VYPR

CWE-664

Improper Control of a Resource Through its Lifetime

PillarDraft

Description

The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-196 · CAPEC-21 · CAPEC-60 · CAPEC-61 · CAPEC-62

CVEs mapped to this weakness (54)

page 3 of 3
  • CVE-2026-8582MedMay 14, 2026
    risk 0.34cvss 5.3epss 0.00

    Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2025-54621MedAug 6, 2025
    risk 0.34cvss 5.3epss 0.00

    Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures.

  • CVE-2025-54619MedAug 6, 2025
    risk 0.34cvss 5.3epss 0.00

    Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability.

  • CVE-2024-45383MedSep 12, 2024
    risk 0.33cvss 5.0epss 0.02

    A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests which leads to a local…

  • CVE-2019-16779MedDec 16, 2019
    risk 0.31cvss 5.8epss 0.01

    In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response.…

  • CVE-2020-36774MedFeb 19, 2024
    risk 0.29cvss 5.5epss 0.00

    plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).

  • CVE-2021-1592MedAug 25, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management for established SSH sessions. An…

  • CVE-2024-23639MedFeb 9, 2024
    risk 0.26cvss 5.1epss 0.00

    Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support for Java, Kotlin and the Groovy language. Enabled but unsecured management endpoints are susceptible to drive-by localhost attacks.…

  • CVE-2022-1385LowApr 19, 2022
    risk 0.24cvss 3.7epss 0.01

    Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public teams and channels.

  • CVE-2026-79603MedSep 8, 2026
    risk 0.21cvss 4.3epss 0.00

    x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush, there's a window where a PV guest can…

  • CVE-2020-3504LowAug 27, 2020
    risk 0.21cvss 3.3epss 0.00

    A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of CLI command parameters. An…

  • CVE-2026-79289LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-86203LowSep 9, 2026
    risk 0.17cvss 3.7epss 0.00

    PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing inventory items and experience to drop…

  • CVE-2026-19380LowAug 10, 2026
    risk 0.15cvss 2.3epss 0.00

    A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local access is required to approach this attack. The exploit is…