VYPR

CWE-491

Public cloneable() Method Without Final ('Object Hijack')

VariantDraft

Description

A class has a cloneable() method that is not declared final, which allows an object to be created without calling the constructor. This can cause the object to be in an unexpected state.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (4)

  • CVE-2025-63685CriNov 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in…

  • CVE-2025-60425HigOct 27, 2025
    risk 0.56cvss 8.6epss 0.01

    Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.

  • CVE-2024-39069HigJul 9, 2024
    risk 0.51cvss 7.8epss 0.01

    An issue in ifood Order Manager v3.35.5 'Gestor de Peddios.exe' allows attackers to execute arbitrary code via a DLL hijacking attack.

  • CVE-2025-55622MedAug 22, 2025
    risk 0.42cvss 6.5epss 0.00

    Reolink v4.54.0.4.20250526 was discovered to contain a task hijacking vulnerability due to inappropriate taskAffinity settings. NOTE: this is disputed by the Supplier because it is intentional behavior to ensure a predictable user experience.