VYPR

CWE-664

Improper Control of a Resource Through its Lifetime

PillarDraft

Description

The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-60 · CAPEC-61 · CAPEC-62

CVEs mapped to this weakness (46)

page 1 of 3
  • CVE-2022-27518CriKEVDec 13, 2022
    risk 0.76cvss 9.8epss 0.07

    Unauthenticated remote arbitrary code execution

  • CVE-2026-8517HigMay 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2019-5816HigJun 27, 2019
    risk 0.57cvss 8.8epss 0.02

    Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.

  • CVE-2026-20269HigAug 5, 2026
    risk 0.56cvss 8.6epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…

  • CVE-2022-20856HigSep 30, 2022
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS)…

  • CVE-2020-3175HigFeb 26, 2020
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the resource handling system of Cisco NX-OS Software for Cisco MDS 9000 Series Multilayer Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper resource…

  • CVE-2016-8763HigApr 2, 2017
    risk 0.51cvss 7.8epss 0.01

    The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier versions and P8 Lite with software ALE-L02C636B150 and earlier versions has an improper resource release vulnerability, which allows…

  • CVE-2026-43503HigMay 23, 2026
    risk 0.50cvss 8.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when…

  • CVE-2026-20158HigJul 15, 2026
    risk 0.49cvss 7.5epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…

  • CVE-2023-52387HigFeb 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-44288HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2022-32846HigFeb 27, 2023
    risk 0.49cvss 7.5epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sensitive data.

  • CVE-2022-2191HigJul 7, 2022
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.

  • CVE-2022-2048HigJul 7, 2022
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no…

  • CVE-2024-7889HigSep 11, 2024
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

  • CVE-2025-34226HigOct 3, 2025
    risk 0.46cvss epss 0.01

    OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be crafted to induce corruption of the programs database. After a successful malformed upload the runtime…

  • CVE-2024-41169HigJul 12, 2025
    risk 0.42cvss 7.5epss 0.01

    The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes…

  • CVE-2025-21593MedJan 9, 2025
    risk 0.42cvss 6.5epss 0.00

    An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS). On devices with SRv6 (Segment Routing…

  • CVE-2024-37139MedJun 26, 2024
    risk 0.42cvss 6.5epss 0.00

    Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a Resource Through its Lifetime vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to…

  • CVE-2023-25942MedApr 4, 2023
    risk 0.42cvss 6.5epss 0.01

    Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious network user with low privileges could potentially exploit this vulnerability in SMB, leading to a potential denial of service.