In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb
In the Linux kernel, the following vulnerability has been resolved: drm/colorop: Fix blob property reference tracking i
In the Linux kernel, the following vulnerability has been resolved: irqchip/imgpdc: Fix resource leak, add missing chai
In the Linux kernel, the following vulnerability has been resolved: igc: fix potential skb leak in igc_fpe_xmit_smd_fra
In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: fix spinlock leak in migrate_vma
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix SID memory leak in set_posix_acl_entries
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: fix urb->setup_packet leak in err
In the Linux kernel, the following vulnerability has been resolved: erofs: fix metabuf leak in inode xattr initializati
In the Linux kernel, the following vulnerability has been resolved: pds_core: fix debugfs_lookup dentry leak and error
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix error path leaks in some WMI WOW
In the Linux kernel, the following vulnerability has been resolved: net: ti: icssm-prueth: fix eth_ports_node leak in p
In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: fix potential memory leaks in ipc_
In the Linux kernel, the following vulnerability has been resolved: gpio: rockchip: teardown bugs and resource leaks A
In the Linux kernel, the following vulnerability has been resolved: iommufd: Move vevent memory allocation outside spin
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode
webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memo
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive S
A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) t
An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur v
Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to
There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhausti
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to
The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store th
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran
@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request t
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool downlo
The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a
Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strin
Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaus
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to both 24.10.6 and 25.12.1, t
A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secur
saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allo
ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers c
ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when openin
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocatio
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below co
A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation
in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.
A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample o
Frequently Asked Questions
What is CWE-401?
CWE-401 (CWE-401) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-401?
There are 2,289 CVE records associated with CWE-401 in our database. Of these, 10 are critical severity, 401 are high severity, and 1380 are medium severity.
How can I protect against CWE-401 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-401 using AI-powered security agents.
Detect CWE-401 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-401 vulnerabilities across your infrastructure.
Get Started