CWE-664
Improper Control of a Resource Through its Lifetime
Description
The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-196 · CAPEC-21 · CAPEC-60 · CAPEC-61 · CAPEC-62
CVEs mapped to this weakness (46)
page 2 of 3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-28287 | Med | 0.42 | 6.5 | 0.01 | Dec 22, 2022 | In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. This vulnerability affects Firefox < 99. | ||
| CVE-2022-46144 | Med | 0.42 | 6.5 | 0.01 | Dec 13, 2022 | A vulnerability has been identified in SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions < V2.3), SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions >= V2.3 < V3.0), SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (All versions < V2.3), SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (All… | ||
| CVE-2022-22250 | Med | 0.42 | 6.5 | 0.00 | Oct 18, 2022 | An Improper Control of a Resource Through its Lifetime vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows unauthenticated adjacent attacker to cause a Denial of Service (DoS). In an EVPN-MPLS scenario, if MAC is learned… | ||
| CVE-2022-22249 | Med | 0.42 | 6.5 | 0.00 | Oct 18, 2022 | An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When there is a continuous mac move a memory… | ||
| CVE-2023-44295 | Med | 0.41 | 6.3 | 0.00 | Dec 5, 2023 | Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure. | ||
| CVE-2025-54613 | Med | 0.38 | 5.9 | 0.00 | Aug 6, 2025 | Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2025-54612 | Med | 0.38 | 5.9 | 0.00 | Aug 6, 2025 | Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2024-22365 | Med | 0.36 | 5.5 | 0.00 | Feb 6, 2024 | linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY. | ||
| CVE-2020-1622 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2020 | A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1. | ||
| CVE-2020-1621 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2020 | A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1. | ||
| CVE-2020-1620 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2020 | A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1. | ||
| CVE-2022-31153 | Med | 0.35 | 6.5 | 0.01 | Jul 15, 2022 | OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue affects all accounts (vanilla and… | ||
| CVE-2022-27512 | Med | 0.35 | 5.3 | 0.01 | Jun 16, 2022 | Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM. | ||
| CVE-2022-20748 | Med | 0.35 | 5.3 | 0.01 | May 3, 2022 | A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to insufficient error handling in… | ||
| CVE-2026-8582 | Med | 0.34 | 5.3 | 0.00 | May 14, 2026 | Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2025-54621 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2025 | Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures. | ||
| CVE-2025-54619 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2025 | Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability. | ||
| CVE-2024-45383 | Med | 0.33 | 5.0 | 0.02 | Sep 12, 2024 | A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests which leads to a local… | ||
| CVE-2019-16779 | Med | 0.31 | 5.8 | 0.01 | Dec 16, 2019 | In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response.… | ||
| CVE-2020-36774 | Med | 0.29 | 5.5 | 0.00 | Feb 19, 2024 | plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash). |
- risk 0.42cvss 6.5epss 0.01
In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. This vulnerability affects Firefox < 99.
- risk 0.42cvss 6.5epss 0.01
A vulnerability has been identified in SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions < V2.3), SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions >= V2.3 < V3.0), SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (All versions < V2.3), SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (All…
- risk 0.42cvss 6.5epss 0.00
An Improper Control of a Resource Through its Lifetime vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows unauthenticated adjacent attacker to cause a Denial of Service (DoS). In an EVPN-MPLS scenario, if MAC is learned…
- risk 0.42cvss 6.5epss 0.00
An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When there is a continuous mac move a memory…
- risk 0.41cvss 6.3epss 0.00
Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure.
- risk 0.38cvss 5.9epss 0.00
Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.38cvss 5.9epss 0.00
Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.36cvss 5.5epss 0.00
linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.
- risk 0.36cvss 5.5epss 0.00
A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1.
- risk 0.36cvss 5.5epss 0.00
A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
- risk 0.36cvss 5.5epss 0.00
A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
- risk 0.35cvss 6.5epss 0.01
OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue affects all accounts (vanilla and…
- risk 0.35cvss 5.3epss 0.01
Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.
- risk 0.35cvss 5.3epss 0.01
A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to insufficient error handling in…
- risk 0.34cvss 5.3epss 0.00
Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.34cvss 5.3epss 0.00
Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures.
- risk 0.34cvss 5.3epss 0.00
Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability.
- risk 0.33cvss 5.0epss 0.02
A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests which leads to a local…
- risk 0.31cvss 5.8epss 0.01
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response.…
- risk 0.29cvss 5.5epss 0.00
plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).