CWE-404— Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.— MITRE CWE catalog
758 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-404page 4 of 16
- CVE-2021-38623HIGHCVSS 7.5EG 7.52021-08-13
The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service via the FAL API because of /var/transient disk consumption.
- CVE-2021-40122MEDIUMCVSS 5.9EG 5.92021-10-21
A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling of large series of me…
- CVE-2021-40405MEDIUMCVSS 6.5EG 6.52022-04-14
A denial of service vulnerability exists in the cgiserver.cgi Upgrade API functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vu…
- CVE-2021-40546MEDIUMCVSS 4.9EG 4.92023-09-05
Tenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin allows attackers (who have the administrator password) to cause a denial of service (device crash) via a long string in the wifiPwd_5G parameter to /goform/setWifi.
- CVE-2021-40833MEDIUMCVSS 5.5EG 5.52021-11-26
A vulnerability affecting F-Secure antivirus engine was discovered whereby unpacking UPX file can lead to denial-of-service. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service o…
- CVE-2021-41441HIGHCVSS 7.4EG 7.42022-02-09
A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated victim. The authenticated victim need to v…
- CVE-2021-4247HIGHCVSS 4.3EG 7.52022-12-18
A vulnerability has been found in OWASP NodeGoat and classified as problematic. This vulnerability affects unknown code of the file app/routes/research.js of the component Query Parameter Handler. The manipulation leads to denial of servic…
- CVE-2021-4249HIGHCVSS 4.3EG 7.52022-12-18
A vulnerability was found in xml-conduit. It has been classified as problematic. Affected is an unknown function of the file xml-conduit/src/Text/XML/Stream/Parse.hs of the component DOCTYPE Entity Expansion Handler. The manipulation leads…
- CVE-2021-4250LOWCVSS 3.5EG 3.52022-12-18
A vulnerability classified as problematic has been found in cgriego active_attr up to 0.15.2. This affects the function call of the file lib/active_attr/typecasting/boolean_typecaster.rb of the component Regex Handler. The manipulation of …
- CVE-2021-4280MEDIUMCVSS 4.3EG 6.52022-12-25
A vulnerability was found in styler_praat_scripts. It has been classified as problematic. Affected is an unknown function of the file file_segmenter.praat of the component Slash Handler. The manipulation leads to denial of service. It is p…
- CVE-2021-43611HIGHCVSS 7.5EG 7.52021-11-12
Belledonne Belle-sip before 5.0.20 can crash applications such as Linphone via " \ " in the display name of a From header.
- CVE-2021-4432MEDIUMCVSS 5.3EG 5.32024-01-16
A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as problematic. This affects an unknown part of the component USER Command Handler. The manipulation leads to denial of service. It is possible to initiate the att…
- CVE-2021-4433MEDIUMCVSS 5.3EG 5.32024-01-18
A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP HEAD Rrequest Handler. The manipulation leads to denial of service. It is possible to…
- CVE-2021-44717MEDIUMCVSS 4.8EG 4.82022-01-01
Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network connection as a consequence of erroneous closing of file descriptor 0 after file-descriptor exhaustion.
- CVE-2021-45829MEDIUMCVSS 5.5EG 5.52022-01-03
HDF5 1.13.1-1 is affected by: segmentation fault, which causes a Denial of Service.
- CVE-2021-46322MEDIUMCVSS 5.5EG 5.52022-01-20
Duktape v2.99.99 was discovered to contain a SEGV vulnerability via the component duk_push_tval in duktape/duk_api_stack.c.
- CVE-2021-46702MEDIUMCVSS 5.5EG 5.52022-02-26
Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to bypass the intended anonymity feature and obtain information regarding the onion services visited by a local user. Thi…
- CVE-2022-0396MEDIUMCVSS 5.3EG 5.32022-03-23
BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period o…
- CVE-2022-1210MEDIUMCVSS 4.3EG 6.52022-04-03
A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requir…
- CVE-2022-1289MEDIUMCVSS 4.3EG 6.52022-04-10
A denial of service vulnerability was found in tildearrow Furnace. It has been classified as problematic. This is due to an incomplete fix of CVE-2022-1211. It is possible to initiate the attack remotely but it requires user interaction. T…
- CVE-2022-2191HIGHCVSS 7.5EG 7.52022-07-07
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.
- CVE-2022-23010HIGHCVSS 7.5EG 7.52022-01-25
On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile and an HTTP profile are configured on a virtual server, undisclosed requests can c…
- CVE-2022-23033HIGHCVSS 7.8EG 7.82022-01-25
arm: guest_physmap_remove_page not removing the p2m mappings The functions to remove one or more entries from a guest p2m pagetable on Arm (p2m_remove_mapping, guest_physmap_remove_page, and p2m_set_entry with mfn set to INVALID_MFN) do no…
- CVE-2022-23242MEDIUMCVSS 6.3EG 6.32022-03-23
TeamViewer Linux versions before 15.28 do not properly execute a deletion command for the connection password in case of a process crash. Knowledge of the crash event and the TeamViewer ID as well as either possession of the pre-crash conn…
- CVE-2022-23634HIGHCVSS 8.0EG 8.02022-02-11
Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being closed in order for its …
- CVE-2022-23717MEDIUMCVSS 5.0EG 5.52022-06-30
PingID Windows Login prior to 2.8 is vulnerable to a denial of service condition on local machines when combined with using offline security keys as part of authentication.
