VYPR

CWE-459

Incomplete Cleanup

BaseDraft

Description

The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

Hierarchy (View 1000)

CVEs mapped to this weakness (222)

page 8 of 12
  • CVE-2023-28859MedMar 26, 2023
    risk 0.35cvss 6.5epss 0.01

    redis-py before 4.4.4 and 4.5.x before 4.5.4 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request. (This could, for example, happen for a non-pipeline operation.) NOTE: the…

  • CVE-2022-27639MedNov 11, 2022
    risk 0.35cvss 5.4epss 0.00

    Incomplete cleanup in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via adjacent access.

  • CVE-2019-20850MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.

  • CVE-2019-20849MedJun 19, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.

  • CVE-2020-12494MedJun 16, 2020
    risk 0.35cvss 5.3epss 0.01

    Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their…

  • CVE-2019-8768MedDec 18, 2019
    risk 0.35cvss 5.3epss 0.02

    "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Catalina 10.15. A user may be unable to delete browsing history items.

  • CVE-2026-79265MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-77761MedAug 21, 2026
    risk 0.34cvss —epss 0.00

    A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into the MISP event generated from a subsequent document when the same parser instance is reused. Several STIX 1 and STIX 2 parser…

  • CVE-2025-29934MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss of data integrity.

  • CVE-2025-20293MedSep 24, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an unauthenticated, remote attacker to access the public-key infrastructure (PKI) server that is running on an affected device. …

  • CVE-2024-23672MedMar 13, 2024
    risk 0.34cvss 6.3epss 0.02

    Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through…

  • CVE-2020-24458MedFeb 17, 2021
    risk 0.34cvss 5.2epss 0.00

    Incomplete cleanup in some Intel(R) PROSet/Wireless WiFi and Killer (TM) drivers before version 22.0 may allow a privileged user to potentially enable information disclosure and denial of service via adjacent access.

  • CVE-2021-32571MedOct 14, 2021
    risk 0.32cvss 4.9epss 0.01

    In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and passwords are left in the system undeleted but in folders accessible by top privileged accounts only. NOTE: This vulnerability only affects products that are no…

  • CVE-2019-3733MedSep 30, 2019
    risk 0.32cvss 4.9epss 0.01

    RSA BSAFE Crypto-C Micro Edition, all versions prior to 4.1.4, is vulnerable to three (3) different Improper Clearing of Heap Memory Before Release vulnerability, also known as 'Heap Inspection vulnerability'. A malicious remote user could potentially exploit this vulnerability…

  • CVE-2026-19019MedAug 6, 2026
    risk 0.31cvss 4.8epss 0.00

    A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_session_persistence of the file executor/app/core/workspace.py of the component Claude File Handler. The manipulation results in incomplete cleanup. The attack…

  • CVE-2024-36952MedMay 30, 2024
    risk 0.31cvss 4.7epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Move NPIV's transport unregistration to after resource clean up There are cases after NPIV deletion where the fabric switch still believes the NPIV is logged into the fabric. This occurs when a…

  • CVE-2024-26005MedMar 12, 2024
    risk 0.31cvss 4.8epss 0.01

    An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS. 

  • CVE-2026-0427MedMay 15, 2026
    risk 0.30cvss —epss 0.00

    Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virtual machine (VM) to access these shared resources from another Guest VM, potentially resulting in the loss of confidentiality, integrity, or availability.

  • CVE-2022-23035MedJan 25, 2022
    risk 0.30cvss 4.6epss 0.00

    Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical devices exposed to x86 HVM guests involves an iterative operation in particular when cleaning up after the guest's use of the device. In the case where an interrupt is not…

  • CVE-2019-1586MedMay 3, 2019
    risk 0.30cvss 4.6epss 0.00

    A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The vulnerability is due to insecure removal of cleartext encryption…