CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,753 vulnerabilities with CWE-401
CVE-2025-38185 MEDIUM
Linux Kernel - Use-After-Free in atmtcp_c_send()
CVSS 5.5
CVE-2025-38165 MEDIUM
Linux Kernel - Use-After-Free in skb_linearize via sk_psock_backlog
CVSS 5.5
CVE-2025-38148 MEDIUM
Linux Kernel - Use-After-Free in One-Step Timestamping
CVSS 5.5
CVE-2025-38124 MEDIUM
Linux Kernel - Memory Corruption in UDP GSO skb_segment
CVSS 5.5
CVE-2025-38115 MEDIUM
Linux Kernel Use-After-Free in SFQ Qdisc (4.16-6.15.3)
CVSS 5.5
CVE-2025-6498 LOW
HTACG tidy-html5 5.8.0 - Memory Leak in defaultAlloc Function
CVSS 3.3
CVE-2025-38057 MEDIUM
Linux Kernel 5.6-6.12.30 - Use-After-Free in ESP-in-TCP Error Paths
CVSS 5.5
CVE-2025-38015 MEDIUM
Linux Kernel 6.0.9-6.14.7 Use-After-Free in idxd_alloc Error Handling
CVSS 5.5
CVE-2025-38011 MEDIUM
Linux Kernel 6.6-6.12.30 - Use-After-Free in AMDGPU CSA Unmap
CVSS 5.5
CVE-2025-29828 HIGH
Windows 11/Server 2022/2025 RCE via Use-After-Free in Cryptographic Services
CVSS 8.1
CVE-2025-5324 LOW
TechPowerUp GPU-Z 2.23.0 - Memory Leak
CVSS 3.3
CVE-2025-37989 MEDIUM
Linux Kernel - Use-After-Free in PHY LED Trigger Code
CVSS 5.5
CVE-2025-37983 MEDIUM
Linux Kernel - Use-After-Free in qibfs Inode Allocation
CVSS 5.5
CVE-2025-37982 MEDIUM
Linux Kernel - Use-After-Free in wl1251_tx_work
CVSS 5.5
CVE-2025-37980 MEDIUM
Linux Kernel 3.13-6.6.87, 6.7.0-6.12.24, 6.13.0-6.14.3 - Use-After-Free in blk_register_queue Error Path
CVSS 5.5
CVE-2025-37962 MEDIUM
Linux Kernel 6.1.134-6.1.138, 6.6.87-6.6.90, 6.12.23-6.12.28, 6.14.2-6.14.6 - Use-After-Free in ksmbd
CVSS 5.5
CVE-2025-37955 MEDIUM
Linux Kernel 6.11-6.12.28, 6.13-6.14.6 - Use-After-Free in virtnet_xsk_pool_enable
CVSS 5.5
CVE-2025-37951 MEDIUM
Linux Kernel 4.18-6.1.139 6.2.0-6.6.91 6.7.0-6.12.29 6.13.0-6.14.7 - Use-After-Free in DRM V3D Job Timeout Handling
CVSS 5.5
CVE-2025-37941 MEDIUM
Linux Kernel - Use-After-Free in wcd937x_soc_codec_probe
CVSS 5.5
CVE-2025-37909 MEDIUM
Linux Kernel 4.17-6.14.5 - Use-After-Free in LAN743x GSO Descriptor Mapping
CVSS 5.5
CVE-2025-37905 MEDIUM
Linux Kernel 5.13-5.14.x, 5.16-6.1.137, 6.2-6.6.89, 6.7-6.12.27, 6.13-6.14.5 - Use-After-Free in SCMI Device Destruction
CVSS 5.5
CVE-2025-37904 MEDIUM
Linux Kernel 6.13-6.14.5 - Use-After-Free in btrfs_iget()
CVSS 5.5
CVE-2025-47935 HIGH
Multer < 2.0.0 - Denial of Service via Unclosed Stream Handling
CVSS 7.5
CVE-2025-23165 LOW
Node.js <v20,v22 - Memory Corruption
CVSS 3.7
CVE-2025-47279 LOW
Undici < 5.29.0, 6.0.0-6.21.1, 7.0.0-7.4.9 - Memory Leak via Repeated Webhook Calls
CVSS 3.1
Details
Vulnerabilities 1,753
Exploit Likelihood Medium