CWE-401— Missing Release of Memory after Effective Lifetime (Memory Leak)
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.— MITRE CWE catalog
1,863 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-401page 5 of 38
- CVE-2020-1815HIGHCVSS 7.5EG 7.52020-02-18
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a memory leak vulnerability. The software does no…
- CVE-2020-1883MEDIUMCVSS 4.9EG 4.92020-06-05
Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with high privileges exploits this vulnerability by continuously performing specific operations. Successful exploitation of this vulnerability …
- CVE-2020-19724MEDIUMCVSS 5.5EG 5.52023-08-22
A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command.
- CVE-2020-20451HIGHCVSS 7.5EG 7.52021-05-25
Denial of Service issue in FFmpeg 4.2 due to resource management errors via fftools/cmdutils.c.
- CVE-2020-20665HIGHCVSS 7.5EG 7.52021-09-30
rudp v0.6 was discovered to contain a memory leak in the component main.c.
- CVE-2020-21490MEDIUMCVSS 5.5EG 5.52023-08-22
An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled.
- CVE-2020-21839MEDIUMCVSS 6.5EG 6.52021-05-17
An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/decode.c:3638.
- CVE-2020-22037MEDIUMCVSS 6.5EG 6.52021-06-01
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.
- CVE-2020-22038MEDIUMCVSS 6.5EG 6.52021-06-01
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c.
- CVE-2020-22039MEDIUMCVSS 6.5EG 6.52021-06-01
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the inavi_add_ientry function.
- CVE-2020-22040MEDIUMCVSS 6.5EG 6.52021-06-01
A Denial of Service vulnerability exists in FFmpeg 4.2 idue to a memory leak in the v_frame_alloc function in frame.c.
- CVE-2020-22041MEDIUMCVSS 6.5EG 6.52021-06-01
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_buffersrc_add_frame_flags function in buffersrc.
- CVE-2020-22042MEDIUMCVSS 6.5EG 6.52021-06-01
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak is affected by: memory leak in the link_filter_inouts function in libavfilter/graphparser.c.
- CVE-2020-22043MEDIUMCVSS 6.5EG 6.52021-06-01
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak at the fifo_alloc_common function in libavutil/fifo.c.
- CVE-2020-22044MEDIUMCVSS 6.5EG 6.52021-06-01
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the url_open_dyn_buf_internal function in libavformat/aviobuf.c.
- CVE-2020-22046MEDIUMCVSS 6.5EG 6.52021-06-02
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the avpriv_float_dsp_allocl function in libavutil/float_dsp.c.
- CVE-2020-22048MEDIUMCVSS 6.5EG 6.52021-06-02
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_frame_pool_get function in framepool.c.
- CVE-2020-22049MEDIUMCVSS 6.5EG 6.52021-06-02
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the wtvfile_open_sector function in wtvdec.c.
- CVE-2020-22051MEDIUMCVSS 6.5EG 6.52021-06-02
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the filter_frame function in vf_tile.c.
- CVE-2020-22054MEDIUMCVSS 6.5EG 6.52021-06-02
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the av_dict_set function in dict.c.
- CVE-2020-22056MEDIUMCVSS 6.5EG 6.52021-06-02
A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the config_input function in af_acrossover.c.
- CVE-2020-22650HIGHCVSS 7.5EG 7.52021-07-19
A memory leak vulnerability in sim-organizer.c of AlienVault Ossim v5 causes a denial of service (DOS) via a system crash triggered by the occurrence of a large number of alarm events.
- CVE-2020-22673MEDIUMCVSS 5.5EG 5.52021-10-12
Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.
- CVE-2020-22679MEDIUMCVSS 5.5EG 5.52021-10-12
Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.
- CVE-2020-22844HIGHCVSS 7.5EG 7.52022-02-28
A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests.
- CVE-2020-23876HIGHCVSS 7.5EG 7.52021-11-10
pdf2xml v2.0 was discovered to contain a memory leak in the function TextPage::testLinkedText.
