulnerability in Huawei smartphones that could allow attackers to gradually consume system memory resources. Successf...

Oct 28, 2021
CVE-2020-20665
7.5

CVE-2020-20665 is a memory leak vulnerability in rudp v0.6's main.c component that allows attackers to cause denial of service through resource exhaus...

Sep 30, 2021
CVE-2021-39176
7.5

CVE-2021-39176 is a memory leak vulnerability in the detect-character-encoding npm package versions 0.3.0 and earlier. The vulnerability allows attack...

Aug 31, 2021
CVE-2020-22650
7.5

A memory leak vulnerability in AlienVault OSSIM v5's sim-organizer.c component causes system crashes when processing large numbers of alarm events, le...

Jul 19, 2021
CVE-2021-20108
7.5

This vulnerability in ManageEngine Asset Explorer Agent allows remote attackers to cause a denial of service through memory exhaustion. By repeatedly ...

Jul 19, 2021
CVE-2020-25672
7.5

CVE-2020-25672 is a memory leak vulnerability in the Linux kernel's llcp_sock_connect function. This vulnerability allows attackers to cause denial of...

May 25, 2021
CVE-2021-27386
7.5

This vulnerability is a heap allocation leak in the SmartVNC device layout handler on client-side devices, which could lead to Denial-of-Service condi...

May 12, 2021
CVE-2020-11255
7.5

This vulnerability is a memory leak in Qualcomm Snapdragon chipsets when processing RTCP packets with multiple SDES reports. It allows attackers to ca...

Apr 7, 2021
CVE-2021-30141
7.5

CVE-2021-30141 is an authentication bypass vulnerability in Friendica's user export feature that allows anonymous users to access sensitive functional...

Apr 5, 2021
CVE-2023-5170
7.4

This vulnerability in Firefox's canvas rendering allows a compromised content process to cause unexpected surface changes, leading to memory leaks in ...

Sep 27, 2023
CVE-2021-34740
7.4

An unauthenticated attacker on the same wireless network can send specially crafted 802.11 frames to Cisco Aironet Access Points, causing a memory lea...

Sep 23, 2021
CVE-2023-52571
7.1

This CVE describes a memory management vulnerability in the Linux kernel's RK817 power supply driver where device tree node reference counts aren't pr...

Mar 2, 2024
CVE-2023-48090
7.1

GPAC 2.3-DEV-rev617-g671976fcc-master contains memory leaks in the extract_attributes function when processing M3U8 files. This vulnerability allows a...

Nov 20, 2023
CVE-2022-48541
7.1

A memory leak vulnerability in ImageMagick allows remote attackers to cause denial of service by triggering the 'identify -help' command. This affects...

Aug 22, 2023
CVE-2022-1651
7.1

A memory leak vulnerability in the Linux kernel's ACRN hypervisor device model allows local privileged attackers to leak kernel memory information, po...

Jul 26, 2022
CVE-2026-21909
6.5

This CVE describes a memory leak vulnerability in Juniper's routing protocol daemon (rpd) that allows an adjacent IS-IS neighbor to send malicious upd...

Jan 15, 2026
CVE-2025-50949
6.5

FontForge v20230101 contains a memory leak in the DlgCreate8 component that allows attackers to cause denial of service through resource exhaustion. T...

Oct 23, 2025
CVE-2025-54805
6.5

This vulnerability in F5 BIG-IP systems causes memory resource exhaustion in the Traffic Management Microkernel (TMM) when iRules are configured via t...

Oct 15, 2025
CVE-2025-47150
6.5

This vulnerability allows attackers to send specific SNMP requests to F5OS Appliance and Chassis systems, causing excessive memory consumption that co...

Oct 15, 2025
CVE-2024-42649
6.5

NanoMQ v0.22.10 contains a memory leak vulnerability in its MQTT PUBLISH message handling. Attackers can send crafted PUBLISH messages to gradually co...

Jul 14, 2025
CVE-2025-46420
6.5

A memory leak vulnerability in libsoup's soup_header_parse_quality_list() function allows attackers to cause denial of service by sending specially cr...

