Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-401

MITRE ↗

CWE-401

10
CRITICAL
401
HIGH
1,380
MEDIUM
78
LOW
1,874 CVEs · Page 19/38
5.5
CVE-2025-60358

radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.

5.5
CVE-2025-60359

radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.

5.5
CVE-2025-60360

radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.

5.5
CVE-2025-64329

containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 thro

5.3
CVE-2025-23085

A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additiona

5.3
CVE-2024-9135

On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak m

5.3
CVE-2025-1992

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could

5.3
CVE-2025-54939

LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.

5.3
CVE-2025-20077

Missing release of memory after effective lifetime in the UEFI OobRasMmbiHandlerDriver module for some Intel(R) referenc

5.3
CVE-2025-66033

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, speci

4.3
CVE-2024-7095

On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under s

4.3
CVE-2025-1816

A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This

4.3
CVE-2025-20135

A vulnerability in the DHCP client functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and

3.7
CVE-2025-23165

In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path

3.7
CVE-2025-53019

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.

3.5
CVE-2025-46686

Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated

3.3
CVE-2025-20011

in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

3.3
CVE-2025-3198

A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability i

3.3
CVE-2025-25057

in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.

3.3
CVE-2021-47671

In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory lea

3.3
CVE-2025-22886

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

3.3
CVE-2025-5324

A vulnerability, which was classified as problematic, was found in TechPowerUp GPU-Z 2.23.0. Affected is the function su

3.3
CVE-2025-6498

A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAllo

3.3
CVE-2025-7068

A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5F

3.3
CVE-2025-8225

A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_de

3.3
CVE-2025-24844

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

3.3
CVE-2025-24925

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

3.3
CVE-2025-27562

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

3.3
CVE-2025-60361

radare2 v5.9.8 and before contains a memory leak in the function bochs_open.

3.1
CVE-2025-1148

A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function lin

3.1
CVE-2025-1149

A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup

3.1
CVE-2025-1150

A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the func

3.1
CVE-2025-1151

A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdu

3.1
CVE-2025-1152

A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the f

3.1
CVE-2025-47279

Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to i

3.1
CVE-2025-8277

A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guess

2.5
CVE-2025-9165

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCC

9.8
CVE-2024-27388

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix some memleaks in gssx_dec_option_array

9.8
CVE-2024-36911

In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo VMs

9.3
CVE-2024-36909

In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Don't free ring buffers that co

8.8
CVE-2024-25450

imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().

8.8
CVE-2024-35804

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Mark target gfn of emulated atomic instru

8.8
CVE-2024-50041

In the Linux kernel, the following vulnerability has been resolved: i40e: Fix macvlan leak by synchronizing access to m

8.8
CVE-2024-56669

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Remove cache tags before disabling ATS

8.6
CVE-2024-20304

A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthen

8.2
CVE-2024-35834

In the Linux kernel, the following vulnerability has been resolved: xsk: recycle buffer in case Rx queue was full Add

7.8
CVE-2021-47158

In the Linux kernel, the following vulnerability has been resolved: net: dsa: sja1105: add error handling in sja1105_se

7.8
CVE-2024-27012

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: restore set elements when del

7.8
CVE-2024-27073

In the Linux kernel, the following vulnerability has been resolved: media: ttpci: fix two memleaks in budget_av_attach

7.8
CVE-2023-52662

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: fix a memleak in vmw_gmrid_man_get_node

Frequently Asked Questions

What is CWE-401?

CWE-401 (CWE-401) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-401?

There are 2,289 CVE records associated with CWE-401 in our database. Of these, 10 are critical severity, 401 are high severity, and 1380 are medium severity.

How can I protect against CWE-401 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-401 using AI-powered security agents.

Detect CWE-401 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-401 vulnerabilities across your infrastructure.

Get Started