- CVE-2020-25340MEDIUMCVSS 5.5EG 5.52021-02-16
An issue was discovered in NFStream 5.2.0. Because some allocated modules are not correctly freed, if the nfstream object is directly destroyed without being used after it is created, it will cause a memory leak that may result in a local …
- CVE-2020-25603HIGHCVSS 7.8EG 7.82020-09-23
An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event channel. Event channels control structures can be accessed lockless as long as the port is considered to be valid. Such a s…
- CVE-2020-25644HIGHCVSS 7.5EG 7.52020-10-06
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to sys…
- CVE-2020-25672HIGHCVSS 7.5EG 7.52021-05-25
A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
- CVE-2020-25689MEDIUMCVSS 5.3EG 5.32020-11-02
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This f…
- CVE-2020-25704MEDIUMCVSS 5.5EG 5.52020-12-02
A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denial of service.
- CVE-2020-25794HIGHCVSS 7.5EG 7.52020-09-19
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, clone can have a memory-safety issue upon a panic.
- CVE-2020-25795HIGHCVSS 7.5EG 7.52020-09-19
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, insert_from can have a memory-safety issue upon a panic.
- CVE-2020-26418MEDIUMCVSS 3.1EG 5.32020-12-11
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
- CVE-2020-26419MEDIUMCVSS 3.1EG 5.32020-12-11
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
- CVE-2020-26420MEDIUMCVSS 3.1EG 5.32020-12-11
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
- CVE-2020-26683MEDIUMCVSS 5.5EG 5.52023-08-22
A memory leak issue discovered in /pdf/pdf-font-add.c in Artifex Software MuPDF 1.17.0 allows attackers to obtain sensitive information.
- CVE-2020-27038MEDIUMCVSS 6.5EG 6.52020-12-15
In process of C2SoftVorbisDec.cpp, there is a possible resource exhaustion due to a memory leak. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Produc…
- CVE-2020-27174HIGHCVSS 7.5EG 7.52020-10-16
In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread,…
- CVE-2020-27713HIGHCVSS 7.5EG 7.52020-12-11
In certain configurations on version 13.1.3.4, when a BIG-IP AFM HTTP security profile is applied to a virtual server and the BIG-IP system receives a request with specific characteristics, the connection is reset and the Traffic Managemen…
- CVE-2020-27725MEDIUMCVSS 4.3EG 4.32020-12-24
In version 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 of BIG-IP DNS, GTM, and Link Controller, zxfrd leaks memory when listing DNS zones. Zones can be listed via TMSH, iControl or SNMP; only users…
- CVE-2020-27753MEDIUMCVSS 5.5EG 5.52020-12-08
There are several memory leaks in the MIFF coder in /coders/miff.c due to improper image depth values, which can be triggered by a specially crafted input file. These leaks could potentially lead to an impact to application availability or…
- CVE-2020-27755LOWCVSS 3.3EG 3.32020-12-08
in SetImageExtent() of /MagickCore/image.c, an incorrect image depth size can cause a memory leak because the code which checks for the proper image depth size does not reset the size in the event there is an invalid size. The patch resets…
- CVE-2020-27822MEDIUMCVSS 5.9EG 5.92020-12-08
A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the OpenTracing API's java-interceptors, there is a possibility of a memory leak. This flaw a…
- CVE-2020-28723HIGHCVSS 7.5EG 7.52020-11-16
Memory leak in IPv6Param::setAddress in CloudAvid PParam 1.3.1.
- CVE-2020-29485MEDIUMCVSS 5.5EG 5.52020-12-15
An issue was discovered in Xen 4.6 through 4.14.x. When acting upon a guest XS_RESET_WATCHES request, not all tracking information is freed. A guest can cause unbounded memory usage in oxenstored. This can lead to a system-wide DoS. Only s…
- CVE-2020-3189HIGHCVSS 8.6EG 8.62020-05-06
A vulnerability in the VPN System Logging functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak that can deplete system memory over time, which can cause unex…
- CVE-2020-3195HIGHCVSS 7.5EG 7.52020-05-06
A vulnerability in the Open Shortest Path First (OSPF) implementation in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory l…
- CVE-2020-3203HIGHCVSS 8.6EG 8.62020-06-03
A vulnerability in the locally significant certificate (LSC) provisioning feature of Cisco Catalyst 9800 Series Wireless Controllers that are running Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory l…
Map vulnerabilities like CWE-401 to your infrastructure
EchelonGraph correlates every CVE — across CWE-401 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →