CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,744 vulnerabilities with CWE-401
CVE-2025-61146 MEDIUM
saitoha libsixel <1.8.7 - Memory Corruption
CVSS 4.0
CVE-2025-15572 LOW
wasm3 < 0.5.0 - Memory Leak in NewCodePage Function
CVSS 3.3
CVE-2025-47397 HIGH
Qualcomm AR8031 Firmware - Memory Corruption via GPU Memory Mapping
CVSS 7.8
CVE-2025-71189 MEDIUM
Linux Kernel 5.19.0-6.1.161, 6.2.0-6.6.121, 6.7.0-6.12.66, 6.13.0-6.18.6 - Use-After-Free in DMA Engine Route Allocation
CVSS 5.5
CVE-2025-71188 MEDIUM
Linux Kernel - Use-After-Free in DMA Engine Route Allocation
CVSS 5.5
CVE-2025-71187 MEDIUM
Linux Kernel 6.16-6.18.7 - Use-After-Free in DMA Engine Probe
CVSS 5.5
CVE-2025-71186 MEDIUM
Linux Kernel - Use-After-Free in DMA Engine Route Allocation
CVSS 5.5
CVE-2025-71185 MEDIUM
Linux Kernel - Use-After-Free in DMA Crossbar Device Allocation
CVSS 5.5
CVE-2025-28164 MEDIUM
libpng 1.6.43-1.6.46 - Denial of Service via png_create_read_struct() Buffer Overflow
CVSS 5.5
CVE-2025-71163 MEDIUM
Linux Kernel 5.15.0-6.18.6 - Use-After-Free in DMA Engine IDXD Compat Bind/Unbind
CVSS 5.5
CVE-2025-71154 MEDIUM
Linux Kernel - Use-After-Free in async_set_registers URB Submission
CVSS 5.5
CVE-2025-71153 MEDIUM
Linux Kernel < 6.6.120, 6.7.0-6.12.64, 6.9.0-6.18.4 - Use-After-Free in ksmbd get_file_all_info()
CVSS 5.5
CVE-2025-71151 MEDIUM
Linux Kernel < 6.6.120, 6.7.0-6.12.64, 6.13.0-6.18.3 - Use-After-Free in SMB3 Session Context Reconfiguration
CVSS 5.5
CVE-2025-71147 MEDIUM
Linux Kernel 5.13-5.15.198, 5.16-6.1.160, 6.2-6.6.120, 6.7-6.12.64, 6.13-6.18.3 - Use-After-Free in TPM2 Key Loading
CVSS 5.5
CVE-2025-71146 MEDIUM
Linux Kernel - Use-After-Free in netfilter nf_conncount Error Paths
CVSS 5.5
CVE-2025-56353 HIGH
tinymqtt - Denial of Service via Malformed UTF-8 Topic Filter Memory Leak
CVSS 7.5
CVE-2025-14027 HIGH
ControlLogix Redundancy Enhanced Module - Denial of Service via Crafted Class 3 Messages
CVE-2025-71114 MEDIUM
Linux Kernel - Use-After-Free in VIA Watchdog Driver Resource Allocation
CVSS 5.5
CVE-2025-56226 MEDIUM
libsndfile <=1.2.2 - Memory Leak in mpeg_l3_encoder_init
CVSS 5.3
CVE-2025-71081 MEDIUM
Linux Kernel - Use-After-Free in ASoC STM32 SAI Driver
CVSS 5.5
CVE-2025-66033 MEDIUM
Okta Java Management SDK <24.0.0 - Memory Corruption
CVSS 5.3
CVE-2025-64329 MEDIUM
containerd <1.7.29, 2.0.0-2.0.6, 2.1.0-2.1.4, 2.2.0-beta.0-2.2.0-rc.1 - Memory Exhaustion via CRI Attach Goroutine Leak
CVSS 5.5
CVE-2025-46784 HIGH
Entr'ouvert Lasso 2.5.1 - Denial of Service via SAML Response Parsing
CVSS 7.5
CVE-2025-50951 MEDIUM
FontForge v20230101 - Memory Corruption
CVSS 6.5
CVE-2025-50949 MEDIUM
FontForge v20230101 - Memory Corruption
CVSS 6.5
Details
Vulnerabilities 1,744
Exploit Likelihood Medium