The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Volume of CVEs assigned to CWE-401 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
1,856 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0158HIGH A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a mem | Mar 28, 2018 | 8.6 | 68 | YES | NO |
CVE-2020-13934HIGH An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a su | Jul 14, 2020 | 7.5 | 60 | NO | NO |
CVE-2016-6304HIGH Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) vi | Sep 26, 2016 | 7.5 | 60 | NO | NO |
CVE-2016-4232HIGH Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to obtain sensitive information f | Jul 13, 2016 | 7.5 | 52 | NO | YES |
Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver all versions from r0p0 - r42p0, Valhall G | Apr 6, 2023 | 3.3 | 51 | YES | NO |
CVE-2019-12265MEDIUM Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 | Aug 9, 2019 | 5.3 | 48 | NO | NO |
CVE-2001-0136MEDIUM Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly ins | Mar 12, 2001 | 5.0 | 45 | NO | YES |
CVE-2026-13474HIGH Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, | Jun 30, 2026 | 7.5 | 37 | NO | NO |
CVE-2026-46289CRITICAL In the Linux kernel, the following vulnerability has been resolved:
lib/scatterlist: fix length calculations in extract_kvec_to_sg
Patch series "Fix bugs in extract_iter_to_sg()" | Jun 8, 2026 | 9.8 | 37 | NO | NO |
CVE-2007-2274HIGH The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and application crash) via a malformed torrent file. NOTE: the ori | Apr 25, 2007 | 7.8 | 37 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.