CWE-664
Improper Control of a Resource Through its Lifetime
Description
The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-196 · CAPEC-21 · CAPEC-60 · CAPEC-61 · CAPEC-62
CVEs mapped to this weakness (54)
page 1 of 3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27518 | Cri | 0.76 | 9.8 | 0.07 | KEV | Dec 13, 2022 | Unauthenticated remote arbitrary code execution | |
| CVE-2026-20353 | Cri | 0.64 | 9.8 | 0.00 | Sep 14, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases… | ||
| CVE-2026-20274 | Cri | 0.64 | 9.8 | 0.01 | Sep 2, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered… | ||
| CVE-2026-20336 | Hig | 0.57 | 8.8 | 0.00 | Sep 16, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a… | ||
| CVE-2026-8517 | Hig | 0.57 | 8.8 | 0.01 | May 14, 2026 | Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2019-5816 | Hig | 0.57 | 8.8 | 0.02 | Jun 27, 2019 | Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page. | ||
| CVE-2026-20269 | Hig | 0.56 | 8.6 | 0.00 | Aug 5, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | ||
| CVE-2022-20856 | Hig | 0.56 | 8.6 | 0.01 | Sep 30, 2022 | A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS)… | ||
| CVE-2020-3175 | Hig | 0.56 | 8.6 | 0.02 | Feb 26, 2020 | A vulnerability in the resource handling system of Cisco NX-OS Software for Cisco MDS 9000 Series Multilayer Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper resource… | ||
| CVE-2016-8763 | Hig | 0.51 | 7.8 | 0.01 | Apr 2, 2017 | The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier versions and P8 Lite with software ALE-L02C636B150 and earlier versions has an improper resource release vulnerability, which allows… | ||
| CVE-2026-54251 | Hig | 0.50 | — | 0.01 | Sep 15, 2026 | netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP gateway decryption path in codec-ohttp/src/main/java/io/netty/incubator/codec/ohttp/OHttpRequestResponseContext.java allocates a pooled… | ||
| CVE-2026-43503 | Hig | 0.50 | 8.8 | 0.00 | May 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when… | ||
| CVE-2026-20158 | Hig | 0.49 | 7.5 | 0.00 | Jul 15, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered… | ||
| CVE-2023-52387 | Hig | 0.49 | 7.5 | 0.00 | Feb 18, 2024 | Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-44288 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, leading to denial of service. | ||
| CVE-2022-32846 | Hig | 0.49 | 7.5 | 0.01 | Feb 27, 2023 | A logic issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sensitive data. | ||
| CVE-2022-2191 | Hig | 0.49 | 7.5 | 0.02 | Jul 7, 2022 | In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths. | ||
| CVE-2022-2048 | Hig | 0.49 | 7.5 | 0.03 | Jul 7, 2022 | In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no… | ||
| CVE-2024-7889 | Hig | 0.47 | 7.3 | 0.00 | Sep 11, 2024 | Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | ||
| CVE-2025-34226 | Hig | 0.46 | — | 0.01 | Oct 3, 2025 | OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be crafted to induce corruption of the programs database. After a successful malformed upload the runtime… |
- risk 0.76cvss 9.8epss 0.07
Unauthenticated remote arbitrary code execution
- risk 0.64cvss 9.8epss 0.00
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases…
- risk 0.64cvss 9.8epss 0.01
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered…
- risk 0.57cvss 8.8epss 0.00
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a…
- risk 0.57cvss 8.8epss 0.01
Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.57cvss 8.8epss 0.02
Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.
- risk 0.56cvss 8.6epss 0.00
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
- risk 0.56cvss 8.6epss 0.01
A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS)…
- risk 0.56cvss 8.6epss 0.02
A vulnerability in the resource handling system of Cisco NX-OS Software for Cisco MDS 9000 Series Multilayer Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper resource…
- risk 0.51cvss 7.8epss 0.01
The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier versions and P8 Lite with software ALE-L02C636B150 and earlier versions has an improper resource release vulnerability, which allows…
- risk 0.50cvss —epss 0.01
netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP gateway decryption path in codec-ohttp/src/main/java/io/netty/incubator/codec/ohttp/OHttpRequestResponseContext.java allocates a pooled…
- risk 0.50cvss 8.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when…
- risk 0.49cvss 7.5epss 0.00
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…
- risk 0.49cvss 7.5epss 0.00
Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.01
Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, leading to denial of service.
- risk 0.49cvss 7.5epss 0.01
A logic issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sensitive data.
- risk 0.49cvss 7.5epss 0.02
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.
- risk 0.49cvss 7.5epss 0.03
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no…
- risk 0.47cvss 7.3epss 0.00
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
- risk 0.46cvss —epss 0.01
OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be crafted to induce corruption of the programs database. After a successful malformed upload the runtime…