CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,867 vulnerabilities with CWE-401
CVE-2025-71188 MEDIUM
Linux Kernel - Use-After-Free in DMA Engine Route Allocation
CVSS 5.5
CVE-2025-71187 MEDIUM
Linux Kernel 6.16-6.18.7 - Use-After-Free in DMA Engine Probe
CVSS 5.5
CVE-2025-71186 MEDIUM
Linux Kernel - Use-After-Free in DMA Engine Route Allocation
CVSS 5.5
CVE-2025-71185 MEDIUM
Linux Kernel - Use-After-Free in DMA Crossbar Device Allocation
CVSS 5.5
CVE-2025-28164 MEDIUM
libpng 1.6.43-1.6.46 - Denial of Service via png_create_read_struct() Buffer Overflow
CVSS 5.5
CVE-2025-71163 MEDIUM
Linux Kernel 5.15.0-6.18.6 - Use-After-Free in DMA Engine IDXD Compat Bind/Unbind
CVSS 5.5
CVE-2025-71154 MEDIUM
Linux Kernel - Use-After-Free in async_set_registers URB Submission
CVSS 5.5
CVE-2025-71153 MEDIUM
Linux Kernel < 6.6.120, 6.7.0-6.12.64, 6.9.0-6.18.4 - Use-After-Free in ksmbd get_file_all_info()
CVSS 5.5
CVE-2025-71151 MEDIUM
Linux Kernel < 6.6.120, 6.7.0-6.12.64, 6.13.0-6.18.3 - Use-After-Free in SMB3 Session Context Reconfiguration
CVSS 5.5
CVE-2025-71147 MEDIUM
Linux Kernel 5.13-5.15.198, 5.16-6.1.160, 6.2-6.6.120, 6.7-6.12.64, 6.13-6.18.3 - Use-After-Free in TPM2 Key Loading
CVSS 5.5
CVE-2025-71146 HIGH
Linux Kernel - Use-After-Free in netfilter nf_conncount Error Paths
CVSS 7.5
CVE-2025-56353 HIGH
tinymqtt - Denial of Service via Malformed UTF-8 Topic Filter Memory Leak
CVSS 7.5
CVE-2025-14027 HIGH
ControlLogix Redundancy Enhanced Module - Denial of Service via Crafted Class 3 Messages
CVE-2025-71114 MEDIUM
Linux Kernel - Use-After-Free in VIA Watchdog Driver Resource Allocation
CVSS 5.5
CVE-2025-56226 MEDIUM
libsndfile <=1.2.2 - Memory Leak in mpeg_l3_encoder_init
CVSS 5.3
CVE-2025-71081 MEDIUM
Linux Kernel - Use-After-Free in ASoC STM32 SAI Driver
CVSS 5.5
CVE-2025-66033 MEDIUM
Okta Java Management SDK <24.0.0 - Memory Corruption
CVSS 5.3
CVE-2025-64329 MEDIUM
containerd <1.7.29, 2.0.0-2.0.6, 2.1.0-2.1.4, 2.2.0-beta.0-2.2.0-rc.1 - Memory Exhaustion via CRI Attach Goroutine Leak
CVSS 5.5
CVE-2025-46784 HIGH
Entr'ouvert Lasso 2.5.1 - Denial of Service via SAML Response Parsing
CVSS 7.5
CVE-2025-50951 MEDIUM
FontForge v20230101 - Memory Corruption
CVSS 6.5
CVE-2025-50949 MEDIUM
FontForge v20230101 - Memory Corruption
CVSS 6.5
CVE-2025-60361 LOW
radare2 < 5.9.8 - Memory Leak in bochs_open
CVSS 3.3
CVE-2025-60360 MEDIUM
radare2 < 5.9.8 - Memory Leak in r2r_subprocess_init
CVSS 5.5
CVE-2025-60359 MEDIUM
radare2 < 5.9.8 - Memory Leak in r_bin_object_new
CVSS 5.5
CVE-2025-60358 MEDIUM
radare2 < 5.9.8 - Memory Leak in _load_relocations
CVSS 5.5
Details
Vulnerabilities 1,867
Exploit Likelihood Medium