CWE-459
Incomplete Cleanup
Description
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
Hierarchy (View 1000)
CVEs mapped to this weakness (222)
page 5 of 12| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-38275 | Hig | 0.42 | 7.5 | 0.00 | Jun 18, 2024 | The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs. | ||
| CVE-2024-21617 | Med | 0.42 | 6.5 | 0.00 | Jan 12, 2024 | An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause memory leak leading to Denial of Service (DoS). On all Junos OS platforms, when NSR is enabled, a BGP flap will… | ||
| CVE-2023-41835 | Hig | 0.42 | 7.5 | 0.08 | Dec 5, 2023 | When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts… | ||
| CVE-2023-22407 | Med | 0.42 | 6.5 | 0.00 | Jan 13, 2023 | An Incomplete Cleanup vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). An rpd crash can occur when an MPLS TE tunnel configuration change occurs… | ||
| CVE-2022-37428 | Med | 0.42 | 6.5 | 0.01 | Aug 23, 2022 | PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties. | ||
| CVE-2020-13346 | Med | 0.42 | 6.5 | 0.01 | Oct 7, 2020 | Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API. | ||
| CVE-2020-12414 | Med | 0.42 | 6.5 | 0.01 | Jul 9, 2020 | IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affects Firefox for iOS < 27. | ||
| CVE-2020-12624 | Med | 0.42 | 6.5 | 0.01 | May 3, 2020 | The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary web site that hosts an external image because an OkHttp object is reused, which allows remote attackers to hijack sessions. | ||
| CVE-2020-6794 | Med | 0.42 | 6.5 | 0.01 | Mar 2, 2020 | If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60.… | ||
| CVE-2019-12902 | Med | 0.42 | 6.5 | 0.01 | Jun 20, 2019 | Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data. | ||
| CVE-2019-11514 | Hig | 0.42 | 7.5 | 0.01 | Apr 25, 2019 | User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens. | ||
| CVE-2026-72714 | Med | 0.41 | 6.3 | 0.00 | Aug 24, 2026 | Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local Unset Universe Checking inside a module is expected to last only until the module ends, and the global flag is restored, but the… | ||
| CVE-2025-55910 | Med | 0.41 | 6.3 | 0.00 | Sep 19, 2025 | CMSEasy v7.7.8.0 and before is vulnerable to Arbitrary file deletion in database_admin.php. | ||
| CVE-2023-20862 | Med | 0.41 | 6.3 | 0.01 | Apr 19, 2023 | In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty… | ||
| CVE-2022-25664 | Med | 0.40 | 6.2 | 0.00 | Oct 19, 2022 | Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2000-0552 | Med | 0.39 | 5.5 | 0.01 | Jun 6, 2000 | ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information. | ||
| CVE-2024-2403 | Med | 0.38 | 5.9 | 0.00 | Mar 13, 2024 | Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attacker that compromised a user endpoint, under specific circumstances, to access sensitive information via residual files in the temporary… | ||
| CVE-2023-42794 | Med | 0.38 | 5.9 | 0.02 | Oct 10, 2023 | Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a… | ||
| CVE-2021-26833 | Med | 0.38 | 5.9 | 0.01 | Apr 6, 2021 | Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attacker who can locally read user's files obtain JWT tokens for user's account due to insufficient cache clearing mechanisms. A threat actor can obtain sensitive… | ||
| CVE-2026-68809 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. |
- risk 0.42cvss 7.5epss 0.00
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
- risk 0.42cvss 6.5epss 0.00
An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause memory leak leading to Denial of Service (DoS). On all Junos OS platforms, when NSR is enabled, a BGP flap will…
- risk 0.42cvss 7.5epss 0.08
When a Multipart request is performed but some of the fields exceed the maxStringLength limit, the upload files will remain in struts.multipart.saveDir even if the request has been denied. Users are recommended to upgrade to versions Struts 2.5.32 or 6.1.2.2 or Struts…
- risk 0.42cvss 6.5epss 0.00
An Incomplete Cleanup vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). An rpd crash can occur when an MPLS TE tunnel configuration change occurs…
- risk 0.42cvss 6.5epss 0.01
PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties.
- risk 0.42cvss 6.5epss 0.01
Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
- risk 0.42cvss 6.5epss 0.01
IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affects Firefox for iOS < 27.
- risk 0.42cvss 6.5epss 0.01
The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary web site that hosts an external image because an OkHttp object is reused, which allows remote attackers to hijack sessions.
- risk 0.42cvss 6.5epss 0.01
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60.…
- risk 0.42cvss 6.5epss 0.01
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data.
- risk 0.42cvss 7.5epss 0.01
User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens.
- risk 0.41cvss 6.3epss 0.00
Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local Unset Universe Checking inside a module is expected to last only until the module ends, and the global flag is restored, but the…
- risk 0.41cvss 6.3epss 0.00
CMSEasy v7.7.8.0 and before is vulnerable to Arbitrary file deletion in database_admin.php.
- risk 0.41cvss 6.3epss 0.01
In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty…
- risk 0.40cvss 6.2epss 0.00
Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.39cvss 5.5epss 0.01
ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information.
- risk 0.38cvss 5.9epss 0.00
Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attacker that compromised a user endpoint, under specific circumstances, to access sensitive information via residual files in the temporary…
- risk 0.38cvss 5.9epss 0.02
Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a…
- risk 0.38cvss 5.9epss 0.01
Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attacker who can locally read user's files obtain JWT tokens for user's account due to insufficient cache clearing mechanisms. A threat actor can obtain sensitive…
- risk 0.36cvss 5.5epss 0.00
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.