CWE-664
Improper Control of a Resource Through its Lifetime
Description
The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-196 · CAPEC-21 · CAPEC-60 · CAPEC-61 · CAPEC-62
CVEs mapped to this weakness (54)
page 2 of 3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-18549 | Hig | 0.42 | 7.5 | 0.01 | Aug 15, 2026 | @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the… | ||
| CVE-2024-41169 | Hig | 0.42 | 7.5 | 0.01 | Jul 12, 2025 | The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes… | ||
| CVE-2025-21593 | Med | 0.42 | 6.5 | 0.00 | Jan 9, 2025 | An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS). On devices with SRv6 (Segment Routing… | ||
| CVE-2024-37139 | Med | 0.42 | 6.5 | 0.00 | Jun 26, 2024 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a Resource Through its Lifetime vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to… | ||
| CVE-2023-25942 | Med | 0.42 | 6.5 | 0.01 | Apr 4, 2023 | Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious network user with low privileges could potentially exploit this vulnerability in SMB, leading to a potential denial of service. | ||
| CVE-2022-28287 | Med | 0.42 | 6.5 | 0.01 | Dec 22, 2022 | In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. This vulnerability affects Firefox < 99. | ||
| CVE-2022-46144 | Med | 0.42 | 6.5 | 0.01 | Dec 13, 2022 | A vulnerability has been identified in SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions < V2.3), SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions >= V2.3 < V3.0), SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (All versions < V2.3), SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (All… | ||
| CVE-2022-22250 | Med | 0.42 | 6.5 | 0.00 | Oct 18, 2022 | An Improper Control of a Resource Through its Lifetime vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows unauthenticated adjacent attacker to cause a Denial of Service (DoS). In an EVPN-MPLS scenario, if MAC is learned… | ||
| CVE-2022-22249 | Med | 0.42 | 6.5 | 0.00 | Oct 18, 2022 | An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When there is a continuous mac move a memory… | ||
| CVE-2023-44295 | Med | 0.41 | 6.3 | 0.00 | Dec 5, 2023 | Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure. | ||
| CVE-2025-54613 | Med | 0.38 | 5.9 | 0.00 | Aug 6, 2025 | Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2025-54612 | Med | 0.38 | 5.9 | 0.00 | Aug 6, 2025 | Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2026-64721 | Med | 0.36 | 5.5 | 0.00 | Jul 27, 2026 | This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access… | ||
| CVE-2024-22365 | Med | 0.36 | 5.5 | 0.00 | Feb 6, 2024 | linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY. | ||
| CVE-2020-1622 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2020 | A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1. | ||
| CVE-2020-1621 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2020 | A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1. | ||
| CVE-2020-1620 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2020 | A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1. | ||
| CVE-2022-31153 | Med | 0.35 | 6.5 | 0.01 | Jul 15, 2022 | OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue affects all accounts (vanilla and… | ||
| CVE-2022-27512 | Med | 0.35 | 5.3 | 0.01 | Jun 16, 2022 | Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM. | ||
| CVE-2022-20748 | Med | 0.35 | 5.3 | 0.01 | May 3, 2022 | A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to insufficient error handling in… |
- risk 0.42cvss 7.5epss 0.01
@fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the…
- risk 0.42cvss 7.5epss 0.01
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes…
- risk 0.42cvss 6.5epss 0.00
An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS). On devices with SRv6 (Segment Routing…
- risk 0.42cvss 6.5epss 0.00
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a Resource Through its Lifetime vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to…
- risk 0.42cvss 6.5epss 0.01
Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious network user with low privileges could potentially exploit this vulnerability in SMB, leading to a potential denial of service.
- risk 0.42cvss 6.5epss 0.01
In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. This vulnerability affects Firefox < 99.
- risk 0.42cvss 6.5epss 0.01
A vulnerability has been identified in SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions < V2.3), SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions >= V2.3 < V3.0), SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (All versions < V2.3), SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (All…
- risk 0.42cvss 6.5epss 0.00
An Improper Control of a Resource Through its Lifetime vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows unauthenticated adjacent attacker to cause a Denial of Service (DoS). In an EVPN-MPLS scenario, if MAC is learned…
- risk 0.42cvss 6.5epss 0.00
An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When there is a continuous mac move a memory…
- risk 0.41cvss 6.3epss 0.00
Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure.
- risk 0.38cvss 5.9epss 0.00
Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.38cvss 5.9epss 0.00
Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.36cvss 5.5epss 0.00
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access…
- risk 0.36cvss 5.5epss 0.00
linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.
- risk 0.36cvss 5.5epss 0.00
A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1.
- risk 0.36cvss 5.5epss 0.00
A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
- risk 0.36cvss 5.5epss 0.00
A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
- risk 0.35cvss 6.5epss 0.01
OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue affects all accounts (vanilla and…
- risk 0.35cvss 5.3epss 0.01
Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.
- risk 0.35cvss 5.3epss 0.01
A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to insufficient error handling in…