CWE-401— Missing Release of Memory after Effective Lifetime (Memory Leak)
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.— MITRE CWE catalog
1,863 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-401page 12 of 38
- CVE-2022-3533MEDIUMCVSS 3.5EG 5.72022-10-17
A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects the function parse_usdt_arg of the file tools/lib/bpf/usdt.c of the component BPF. The manipulation of the argument reg_name leads to memory le…
- CVE-2022-3543MEDIUMCVSS 3.5EG 5.52022-10-17
A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function unix_sock_destructor/unix_release_sock of the file net/unix/af_unix.c of the component BPF. The manipulation leads to mem…
- CVE-2022-35433MEDIUMCVSS 6.5EG 6.52022-08-16
ffjpeg commit caade60a69633d74100bd3c2528bddee0b6a1291 was discovered to contain a memory leak via /src/jfif.c.
- CVE-2022-3551HIGHCVSS 3.5EG 7.52022-10-17
A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a pat…
- CVE-2022-3577HIGHCVSS 7.8EG 7.82022-10-20
An out-of-bounds memory write flaw was found in the Linux kernel’s Kid-friendly Wired Controller driver. This flaw allows a local user to crash or potentially escalate their privileges on the system. It is in bigben_probe of drivers/hid/…
- CVE-2022-35858HIGHCVSS 7.8EG 7.82022-08-04
The TEE_PopulateTransientObject and __utee_from_attr functions in Samsung mTower 0.3.0 allow a trusted application to trigger a memory overwrite, denial of service, and information disclosure by invoking the function TEE_PopulateTransientO…
- CVE-2022-35894MEDIUMCVSS 6.0EG 6.02022-09-22
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The SMI handler for the FwBlockServiceSmm driver uses an untrusted pointer as the location to copy data to an attacker-specified buffer, leading to information disclo…
- CVE-2022-36152MEDIUMCVSS 5.5EG 5.52022-08-16
tifig v0.2.2 was discovered to contain a memory leak via operator new[](unsigned long) at /asan/asan_new_delete.cpp.
- CVE-2022-3619MEDIUMCVSS 3.5EG 4.32022-10-20
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to memory le…
- CVE-2022-3624LOWCVSS 3.5EG 3.52022-10-21
A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. The manipulation leads to memory leak. It is re…
- CVE-2022-3629LOWCVSS 2.6EG 3.32022-10-21
A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function vsock_connect of the file net/vmw_vsock/af_vsock.c. The manipulation leads to memory leak. The complexity of an attack …
- CVE-2022-3630MEDIUMCVSS 3.1EG 5.52022-10-21
A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects some unknown processing of the file fs/fscache/cookie.c of the component IPsec. The manipulation leads to memory leak. It is recommended to app…
- CVE-2022-3633LOWCVSS 3.5EG 3.52022-10-21
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak. It is recommended to apply a patch to fi…
- CVE-2022-3646MEDIUMCVSS 3.1EG 5.32022-10-21
A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function nilfs_attach_log_writer of the file fs/nilfs2/segment.c of the component BPF. The manipulation leads to memory leak. The …
- CVE-2022-3668MEDIUMCVSS 5.3EG 5.52022-10-26
A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can…
- CVE-2022-3669MEDIUMCVSS 5.3EG 5.52022-10-26
A vulnerability was found in Axiomatic Bento4 and classified as problematic. This issue affects the function AP4_AvccAtom::Create of the component mp4edit. The manipulation leads to memory leak. The attack may be initiated remotely. The ex…
- CVE-2022-3812MEDIUMCVSS 4.3EG 6.52022-11-01
A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is the function AP4_ContainerAtom::AP4_ContainerAtom of the component mp4encrypt. The manipulation leads to memory leak. The attack may…
- CVE-2022-38177HIGHCVSS 7.5EG 7.52022-09-21
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
- CVE-2022-38178HIGHCVSS 7.5EG 7.52022-09-21
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
- CVE-2022-38371HIGHCVSS 7.5EG 7.52022-10-11
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BA…
- CVE-2022-38600MEDIUMCVSS 5.5EG 5.52022-09-15
Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vf_vo.c.
- CVE-2022-39004HIGHCVSS 7.5EG 7.52022-09-16
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
- CVE-2022-39005HIGHCVSS 7.5EG 7.52022-09-16
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks.
- CVE-2022-3957MEDIUMCVSS 4.3EG 6.52022-11-11
A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory…
- CVE-2022-40281HIGHCVSS 7.5EG 7.52022-09-08
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.