- CVE-2022-25762HIGHCVSS 8.6EG 8.62022-05-13
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use t…
- CVE-2022-2591HIGHCVSS 7.5EG 7.52022-08-01
A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0. Affected is an unknown function of the file /sistema/flash/reboot. The manipulation leads to denial of service. It is possible to launch the attack remotely. The…
- CVE-2022-2776MEDIUMCVSS 5.4EG 5.42022-08-11
A vulnerability classified as problematic has been found in SourceCodester Gym Management System. Affected is an unknown function of the file delete_user.php. The manipulation of the argument delete_user leads to denial of service. It is p…
- CVE-2022-28875MEDIUMCVSS 4.3EG 6.52022-05-25
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the scanning the aemobile component can crash the scanning engine. The exploit can be triggered remotely by an attacker.
- CVE-2022-28887HIGHCVSS 4.3EG 7.52022-10-12
Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll unpacker handler function crashes. This can lead to a possible scanning engine crash.
- CVE-2022-31182MEDIUMCVSS 5.3EG 5.32022-08-01
Discourse is the an open source discussion platform. In affected versions a maliciously crafted request for static assets could cause error responses to be cached by Discourse's default NGINX proxy configuration. A corrected NGINX configur…
- CVE-2022-31622MEDIUMCVSS 5.5EG 5.52022-05-25
MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (pthread_create returns a nonzero value) while executing the method create_worker_threads, the held lock is not releas…
- CVE-2022-31624MEDIUMCVSS 5.5EG 5.52022-05-25
MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a de…
- CVE-2022-31693MEDIUMCVSS 5.5EG 5.52023-06-07
VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver. A malicious actor with local user privileges in the Windows guest OS, where VMware Tools is installed, ca…
- CVE-2022-32589HIGHCVSS 7.5EG 7.52022-10-07
In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. …
- CVE-2022-3299MEDIUMCVSS 4.3EG 6.52022-09-26
A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality in the library lib/sbi/client.c of the component AMF. The manipulation leads to denial of se…
- CVE-2022-3318MEDIUMCVSS 4.3EG 6.52022-11-01
Use after free in ChromeOS Notifications in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to reboot Chrome OS to potentially exploit heap corruption via UI interaction. (Chromium security s…
- CVE-2022-33324HIGHCVSS 7.5EG 7.52022-12-23
Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU Firmware versions "32" and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU Firmware ve…
- CVE-2022-3353HIGHCVSS 5.9EG 7.52023-02-21
A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products. An attacker could exploit the vulnerability by using a specially crafted message sequence, to force the IEC 61850 MMS-server c…
- CVE-2022-3354HIGHCVSS 3.5EG 7.52022-09-28
A vulnerability has been found in Open5GS up to 2.4.10 and classified as problematic. This vulnerability affects unknown code in the library lib/core/ogs-tlv-msg.c of the component UDP Packet Handler. The manipulation leads to denial of se…
- CVE-2022-33746MEDIUMCVSS 6.5EG 6.52022-10-11
P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of significant size. Therefore its freeing may take more time than is reasonable without intermediate preemption checks. Suc…
- CVE-2022-33747LOWCVSS 3.8EG 3.82022-10-11
Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a r…
- CVE-2022-3407MEDIUMCVSS 4.9EG 4.92023-09-01
I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a call on the device, then the device's modem may reset and cause the phone call t…
- CVE-2022-35191MEDIUMCVSS 6.5EG 6.52022-08-23
D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.
- CVE-2022-3524HIGHCVSS 4.3EG 7.52022-10-16
A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function ipv6_renew_options of the component IPv6 Handler. The manipulation leads to memory leak. The attack can be launc…
- CVE-2022-35240HIGHCVSS 7.5EG 7.52022-08-04
In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when the Message Routing (MR) Message Queuing Telemetry Transport (MQTT) profile is configured on a virtual server, undisclosed requests can cause…
- CVE-2022-3526HIGHCVSS 5.3EG 7.52022-10-16
A vulnerability classified as problematic was found in Linux Kernel. This vulnerability affects the function macvlan_handle_frame of the file drivers/net/macvlan.c of the component skb. The manipulation leads to memory leak. The attack can…
- CVE-2022-35272HIGHCVSS 7.5EG 7.52022-08-04
In BIG-IP Versions 17.0.x before 17.0.0.1 and 16.1.x before 16.1.3.1, when source-port preserve-strict is configured on an HTTP Message Routing Framework (MRF) virtual server, undisclosed traffic may cause the Traffic Management Microkerne…
- CVE-2022-3533MEDIUMCVSS 3.5EG 5.72022-10-17
A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects the function parse_usdt_arg of the file tools/lib/bpf/usdt.c of the component BPF. The manipulation of the argument reg_name leads to memory le…
Map vulnerabilities like CWE-404 to your infrastructure
EchelonGraph correlates every CVE — across CWE-404 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →