VYPR

CWE-460

Improper Cleanup on Thrown Exception

BaseDraftLikelihood: Medium

Description

The product does not clean up its state or incorrectly cleans up its state when an exception is thrown, leading to unexpected state or control flow.

Often, when functions or loops become complicated, some level of resource cleanup is needed throughout execution. Exceptions can disturb the flow of the code and prevent the necessary cleanup from happening.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (26)

page 1 of 2
  • CVE-2022-22150HigFeb 4, 2022
    risk 0.57cvss 8.8epss 0.02

    A memory corruption vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. A specially-crafted PDF document can trigger an exception which is improperly handled, leaving the engine in an invalid state, which can lead to memory…

  • CVE-2025-31650HigApr 28, 2025
    risk 0.50cvss 7.5epss 0.60

    Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException…

  • CVE-2025-43855HigApr 24, 2025
    risk 0.50cvss epss 0.00

    tRPC allows users to build & consume fully typesafe APIs without schemas or code generation. In versions starting from 11.0.0 to before 11.1.1, an unhandled error is thrown when validating invalid connectionParams which crashes a tRPC WebSocket server. This allows any…

  • CVE-2023-46393HigOct 27, 2023
    risk 0.49cvss 7.5epss 0.00

    gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet.

  • CVE-2026-40583HigApr 21, 2026
    risk 0.46cvss 8.2epss 0.00

    UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance prechecks, but fails authorization only after state mutation has already occurred.

  • CVE-2026-20118MedMar 11, 2026
    risk 0.44cvss 6.8epss 0.00

    A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series with NC57 line cards and Cisco NCS 5700 Routers and Cisco IOS XR Software for Third Party Software could…

  • CVE-2024-0316MedJan 15, 2024
    risk 0.44cvss 6.8epss 0.00

    Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to send multiple request packets to the containment_notify/preview parameter, which could lead to a service outage.

  • CVE-2021-34716MedAug 18, 2021
    risk 0.44cvss 6.7epss 0.02

    A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as the root user. This…

  • CVE-2026-61387HigAug 4, 2026
    risk 0.42cvss 7.5epss 0.00

    In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. Deeply nested PubSub ExtensionObjects in a `CreateMonitoredItems` event filter can…

  • CVE-2017-9657MedApr 30, 2018
    risk 0.42cvss 6.5epss 0.01

    Under specific 802.11 network conditions, a partial re-association of the Philips IntelliVue MX40 Version B.06.18 WLAN monitor to the central monitoring station is possible. In this state, the central monitoring station can indicate the MX40 is not connected or associated to the…

  • CVE-2025-69652MedMar 6, 2026
    risk 0.40cvss 6.2epss 0.00

    GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate…

  • CVE-2022-3707MedMar 6, 2023
    risk 0.36cvss 5.5epss 0.00

    A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload, causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a local user to crash the system.

  • CVE-2025-32439MedApr 15, 2025
    risk 0.35cvss 6.5epss 0.00

    pleezer is a headless Deezer Connect player. Hook scripts in pleezer can be triggered by various events like track changes and playback state changes. In versions before 0.16.0, these scripts were spawned without proper process cleanup, leaving zombie processes in the system's…

  • CVE-2025-30157MedMar 21, 2025
    risk 0.35cvss 6.5epss 0.00

    Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a local reply is sent to the external server due to the filter's life time issue. A known situation is the…

  • CVE-2019-14891MedNov 25, 2019
    risk 0.33cvss 5.0epss 0.01

    A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could…

  • CVE-2024-12289MedDec 12, 2024
    risk 0.31cvss 5.9epss 0.00

    Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the…

  • CVE-2024-20354MedMar 27, 2024
    risk 0.31cvss 4.7epss 0.00

    A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of…

  • CVE-2020-35923MedDec 31, 2020
    risk 0.29cvss 5.5epss 0.00

    An issue was discovered in the ordered-float crate before 1.1.1 and 2.x before 2.0.1 for Rust. A NotNan value can contain a NaN.

  • CVE-2020-14304MedSep 15, 2020
    risk 0.29cvss 4.4epss 0.00

    A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of the device. This flaw allows a local user to read uninitialized values from the kernel memory. The highest threat from this vulnerability is to confidentiality.

  • CVE-2016-9592MedApr 16, 2018
    risk 0.28cvss 4.3epss 0.01

    openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation to fail with 'VolumeInUse' error. Since the delete operation is retried every 30 seconds for each volume, this could lead to a denial of…