VYPR

CWE-404

Improper Resource Shutdown or Release

ClassDraftLikelihood: Medium

Description

The product does not release or incorrectly releases a resource before it is made available for re-use.

When a resource is created or allocated, the developer is responsible for properly releasing the resource as well as accounting for all potential paths of expiration or invalidation, such as a set period of time or revocation.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-131 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-666

CVEs mapped to this weakness (759)

page 5 of 38
  • CVE-2024-22019HigFeb 20, 2024
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of…

  • CVE-2023-7209HigJan 7, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Uniway Router up to 2.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boaform/device_reset.cgi of the component Device Reset Handler. The manipulation leads to denial of service. The attack may be…

  • CVE-2023-4882HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.01

    DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the service to crash.

  • CVE-2022-48500HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.

  • CVE-2022-48499HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.

  • CVE-2022-48489HigJun 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-29726HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    The Call Blocker application 6.6.3 for Android incorrectly opens a key component that an attacker can use to inject large amounts of dirty data into the application's database. When the application starts, it loads the data from the database into memory. Once the attacker…

  • CVE-2023-2379HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability classified as critical has been found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This affects an unknown part of the component Web Service. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2022-3684HigMar 28, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web services become busy rendering the application unresponsive. This issue affects: All SDM600 versions prior to version 1.2 FP3 HF4…

  • CVE-2023-1444HigMar 17, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Filseclab Twister Antivirus 8. It has been rated as critical. This issue affects the function 0x8011206B in the library fildds.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack may be initiated…

  • CVE-2022-33324HigDec 23, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU Firmware versions "32" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU Firmware versions "65" and prior, Mitsubishi…

  • CVE-2022-46314HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-44552HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.00

    The lock screen module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-32589HigOct 7, 2022
    risk 0.49cvss 7.5epss 0.01

    In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07030600; Issue ID:…

  • CVE-2022-40890HigSep 29, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.

  • CVE-2022-37133HigAug 22, 2022
    risk 0.49cvss 7.5epss 0.01

    D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end.

  • CVE-2022-35272HigAug 4, 2022
    risk 0.49cvss 7.5epss 0.00

    In BIG-IP Versions 17.0.x before 17.0.0.1 and 16.1.x before 16.1.3.1, when source-port preserve-strict is configured on an HTTP Message Routing Framework (MRF) virtual server, undisclosed traffic may cause the Traffic Management Microkernel (TMM) to produce a core file and the…

  • CVE-2022-35240HigAug 4, 2022
    risk 0.49cvss 7.5epss 0.01

    In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when the Message Routing (MR) Message Queuing Telemetry Transport (MQTT) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource…

  • CVE-2022-2191HigJul 7, 2022
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.

  • CVE-2022-1473HigMay 3, 2022
    risk 0.49cvss 7.5epss 0.03

    The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys…