CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,744 vulnerabilities with CWE-401
CVE-2025-38590 MEDIUM
Linux Kernel 5.9-6.6.101, 6.7-6.12.41, 6.13-6.15.9, 6.16 - Use-After-Free in mlx5e Hardware Decryption
CVSS 5.5
CVE-2025-38549 MEDIUM
Linux Kernel - Use-After-Free in efivarfs_fs_info
CVSS 5.5
CVE-2025-38546 MEDIUM
Linux Kernel Use-After-Free in ATM Clip Module
CVSS 5.5
CVE-2025-38545 MEDIUM
Linux Kernel 6.10-6.12.39, 6.13-6.15.7 - Use-After-Free in SKB Memory Allocation
CVSS 5.5
CVE-2025-20254 MEDIUM
Cisco Secure Firewall ASA/FTD - Memory Corruption
CVSS 5.8
CVE-2025-20252 MEDIUM
Cisco Secure Firewall ASA/FTD - Memory Corruption
CVSS 5.8
CVE-2025-20239 HIGH
Cisco IOS 15.2(4)E-15.2(6)E - Unauthenticated Denial of Service via IKEv2 Packet Processing
CVSS 8.6
CVE-2025-20225 MEDIUM
Cisco IOS - Unauthenticated Denial of Service via IKEv2 Packet Processing
CVSS 5.8
CVE-2025-20224 MEDIUM
Cisco Secure Firewall ASA/FTD - Memory Corruption
CVSS 5.8
CVE-2025-20135 MEDIUM
Cisco Secure Firewall ASA/FTD - Memory Corruption
CVSS 4.3
CVE-2025-20133 HIGH
Cisco Secure Firewall ASA/FTD - DoS
CVSS 8.6
CVE-2025-20077 MEDIUM
Intel(R) reference server - Use After Free
CVSS 5.3
CVE-2025-27562 LOW
OpenHarmony < 5.0.3 - Denial of Service via Missing Memory Release
CVSS 3.3
CVE-2025-24925 LOW
OpenHarmony < 5.0.3 - Denial of Service via Missing Memory Release
CVSS 3.3
CVE-2025-24844 LOW
OpenHarmony < 5.0.3 - Denial of Service via Missing Memory Release
CVSS 3.3
CVE-2025-54939 MEDIUM
LiteSpeed QUIC Library < 4.3.1 - Memory Leak in lsquic_engine_packet_in
CVSS 5.3
CVE-2025-8225 LOW
GNU Binutils 2.44 - Memory Leak in DWARF Section Handler
CVSS 3.3
CVE-2025-38465 MEDIUM
Linux Kernel 2.6.13-6.15.6 - Use-After-Free in Netlink sk_rmem_alloc Wrapper
CVSS 5.5
CVE-2025-38444 MEDIUM
Linux Kernel - Use-After-Free in RAID10 Request Handling
CVSS 5.5
CVE-2025-38438 MEDIUM
Linux Kernel 5.2-6.12.39, 6.13.0-6.15.7 - Use-After-Free in ASoC SOF Intel HDA Driver
CVSS 5.5
CVE-2025-38427 MEDIUM
Linux Kernel - Use-After-Free in screen_info Framebuffer Handling
CVSS 5.5
CVE-2025-38419 MEDIUM
Linux Kernel 5.13-6.15.3 Use-After-Free in Remote Processor Attach
CVSS 5.5
CVE-2025-38418 MEDIUM
Linux Kernel 5.13-5.14 - Use-After-Free in Remote Processor Core
CVSS 5.5
CVE-2025-38417 MEDIUM
Linux Kernel 6.12-6.12.34, 6.13-6.15.3, 6.16 - Use-After-Free in ice_repr_create_vf
CVSS 5.5
CVE-2025-38410 MEDIUM
Linux Kernel 3.12-5.15.187, 5.16-6.1.144, 6.2-6.6.97, 6.7-6.12.37, 6.13-6.15.6 - Use-After-Free in DRM/MSM
CVSS 5.5
Details
Vulnerabilities 1,744
Exploit Likelihood Medium