CWE-459

Incomplete Cleanup

Parent: CWE-404 - Improper Resource Shutdown or Release

The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

189 vulnerabilities with CWE-459
CVE-2023-42794 MEDIUM
Apache Tomcat 8.5.85-8.5.93 and 9.0.70-9.0.80 - Denial of Service via Unclosed File Stream
CVSS 5.9
CVE-2023-35945 HIGH
Envoy < 1.23.11 - Denial of Service via HTTP/2 RST_STREAM and GOAWAY Frame Handling
CVSS 7.5
CVE-2023-36468 CRITICAL
XWiki 2.0-14.10.7 - Incomplete Cleanup of Vulnerable Document Revisions
CVSS 9.9
CVE-2023-2400 LOW
Dovolations Server <2023.1.8 - Info Disclosure
CVSS 2.7
CVE-2023-20862 MEDIUM
Spring Security <5.7.8-<5.8.3-<6.0.3 - Privilege Escalation
CVSS 6.3
CVE-2023-0836 HIGH
HAProxy 2.1-2.2.26, 2.3-2.4.20, 2.5-2.5.10, 2.6-2.6.7, 2.7 - Information Disclosure
CVSS 7.5
CVE-2023-28859 MEDIUM
Redis-py <4.4.4, 4.5.x <4.5.4 - Info Disclosure
CVSS 6.5
CVE-2023-22407 MEDIUM
Juniper Networks Junos OS <18.4R2-S7, <19.1R3-S2, <19.2R3, <19.3R3,...
CVSS 6.5
CVE-2022-49028 MEDIUM
Linux Kernel 4.5-5.10.158 5.11-5.15.82 5.16-6.0.12 - Resource Leak in ixgbevf_init_module
CVSS 5.5
CVE-2022-49012 MEDIUM
Linux Kernel 6.0-6.0.12 - Incomplete Cleanup in afs_put_server
CVSS 5.5
CVE-2022-48893 MEDIUM
Linux Kernel - Resource Leak via Incomplete Engine Discovery Cleanup
CVSS 5.5
CVE-2022-46298 LOW
Intel Unison Software < 20.14.5683.0 - Denial of Service via Incomplete Cleanup
CVSS 1.9
CVE-2022-43477 LOW
Intel Unison Software < 20.14.5683.0 - Authenticated Information Disclosure via Incomplete Cleanup
CVSS 3.3
CVE-2022-40974 LOW
Intel(R) IPP Cryptography <2021.6 - Info Disclosure
CVSS 1.8
CVE-2022-45455 HIGH
Acronis Agent < 30025, Cyber Protect < 30984, Home Office < 40107 - Local Privilege Escalation
CVSS 7.8
CVE-2022-45347 CRITICAL
Apache ShardingSphere-Proxy <5.3.0 - Command Injection
CVSS 9.8
CVE-2022-3238 HIGH
Linux Kernel - Double Free in NTFS3 Subsystem via Simultaneous Remount and Umount
CVSS 7.8
CVE-2022-28764 LOW
Zoom Client <5.12.6 - Info Disclosure
CVSS 3.3
CVE-2022-27639 MEDIUM
Intel(R) XMM(TM) 7560 Modem <M2_7560_R_01.2146.00 - Privilege Escal...
CVSS 5.4
CVE-2022-39368 HIGH
Eclipse Californium < 2.7.4 and 3.0.0-3.7.0 - Denial of Service via Handshake Counter Cleanup Failure
CVSS 8.2
CVE-2022-44546 HIGH
HarmonyOS - Denial of Service via Kernel Memory Mapping Cleanup
CVSS 7.5
CVE-2022-42320 HIGH
Xen - Unauthorized Xenstore Node Access via Stale Domain ID Reuse
CVSS 7.0
CVE-2022-42310 MEDIUM
Xen 4.9.0-4.12.x - Incomplete Cleanup of Orphaned Xenstore Nodes
CVSS 5.5
CVE-2022-25664 MEDIUM
Qualcomm APQ8009 Firmware - Information Disclosure via GPU Data Read
CVSS 6.2
CVE-2022-1552 HIGH
PostgreSQL 10.0-10.20 SQL Injection via Multiple Commands
CVSS 8.8
Details
Vulnerabilities 189