CWE-401 · 1,858 records
Missing Release of Memory after Effective Lifetime
CVEs in this class
1,858 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2020-13934No exploit | An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 procesapache · tomcat · CWE-401 | High7.5 | — | 64.1% | Jul 14, 2020 |
49Plan | CVE-2016-6304No exploit | Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a dopenssl · openssl · CWE-401 | High7.5 | — | 63.0% | Sep 26, 2016 |
43Plan | CVE-2023-26083Weaponized | Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver aarm · 5th gen gpu architecture kernel driver · CWE-401 | Low3.3 | KEV | 1.2% | Apr 6, 2023 |
41Plan | CVE-2016-4232Proof of concept | Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attadobe · flash player desktop runtime · CWE-401 | High7.5 | — | 36.5% | Jul 12, 2016 |
39Monitor | CVE-2019-12265No exploit | Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component.windriver · vxworks · CWE-401 | Medium5.3 | — | 59.8% | Aug 9, 2019 |
39Monitor | CVE-2026-46289No exploit | lib/scatterlist: fix length calculations in extract_kvec_to_sglinux · linux kernel · CWE-401 | Critical9.8 | — | 0.5% | Jun 8, 2026 |
36Monitor | CVE-2019-6128No exploit | The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.libtiff · libtiff · CWE-401 | High8.8 | — | 3.9% | Jan 11, 2019 |
36Monitor | CVE-2021-40633No exploit | A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or dengiflib project · giflib · CWE-401 | High8.8 | — | 1.7% | Jun 14, 2022 |
36Monitor | CVE-2026-87078No exploit | Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycodeCWE-401 | Critical9.1 | — | 0.7% | Sep 22, 2026 |
35Monitor | CVE-2023-33718No exploit | mp4v2 v2.1.3 was discovered to contain a memory leak via MP4File::ReadString() at mp4file_io.cppmp4v2 project · mp4v2 · CWE-401 | High8.8 | — | 0.7% | May 31, 2023 |
35Monitor | CVE-2024-25450No exploit | imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().enlightenment · imlib2 · CWE-401 | High8.8 | — | 0.7% | Feb 9, 2024 |
35Monitor | CVE-2019-17340No exploit | An issue was discovered in Xen through 4.11.x allowing x86 guest OS users to cause a denial of service or gain privileges because grant-tablxen · xen · CWE-401 | High8.8 | — | 0.4% | Oct 7, 2019 |
34Monitor | CVE-2021-1387No exploit | Cisco NX-OS Software IPv6 Netstack Denial of Service Vulnerabilitycisco · unified computing system · CWE-401 | High8.6 | — | 1.4% | Feb 24, 2021 |
34Monitor | CVE-2021-1353No exploit | Cisco StarOS IPv4 Denial of Service Vulnerabilitycisco · staros · CWE-401 | High8.6 | — | 1.3% | Jan 20, 2021 |
34Monitor | CVE-2023-38380No exploit | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl.siemens · 6gk7243-8rx30-0xe0 firmware · CWE-401 | High8.7 | — | 1.0% | Dec 12, 2023 |
34Monitor | CVE-2026-48059No exploit | Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustionnetty · netty · CWE-401 | High8.7 | — | 0.9% | Jun 12, 2026 |
34Monitor | CVE-2026-48006No exploit | Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregatornetty · netty · CWE-401 | High8.7 | — | 0.8% | Jun 12, 2026 |
34Monitor | CVE-2025-20133No exploit | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Authentication Targeted Denial of Service Vucisco · cisco adaptive security appliance (asa) software · CWE-401 | High8.6 | — | 0.8% | Aug 14, 2025 |
34Monitor | CVE-2026-93436No exploit | vLLM through 0.29.0 Memory Exhaustion via Rejected Requestsvllm · vllm · CWE-401 | High8.7 | — | 0.8% | Sep 17, 2026 |
34Monitor | CVE-2026-35505No exploit | OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetimeoffis dicom · dcmtk toolkit · CWE-401 | High8.7 | — | 0.6% | Jun 30, 2026 |
34Monitor | CVE-2026-50254No exploit | OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetimeoffis dicom · dcmtk toolkit · CWE-401 | High8.7 | — | 0.6% | Jun 30, 2026 |
34Monitor | CVE-2026-44660No exploit | UltraJSON: Memory Leak in ujson.dump() on Write Failureultrajson project · ultrajson · CWE-401 | High8.7 | — | 0.6% | May 27, 2026 |
34Monitor | CVE-2026-94627No exploit | vLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID Collisionvllm · vllm · CWE-401 | High8.7 | — | 0.6% | Sep 21, 2026 |
34Monitor | CVE-2025-20239No exploit | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Secucisco · ios · CWE-401 | High8.6 | — | 0.6% | Aug 14, 2025 |
34Monitor | CVE-2026-3650No exploit | Grassroots DICOM Missing release of memory after effective lifetimegrassroots · grassroots dicom (gdcm) · CWE-401 | High8.7 | — | 0.6% | Mar 26, 2026 |
- CVE-2020-1393449Plan
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 proces
HighCVSS 7.5No exploitEPSS 64%apache · tomcatJul 14, 2020
- CVE-2016-630449Plan
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a d
HighCVSS 7.5No exploitEPSS 63%openssl · opensslSep 26, 2016
- CVE-2023-2608343Plan
Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver a
LowCVSS 3.3KEVWeaponizedEPSS 1%arm · 5th gen gpu architecture kernel driverApr 6, 2023
- CVE-2016-423241Plan
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows att
HighCVSS 7.5Proof of conceptEPSS 36%adobe · flash player desktop runtimeJul 12, 2016
- CVE-2019-1226539Monitor
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component.
