CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,867 vulnerabilities with CWE-401
CVE-2025-20254 MEDIUM
Cisco Secure Firewall ASA/FTD - Memory Corruption
CVSS 5.8
CVE-2025-20252 MEDIUM
Cisco Secure Firewall ASA/FTD - Memory Corruption
CVSS 5.8
CVE-2025-20239 HIGH
Cisco IOS 15.2(4)E-15.2(6)E - Unauthenticated Denial of Service via IKEv2 Packet Processing
CVSS 8.6
CVE-2025-20225 MEDIUM
Cisco IOS - Unauthenticated Denial of Service via IKEv2 Packet Processing
CVSS 5.8
CVE-2025-20224 MEDIUM
Cisco Secure Firewall ASA/FTD - Memory Corruption
CVSS 5.8
CVE-2025-20135 MEDIUM
Cisco Secure Firewall ASA/FTD - Memory Corruption
CVSS 4.3
CVE-2025-20133 HIGH
Cisco Secure Firewall ASA/FTD - DoS
CVSS 8.6
CVE-2025-20077 MEDIUM
Intel(R) reference server - Use After Free
CVSS 5.3
CVE-2025-27562 LOW
OpenHarmony < 5.0.3 - Denial of Service via Missing Memory Release
CVSS 3.3
CVE-2025-24925 LOW
OpenHarmony < 5.0.3 - Denial of Service via Missing Memory Release
CVSS 3.3
CVE-2025-24844 LOW
OpenHarmony < 5.0.3 - Denial of Service via Missing Memory Release
CVSS 3.3
CVE-2025-54939 MEDIUM
LiteSpeed QUIC Library < 4.3.1 - Memory Leak in lsquic_engine_packet_in
CVSS 5.3
CVE-2025-8225 LOW
GNU Binutils 2.44 - Memory Leak in DWARF Section Handler
CVSS 3.3
CVE-2025-38465 MEDIUM
Linux Kernel 2.6.13-6.15.6 - Use-After-Free in Netlink sk_rmem_alloc Wrapper
CVSS 5.5
CVE-2025-38444 MEDIUM
Linux Kernel - Use-After-Free in RAID10 Request Handling
CVSS 5.5
CVE-2025-38438 MEDIUM
Linux Kernel 5.2-6.12.39, 6.13.0-6.15.7 - Use-After-Free in ASoC SOF Intel HDA Driver
CVSS 5.5
CVE-2025-38427 MEDIUM
Linux Kernel - Use-After-Free in screen_info Framebuffer Handling
CVSS 5.5
CVE-2025-38419 MEDIUM
Linux Kernel 5.13-6.15.3 Use-After-Free in Remote Processor Attach
CVSS 5.5
CVE-2025-38418 MEDIUM
Linux Kernel 5.13-5.14 - Use-After-Free in Remote Processor Core
CVSS 5.5
CVE-2025-38417 MEDIUM
Linux Kernel 6.12-6.12.34, 6.13-6.15.3, 6.16 - Use-After-Free in ice_repr_create_vf
CVSS 5.5
CVE-2025-38410 MEDIUM
Linux Kernel 3.12-5.15.187, 5.16-6.1.144, 6.2-6.6.97, 6.7-6.12.37, 6.13-6.15.6 - Use-After-Free in DRM/MSM
CVSS 5.5
CVE-2025-38409 MEDIUM
Linux Kernel 3.12-6.1.144, 6.2-6.6.97, 6.7-6.12.37, 6.13-6.15.6 - Use-After-Free in DRM MSM Submit Error Path
CVSS 5.5
CVE-2025-38405 HIGH
Linux Kernel 6.10.10-6.12.37, 6.11.0-6.12.37, 6.13.0-6.15.6 - Use-After-Free in NVMe Target Bio Integrity Handling
CVSS 7.5
CVE-2025-38390 MEDIUM
Linux Kernel 6.7-6.12.37, 6.13-6.15.6 - Use-After-Free in ARM FFA Notifier Callback
CVSS 5.5
CVE-2025-38384 MEDIUM
Linux Kernel - Use-After-Free in MTD SPI-NAND ECC Engine Configuration
CVSS 5.5
Details
Vulnerabilities 1,867
Exploit Likelihood Medium