CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,744 vulnerabilities with CWE-401
CVE-2026-4247 HIGH
TCP: remotely exploitable DoS vector (mbuf leak)
CVSS 7.5
CVE-2026-20012 HIGH
Cisco IOS - Unauthenticated Denial of Service via IKEv2 Packet Parsing
CVSS 8.6
CVE-2026-3104 HIGH
Memory leak in code preparing DNSSEC proofs of non-existence
CVSS 7.5
CVE-2026-23389 MEDIUM
Linux kernel - Memory Leak in ice_set_ringparam()
CVSS 5.5
CVE-2026-23384 MEDIUM
RDMA/ionic: Fix kernel stack leak in ionic_create_cq()
CVSS 5.5
CVE-2026-23360 MEDIUM
nvme: fix admin queue leak on controller reset
CVSS 5.5
CVE-2026-23350 HIGH
drm/xe/queue: Call fini on exec queue creation fail
CVSS 7.8
CVE-2026-23339 MEDIUM
nfc: nci: free skb on nci_transceive early error paths
CVSS 5.5
CVE-2026-23337 MEDIUM
pinctrl: pinconf-generic: Fix memory leak in pinconf_generic_parse_dt_config()
CVSS 5.5
CVE-2026-23335 MEDIUM
RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah()
CVSS 5.5
CVE-2026-23330 MEDIUM
nfc: nci: complete pending data exchange on device close
CVSS 5.5
CVE-2026-23297 MEDIUM
nfsd: Fix cred ref leak in nfsd_nl_threads_set_doit().
CVSS 5.5
CVE-2026-33852 HIGH
Missing Release of Memory after Effective Lifetime in MolotovCherry Android-ImageMagick7
CVSS 7.5
CVE-2026-33856 HIGH
Missing Release of Memory after Effective Lifetime in MolotovCherry Android-ImageMagick7
CVSS 7.5
CVE-2026-32874 HIGH
UltraJSON 5.4.0-5.11.0 - Large Integer Memory Leak Denial of Service
CVSS 7.5
CVE-2026-30873 MEDIUM
OpenWrt Project jsonpath: Memory leak when processing strings, labels, and regexp tokens
CVSS 4.9
CVE-2026-23263 MEDIUM
io_uring/zcrx: fix page array leak
CVSS 5.5
CVE-2026-23261 MEDIUM
nvme-fc: release admin tagset if init fails
CVSS 5.5
CVE-2026-23260 MEDIUM
regmap: maple: free entry on mas_store_gfp() failure
CVSS 5.5
CVE-2026-23258 MEDIUM
net: liquidio: Initialize netdev pointer before queue setup
CVSS 5.5
CVE-2026-0639 LOW
OpenHarmony <=6.0 liteos_a - Memory Leak Denial of Service
CVSS 3.3
CVE-2026-1605 HIGH
Eclipse Jetty 12.0.0-12.0.31/12.1.0-12.0.5 - Memory Corruption
CVSS 7.5
CVE-2026-20021 MEDIUM
Cisco Adaptive Security Appliance and Firepower Threat Defense Software - Denial of Service via OSPF Packet Parsing
CVSS 4.3
CVE-2026-20106 MEDIUM
Cisco ASA & FTD Unauthenticated DoS via Remote Access SSL VPN
CVSS 5.3
CVE-2026-20105 HIGH
Cisco ASA & FTD Authenticated DoS via Remote Access SSL VPN
CVSS 7.7
Details
Vulnerabilities 1,744
Exploit Likelihood Medium