MediumCVSS 5.3No exploitEPSS 60%windriver · vxworksAug 9, 2019
- CVE-2026-4628939Monitor
lib/scatterlist: fix length calculations in extract_kvec_to_sg
CriticalCVSS 9.8No exploitEPSS 0%linux · linux kernelJun 8, 2026
- CVE-2019-612836Monitor
The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.
HighCVSS 8.8No exploitEPSS 4%libtiff · libtiffJan 11, 2019
- CVE-2021-4063336Monitor
A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of memory exception or den
HighCVSS 8.8No exploitEPSS 2%giflib project · giflibJun 14, 2022
- CVE-2026-8707836Monitor
Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode
CriticalCVSS 9.1No exploitEPSS 1%Sep 22, 2026
- CVE-2023-3371835Monitor
mp4v2 v2.1.3 was discovered to contain a memory leak via MP4File::ReadString() at mp4file_io.cpp
HighCVSS 8.8No exploitEPSS 1%mp4v2 project · mp4v2May 31, 2023
- CVE-2024-2545035Monitor
imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().
HighCVSS 8.8No exploitEPSS 1%enlightenment · imlib2Feb 9, 2024
- CVE-2019-1734035Monitor
An issue was discovered in Xen through 4.11.x allowing x86 guest OS users to cause a denial of service or gain privileges because grant-tabl
HighCVSS 8.8No exploitEPSS 0%xen · xenOct 7, 2019
- CVE-2021-138734Monitor
Cisco NX-OS Software IPv6 Netstack Denial of Service Vulnerability
HighCVSS 8.6No exploitEPSS 1%cisco · unified computing systemFeb 24, 2021
- CVE-2021-135334Monitor
Cisco StarOS IPv4 Denial of Service Vulnerability
HighCVSS 8.6No exploitEPSS 1%cisco · starosJan 20, 2021
- CVE-2023-3838034Monitor
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl.
HighCVSS 8.7No exploitEPSS 1%siemens · 6gk7243-8rx30-0xe0 firmwareDec 12, 2023
- CVE-2026-4805934Monitor
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
HighCVSS 8.7No exploitEPSS 1%netty · nettyJun 12, 2026
- CVE-2026-4800634Monitor
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
HighCVSS 8.7No exploitEPSS 1%netty · nettyJun 12, 2026
- CVE-2025-2013334Monitor
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Authentication Targeted Denial of Service Vu
HighCVSS 8.6No exploitEPSS 1%cisco · cisco adaptive security appliance (asa) softwareAug 14, 2025
- CVE-2026-9343634Monitor
vLLM through 0.29.0 Memory Exhaustion via Rejected Requests
HighCVSS 8.7No exploitEPSS 1%vllm · vllmSep 17, 2026
- CVE-2026-3550534Monitor
OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime
HighCVSS 8.7No exploitEPSS 1%offis dicom · dcmtk toolkitJun 30, 2026
- CVE-2026-5025434Monitor
OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime
HighCVSS 8.7No exploitEPSS 1%offis dicom · dcmtk toolkitJun 30, 2026
- CVE-2026-4466034Monitor
UltraJSON: Memory Leak in ujson.dump() on Write Failure
HighCVSS 8.7No exploitEPSS 1%ultrajson project · ultrajsonMay 27, 2026
- CVE-2026-9462734Monitor
vLLM through 0.29.0 GPU KV Cache Leak via Mooncake Transfer ID Collision
HighCVSS 8.7No exploitEPSS 1%vllm · vllmSep 21, 2026
- CVE-2025-2023934Monitor
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Secu
HighCVSS 8.6No exploitEPSS 1%cisco · iosAug 14, 2025
- CVE-2026-365034Monitor
Grassroots DICOM Missing release of memory after effective lifetime
HighCVSS 8.7No exploitEPSS 1%grassroots · grassroots dicom (gdcm)Mar 26, 2026