Apr 24, 2025
CVE-2024-6875
6.5

This vulnerability in Infinispan's REST compare API allows attackers to cause a buffer leak and out-of-memory errors by sending continuous requests wi...

Mar 28, 2025
CVE-2025-26306
6.5

A memory leak vulnerability in libming's readSizedString function allows attackers to cause denial of service by processing crafted files. This affect...

Feb 20, 2025
CVE-2025-26308
6.5

A memory leak vulnerability in libming's SWF file parser allows attackers to cause denial of service by submitting specially crafted SWF files. This a...

Feb 20, 2025
CVE-2025-25469
6.5

A memory leak vulnerability exists in FFmpeg's IAMF (Immersive Audio Model and Format) component that could allow attackers to cause denial of service...

Feb 18, 2025
CVE-2024-47493
6.5

This vulnerability allows an unauthenticated attacker on the same network segment to cause a denial of service on Juniper MX Series routers with Trio-...

Oct 11, 2024
CVE-2024-39550
6.5

An unauthenticated adjacent attacker can cause a memory leak in the rtlogd process on Juniper MX Series routers with SPC3 line cards by triggering rep...

Jul 11, 2024
CVE-2024-5294
6.5

This vulnerability allows network-adjacent attackers to cause a denial-of-service condition on D-Link DIR-3040 routers by exploiting a memory leak in ...

May 23, 2024
CVE-2024-35853
6.4

This CVE describes a memory leak vulnerability in the Linux kernel's mlxsw driver for Mellanox Spectrum switches. When ACL TCAM region rehashing fails...

May 17, 2024
CVE-2026-1757
6.2

A memory leak vulnerability in xmllint's interactive shell allows local denial-of-service attacks. When users input only whitespace, the program fails...

Feb 2, 2026
CVE-2024-39490
6.2

A memory leak vulnerability exists in the Linux kernel's IPv6 Segment Routing (SRv6) implementation. When processing SRv6 packets, if skb_cow_head() f...

Jul 10, 2024
CVE-2026-20013
5.8

A memory exhaustion vulnerability in Cisco ASA and FTD software's IKEv2 implementation allows unauthenticated remote attackers to cause denial of serv...

Mar 4, 2026
CVE-2025-20252
5.8

This vulnerability in Cisco ASA and FTD software allows unauthenticated remote attackers to trigger a memory leak by sending crafted IKEv2 packets, ca...

Aug 14, 2025
CVE-2025-20225
5.8

An unauthenticated remote attacker can send crafted IKEv2 packets to trigger a memory leak in affected Cisco devices, causing denial of service. On IO...

Aug 14, 2025
CVE-2025-28164
5.5

A buffer overflow vulnerability in libpng versions 1.6.43 through 1.6.46 allows local attackers to cause denial of service by exploiting the png_creat...

Jan 27, 2026
CVE-2025-71163
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's dmaengine idxd driver. When using the compat bind/unbind sysfs interface, the dri...

Jan 25, 2026
CVE-2026-22979
5.5

A memory leak vulnerability in the Linux kernel's network stack occurs when handling GRO (Generic Receive Offload) packets during segmentation. This p...

Jan 23, 2026
CVE-2025-71153
5.5

A memory leak vulnerability exists in the Linux kernel's ksmbd module when vfs_getattr() fails in get_file_all_info(). This could lead to gradual memo...

Jan 23, 2026
CVE-2025-71154
5.5

This CVE describes a memory leak vulnerability in the Linux kernel's rtl8150 USB Ethernet driver. When USB URB submission fails in async_set_registers...

Jan 23, 2026

About CWE-401 (CWE-401)

Our database tracks 544 CVEs classified as CWE-401, with 0 rated critical and 76 rated high severity. The average CVSS score for CWE-401 vulnerabilities is 5.8.

External reference: View CWE-401 on MITRE CWE →

Monitor CWE-401 Vulnerabilities

Get alerted when new CWE-401 CVEs affect your infrastructure.

Start Monitoring Free