CWE-401— Missing Release of Memory after Effective Lifetime (Memory Leak)
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.— MITRE CWE catalog
1,863 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-401page 7 of 38
- CVE-2021-1597MEDIUMCVSS 6.5EG 6.52021-07-08
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial …
- CVE-2021-1598MEDIUMCVSS 6.5EG 6.52021-07-08
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial …
- CVE-2021-20108HIGHCVSS 7.5EG 7.52021-07-19
Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send commands over port 90…
- CVE-2021-20193MEDIUMCVSS 3.3EG 5.52021-03-26
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availa…
- CVE-2021-20209HIGHCVSS 7.5EG 7.52021-05-25
A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are configured.
- CVE-2021-20210HIGHCVSS 7.5EG 7.52021-03-25
A flaw was found in Privoxy in versions before 3.0.29. Memory leak in the show-status CGI handler when no filter files are configured can lead to a system crash.
- CVE-2021-20211HIGHCVSS 7.5EG 7.52021-03-25
A flaw was found in Privoxy in versions before 3.0.29. Memory leak when client tags are active can cause a system crash.
- CVE-2021-20212HIGHCVSS 7.5EG 7.52021-03-25
A flaw was found in Privoxy in versions before 3.0.29. Memory leak if multiple filters are executed and the last one is skipped due to a pcre error leading to a system crash.
- CVE-2021-20214HIGHCVSS 7.5EG 7.52021-03-25
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail can lead to a system crash.
- CVE-2021-20215HIGHCVSS 7.5EG 7.52021-03-25
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash.
- CVE-2021-20216HIGHCVSS 7.5EG 7.52021-03-25
A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability.
- CVE-2021-20234MEDIUMCVSS 6.5EG 6.52021-04-01
An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp. This issue causes a client that connects to multiple malicious or compromised servers to crash. The highest th…
- CVE-2021-20237HIGHCVSS 7.5EG 7.52021-05-28
An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remote unauthenticated attacker to send crafted PUB messages that consume excessive memory if the CURVE…
- CVE-2021-20265MEDIUMCVSS 5.5EG 5.52021-03-10
A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The …
- CVE-2021-21723HIGHCVSS 7.5EG 7.52021-01-26
Some ZTE products have a DoS vulnerability. Due to the improper handling of memory release in some specific scenarios, a remote attacker can trigger the vulnerability by performing a series of operations, resulting in memory leak, which ma…
- CVE-2021-21724MEDIUMCVSS 4.4EG 4.42021-02-26
A ZTE product has a memory leak vulnerability. Due to the product's improper handling of memory release in certain scenarios, a local attacker with device permissions repeatedly attenuated the optical signal to cause memory leak and abnorm…
- CVE-2021-22173HIGHCVSS 3.7EG 7.52021-02-17
Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
- CVE-2021-22312MEDIUMCVSS 6.5EG 6.52021-04-08
There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful…
- CVE-2021-22341MEDIUMCVSS 4.9EG 4.92021-06-29
There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers with high privilege can exploit this vulnerability by performing some operations. This can lead to memory leak. Affected …
- CVE-2021-22424MEDIUMCVSS 5.5EG 5.52021-08-03
A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability to cause Kernel Denial of Service.
- CVE-2021-23218MEDIUMCVSS 5.3EG 5.32022-01-10
When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service.
- CVE-2021-25701MEDIUMCVSS 5.5EG 5.52021-07-21
The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the handling of a variety of IOCTLs, which allowed an attacker to cause a denial of service.
- CVE-2021-26090MEDIUMCVSS 5.3EG 5.32021-07-12
A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may allow an unauthenticated remote attacker to exhaust available memory via specifically crafte…
- CVE-2021-26111MEDIUMCVSS 6.5EG 6.52021-06-01
A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below may allow an attacker on an adjacent network to exhaust available memory by sending specific…
- CVE-2021-26393MEDIUMCVSS 5.5EG 5.52022-11-09
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory w…
- CVE-2021-27386HIGHCVSS 7.5EG 7.52021-05-12
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16…
- CVE-2021-28651HIGHCVSS 7.5EG 7.52021-05-27
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is a…
- CVE-2021-28652MEDIUMCVSS 4.9EG 4.92021-05-27
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validation, it allows a Denial of Service attack against the Cache Manager API. This allows a trusted client to trigger memory leaks that. over time…
- CVE-2021-28665HIGHCVSS 7.5EG 7.52021-05-06
Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.
- CVE-2021-29649MEDIUMCVSS 5.5EG 5.52021-03-30
An issue was discovered in the Linux kernel before 5.11.11. The user mode driver (UMD) has a copy_process() memory leak, related to a lack of cleanup steps in kernel/usermode_driver.c and kernel/bpf/preload/bpf_preload_kern.c, aka CID-f60a…
- CVE-2021-30002MEDIUMCVSS 6.2EG 6.22021-04-02
An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v4l2-core/v4l2-ioctl.c has a memory leak for large arguments, aka CID-fb18802a338b.
- CVE-2021-30141HIGHCVSS 7.5EG 7.52021-04-05
Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as demonstrated by an attempted access to an array offset on a value of type null, and excessive memory consumption. NOTE…
- CVE-2021-30844HIGHCVSS 7.5EG 7.52021-10-19
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A remote attacker may be able to leak memory.
- CVE-2021-31240HIGHCVSS 7.8EG 7.82023-05-09
An issue found in libming v.0.4.8 allows a local attacker to execute arbitrary code via the parseSWF_IMPORTASSETS function in the parser.c file.
- CVE-2021-31256MEDIUMCVSS 5.5EG 5.52021-04-19
Memory leak in the stbl_GetSampleInfos function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
- CVE-2021-31367MEDIUMCVSS 6.5EG 6.52021-10-19
A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows an adjacent attacker to cause a Denial of Service (DoS) by sending genuine BGP flows…
- CVE-2021-3181MEDIUMCVSS 6.5EG 6.52021-01-19
rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A sma…
- CVE-2021-32032HIGHCVSS 7.5EG 7.52021-05-21
In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the event of a failure) can prevent the abort() operation in the associated cryptographic library from freeing internal reso…
- CVE-2021-33361MEDIUMCVSS 5.5EG 5.52021-09-13
Memory leak in the afra_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
- CVE-2021-33363MEDIUMCVSS 5.5EG 5.52021-09-13
Memory leak in the infe_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
- CVE-2021-33364MEDIUMCVSS 5.5EG 5.52021-09-13
Memory leak in the def_parent_box_new function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
- CVE-2021-33365MEDIUMCVSS 5.5EG 5.52021-09-13
Memory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
- CVE-2021-33366MEDIUMCVSS 5.5EG 5.52021-09-13
Memory leak in the gf_isom_oinf_read_entry function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
- CVE-2021-33437MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in mjs.c.
- CVE-2021-33450MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c.
- CVE-2021-33451MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.
- CVE-2021-33452MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_malloc() in nasmlib/alloc.c.
- CVE-2021-33645HIGHCVSS 7.5EG 7.52022-08-10
The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.
- CVE-2021-33646HIGHCVSS 7.5EG 7.52022-08-10
The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.
- CVE-2021-34389MEDIUMCVSS 5.0EG 5.02021-06-21
Trusty contains a vulnerability in NVIDIA OTE protocol message parsing code, which is present in all the TAs. An incorrect bounds check can allow a local user through a malicious client to access memory from the heap in the TrustZone, whic…
Map vulnerabilities like CWE-401 to your infrastructure
EchelonGraph correlates every CVE — across CWE-401 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →