radare2 v.5.9.8 and before contains a memory leak in the function _load_relocations.
radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new.
radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init.
containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 thro
A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additiona
On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak m
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
Missing release of memory after effective lifetime in the UEFI OobRasMmbiHandlerDriver module for some Intel(R) referenc
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, speci
On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under s
A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This
A vulnerability in the DHCP client functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.
Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated
in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.
A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability i
in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.
In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory lea
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
A vulnerability, which was classified as problematic, was found in TechPowerUp GPU-Z 2.23.0. Affected is the function su
A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAllo
A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5F
A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_de
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
radare2 v5.9.8 and before contains a memory leak in the function bochs_open.
A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function lin
A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup
A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the func
A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdu
A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the f
Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to i
A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guess
A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCC
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix some memleaks in gssx_dec_option_array
In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo VMs
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Don't free ring buffers that co
imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Mark target gfn of emulated atomic instru
In the Linux kernel, the following vulnerability has been resolved: i40e: Fix macvlan leak by synchronizing access to m
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Remove cache tags before disabling ATS
A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthen
In the Linux kernel, the following vulnerability has been resolved: xsk: recycle buffer in case Rx queue was full Add
In the Linux kernel, the following vulnerability has been resolved: net: dsa: sja1105: add error handling in sja1105_se
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: restore set elements when del
In the Linux kernel, the following vulnerability has been resolved: media: ttpci: fix two memleaks in budget_av_attach
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: fix a memleak in vmw_gmrid_man_get_node
Frequently Asked Questions
What is CWE-401?
CWE-401 (CWE-401) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-401?
There are 2,289 CVE records associated with CWE-401 in our database. Of these, 10 are critical severity, 401 are high severity, and 1380 are medium severity.
How can I protect against CWE-401 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-401 using AI-powered security agents.
Detect CWE-401 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-401 vulnerabilities across your infrastructure.
Get Started