- CVE-2022-40439MEDIUMCVSS 6.5EG 6.52022-09-14
An memory leak issue was discovered in AP4_StdcFileByteStream::Create in mp42ts in Bento4 v1.6.0-639, allows attackers to cause a denial of service via a crafted file.
- CVE-2022-40884MEDIUMCVSS 5.5EG 5.52022-10-19
Bento4 1.6.0 has memory leaks via the mp4fragment.
- CVE-2022-4132MEDIUMCVSS 5.9EG 5.92023-10-04
A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page).
- CVE-2022-4139HIGHCVSS 7.8EG 7.82023-01-27
An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memory corruption or data leaks. This flaw could allow a local user to crash the system or escalate their privileges on th…
- CVE-2022-41419MEDIUMCVSS 6.5EG 6.52022-10-03
Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.
- CVE-2022-41424MEDIUMCVSS 6.5EG 6.52022-10-03
Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_SttsAtom::Create function in mp42hls.
- CVE-2022-41426MEDIUMCVSS 6.5EG 6.52022-10-03
Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_AtomFactory::CreateAtomFromStream function in mp4split.
- CVE-2022-41427MEDIUMCVSS 6.5EG 6.52022-10-03
Bento4 v1.6.0-639 was discovered to contain a memory leak in the AP4_AvcFrameParser::Feed function in mp4mux.
- CVE-2022-41556HIGHCVSS 7.5EG 7.52022-10-06
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/…
- CVE-2022-41624HIGHCVSS 7.5EG 7.52022-10-19
In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.2, 15.1.x before 15.1.7, 14.1.x before 14.1.5.2, and 13.1.x before 13.1.5.1, when a sideband iRule is configured on a virtual server, undisclosed traffic can cause an increase…
- CVE-2022-41832HIGHCVSS 7.5EG 7.52022-10-19
In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when a SIP profile is configured on a virtual server, undisclosed messages can cause an increase…
- CVE-2022-41847MEDIUMCVSS 5.5EG 5.52022-09-30
An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*, char const*, AP4_FileByteStream::Mode, AP4_ByteStream*&) in System/StdC/Ap4StdCFileByteStream.cpp.
- CVE-2022-42311HIGHCVSS 6.5EG 7.52022-11-01
Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amo…
- CVE-2022-42319HIGHCVSS 6.5EG 7.52022-11-01
Xenstore: Guests can cause Xenstore to not free temporary memory When working on a request of a guest, xenstored might need to allocate quite large amounts of memory temporarily. This memory is freed only after the request has been finishe…
- CVE-2022-42322MEDIUMCVSS 5.5EG 5.52022-11-01
Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node …
- CVE-2022-42323MEDIUMCVSS 5.5EG 5.52022-11-01
Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node …
- CVE-2022-42325MEDIUMCVSS 5.5EG 5.52022-11-01
Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a tr…
- CVE-2022-42326MEDIUMCVSS 5.5EG 5.52022-11-01
Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a tr…
- CVE-2022-43032MEDIUMCVSS 6.5EG 6.52022-10-19
An issue was discovered in Bento4 v1.6.0-639. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42aac.
- CVE-2022-43037MEDIUMCVSS 6.5EG 6.52022-10-19
An issue was discovered in Bento4 1.6.0-639. There is a memory leak in the function AP4_File::ParseStream in /Core/Ap4File.cpp.
- CVE-2022-43151MEDIUMCVSS 5.5EG 5.52022-10-31
timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-query.cc.
- CVE-2022-43221HIGHCVSS 7.5EG 7.52022-11-01
open5gs v2.4.11 was discovered to contain a memory leak in the component src/upf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.
- CVE-2022-43222HIGHCVSS 7.5EG 7.52022-11-01
open5gs v2.4.11 was discovered to contain a memory leak in the component src/smf/pfcp-path.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PFCP packet.
- CVE-2022-43223HIGHCVSS 7.5EG 7.52022-11-01
open5gs v2.4.11 was discovered to contain a memory leak in the component ngap-handler.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted UE attachment.
- CVE-2022-43254MEDIUMCVSS 5.5EG 5.52022-11-02
GPAC v2.1-DEV-rev368-gfd054169b-master was discovered to contain a memory leak via the component gf_list_new at utils/list.c.
Map vulnerabilities like CWE-401 to your infrastructure
EchelonGraph correlates every CVE — across CWE-401 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →