VYPR

CWE-664

Improper Control of a Resource Through its Lifetime

PillarDraft

Description

The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-60 · CAPEC-61 · CAPEC-62

CVEs mapped to this weakness (46)

page 3 of 3
  • CVE-2021-1592MedAug 25, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management for established SSH sessions. An…

  • CVE-2024-23639MedFeb 9, 2024
    risk 0.26cvss 5.1epss 0.00

    Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support for Java, Kotlin and the Groovy language. Enabled but unsecured management endpoints are susceptible to drive-by localhost attacks.…

  • CVE-2022-1385LowApr 19, 2022
    risk 0.24cvss 3.7epss 0.01

    Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels.

  • CVE-2020-3504LowAug 27, 2020
    risk 0.21cvss 3.3epss 0.00

    A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of CLI command parameters. An…

  • CVE-2026-19380LowAug 10, 2026
    risk 0.15cvss 2.3epss 0.00

    A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local access is required to approach this attack. The exploit is…

  • CVE-2026-64721MedJul 27, 2026
    risk 0.00cvss 5.5epss 0.00

    This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.