VYPR

CWE-404

Improper Resource Shutdown or Release

ClassDraftLikelihood: Medium

Description

The product does not release or incorrectly releases a resource before it is made available for re-use.

When a resource is created or allocated, the developer is responsible for properly releasing the resource as well as accounting for all potential paths of expiration or invalidation, such as a set period of time or revocation.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-131 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-666

CVEs mapped to this weakness (759)

page 11 of 38
  • CVE-2021-40405MedApr 14, 2022
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi Upgrade API functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2020-0414MedOct 14, 2020
    risk 0.42cvss 6.5epss 0.01

    In AudioFlinger::RecordThread::threadLoop of audioflinger/Threads.cpp, there is a possible non-silenced audio buffer due to a permissions bypass. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2020-5416MedAug 21, 2020
    risk 0.42cvss 6.5epss 0.01

    Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in which an unauthenticated malicious attacker can send specially-crafted HTTP…

  • CVE-2020-14307MedJul 24, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows…

  • CVE-2020-12758HigJun 11, 2020
    risk 0.42cvss 7.5epss 0.02

    HashiCorp Consul and Consul Enterprise could crash when configured with an abnormally-formed service-router entry. Introduced in 1.6.0, fixed in 1.6.6 and 1.7.4.

  • CVE-2020-4325MedApr 2, 2020
    risk 0.42cvss 6.5epss 0.01

    The IBM Process Federation Server 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, and 19.0.0.3 Global Teams REST API does not properly shutdown the thread pools that it creates to retrieve Global Teams information from the federated systems. As a consequence, the Java Virtual Machine…

  • CVE-2019-15302MedSep 11, 2019
    risk 0.42cvss 6.5epss 0.01

    The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the URL) to corrupt it (i.e., cause data loss) via a trivial URL modification.

  • CVE-2017-11480HigDec 8, 2017
    risk 0.42cvss 7.5epss 0.01

    Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker could prevent Packetbeat…

  • CVE-2017-5650HigApr 17, 2017
    risk 0.42cvss 7.5epss 0.08

    In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting for a WINDOW_UPDATE before allowing the application to write more data. These…

  • CVE-2023-0417MedJan 26, 2023
    risk 0.41cvss 6.3epss 0.01

    Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

  • CVE-2023-0416MedJan 26, 2023
    risk 0.41cvss 6.3epss 0.01

    GNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

  • CVE-2023-0415MedJan 26, 2023
    risk 0.41cvss 6.3epss 0.01

    iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

  • CVE-2023-0414MedJan 26, 2023
    risk 0.41cvss 6.3epss 0.01

    Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture file

  • CVE-2023-0413MedJan 26, 2023
    risk 0.41cvss 6.3epss 0.01

    Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

  • CVE-2023-0412MedJan 26, 2023
    risk 0.41cvss 6.3epss 0.01

    TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

  • CVE-2022-23242MedMar 23, 2022
    risk 0.41cvss 6.3epss 0.00

    TeamViewer Linux versions before 15.28 do not properly execute a deletion command for the connection password in case of a process crash. Knowledge of the crash event and the TeamViewer ID as well as either possession of the pre-crash connection password or local authenticated…

  • CVE-2021-1093MedJul 22, 2021
    risk 0.40cvss 6.2epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary, and may…

  • CVE-2023-45802MedOct 23, 2023
    risk 0.39cvss 5.9epss 0.03

    When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy…

  • CVE-2021-26906MedFeb 18, 2021
    risk 0.39cvss 5.9epss 0.03

    An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP negotiation vulnerability in PJSIP allows a remote server to…

  • CVE-2017-7472MedMay 11, 2017
    risk 0.39cvss 5.5epss 0.02

    The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_DEFL_THREAD_KEYRING keyctl_set_reqkey_keyring calls.