CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,744 vulnerabilities with CWE-401
CVE-2026-20015 MEDIUM
Cisco Secure Firewall ASA/FTD - DoS
CVSS 5.8
CVE-2026-20014 HIGH
Cisco Secure Firewall ASA/FTD - DoS
CVSS 7.7
CVE-2026-20013 MEDIUM
Cisco Secure Firewall ASA/FTD - DoS
CVSS 5.8
CVE-2026-25988 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Memory Corruption
CVSS 5.3
CVE-2026-25969 MEDIUM
ImageMagick <7.1.2-15 - Memory Corruption
CVSS 5.3
CVE-2026-25796 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Memory Corruption
CVSS 5.3
CVE-2026-25638 MEDIUM
ImageMagick <7.1.2-15/<6.9.13-40 - Memory Corruption
CVSS 5.3
CVE-2026-25637 MEDIUM
ImageMagick <7.1.2-15 - Memory Corruption
CVSS 5.3
CVE-2026-23228 MEDIUM
Linux Kernel < 5.15.201 Use-After-Free in SMB Server Connection Handling
CVSS 5.5
CVE-2026-23205 MEDIUM
Linux Kernel < 6.1.163, 6.2.0-6.6.124, 6.7.0-6.12.70, 6.13.0-6.18.10 - Use-After-Free in SMB2 File Open
CVSS 5.5
CVE-2026-23190 MEDIUM
Linux Kernel 5.8.0-6.18.9 - Use-After-Free in ASoC AMD ACP3x PDM DMA
CVSS 5.5
CVE-2026-23172 HIGH
Linux Kernel Use-After-Free via Excessive SKB Fragments in DPMAIF RX Path
CVSS 8.4
CVE-2026-23170 MEDIUM
Linux Kernel Use-After-Free in DRM i.MX TVE DDC Device Reference
CVSS 5.5
CVE-2026-23164 MEDIUM
Linux Kernel - Use-After-Free in rocker_world_port_post_fini
CVSS 5.5
CVE-2026-23160 MEDIUM
Linux Kernel 6.4.0-6.6.122, 6.7.0-6.12.68, 6.13.0-6.18.8 - Use-After-Free in octep_device_setup
CVSS 5.5
CVE-2026-23151 MEDIUM
Linux Kernel - Use-After-Free in Bluetooth MGMT set_ssp_complete
CVSS 5.5
CVE-2026-23150 MEDIUM
Linux Kernel - Use-After-Free in NFC LLCP Socket Cleanup
CVSS 5.5
CVE-2026-23147 MEDIUM
Linux Kernel 6.15-6.18.9 - Use-After-Free in Btrfs Zlib S390 Hardware Acceleration
CVSS 5.5
CVE-2026-23145 MEDIUM
Linux kernel - Use After Free
CVSS 5.5
CVE-2026-23137 MEDIUM
Linux Kernel 3.18-6.18.5 - Use-After-Free in unittest_data_add()
CVSS 5.5
CVE-2026-21438 MEDIUM
webtransport-go < 0.10.0 - Denial of Service via Unbounded Memory Consumption
CVSS 5.3
CVE-2026-23108 MEDIUM
Linux Kernel 3.9.0-6.18.7 - Use-After-Free in CAN usb_8dev URB Handling
CVSS 5.5
CVE-2026-23095 HIGH
Linux Kernel - Memory Leak in GUE Packet Handling
CVSS 7.5
CVE-2026-23091 MEDIUM
Linux Kernel 4.4.0-6.18.7 - Use-After-Free in Intel TH Output Device Handling
CVSS 5.5
CVE-2026-23087 MEDIUM
Linux Kernel Use-After-Free in scsiback_remove()
CVSS 5.5
Details
Vulnerabilities 1,744
Exploit Likelihood Medium