CWE-404— Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.— MITRE CWE catalog
758 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-404page 5 of 16
- CVE-2022-3543MEDIUMCVSS 3.5EG 5.52022-10-17
A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function unix_sock_destructor/unix_release_sock of the file net/unix/af_unix.c of the component BPF. The manipulation leads to mem…
- CVE-2022-3544MEDIUMCVSS 3.5EG 5.52022-10-17
A vulnerability, which was classified as problematic, was found in Linux Kernel. Affected is the function damon_sysfs_add_target of the file mm/damon/sysfs.c of the component Netfilter. The manipulation leads to memory leak. It is recommen…
- CVE-2022-3551HIGHCVSS 3.5EG 7.52022-10-17
A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a pat…
- CVE-2022-3553HIGHCVSS 3.5EG 7.52022-10-17
A vulnerability, which was classified as problematic, was found in X.org Server. This affects an unknown part of the file hw/xquartz/X11Controller.m of the component xquartz. The manipulation leads to denial of service. It is recommended t…
- CVE-2022-3563MEDIUMCVSS 3.5EG 5.72022-10-17
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len leads to nu…
- CVE-2022-3594HIGHCVSS 5.3EG 7.52022-10-18
A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function intr_callback of the file drivers/net/usb/r8152.c of the component BPF. The manipulation leads to logging of exc…
- CVE-2022-3606MEDIUMCVSS 3.5EG 5.52022-10-19
A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by_sec_insn of the file tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null pointer dereference. …
- CVE-2022-3619MEDIUMCVSS 3.5EG 4.32022-10-20
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to memory le…
- CVE-2022-3621HIGHCVSS 4.3EG 7.52022-10-20
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_bmap_lookup_at_level of the file fs/nilfs2/inode.c of the component nilfs2. The manipulation leads to null pointer dereference…
- CVE-2022-3624LOWCVSS 3.5EG 3.52022-10-21
A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. The manipulation leads to memory leak. It is re…
- CVE-2022-3629LOWCVSS 2.6EG 3.32022-10-21
A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function vsock_connect of the file net/vmw_vsock/af_vsock.c. The manipulation leads to memory leak. The complexity of an attack …
- CVE-2022-3630MEDIUMCVSS 3.1EG 5.52022-10-21
A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects some unknown processing of the file fs/fscache/cookie.c of the component IPsec. The manipulation leads to memory leak. It is recommended to app…
- CVE-2022-3633LOWCVSS 3.5EG 3.52022-10-21
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak. It is recommended to apply a patch to fi…
- CVE-2022-3637MEDIUMCVSS 2.6EG 5.52022-10-21
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function jlink_init of the file monitor/jlink.c of the component BlueZ. The manipulation leads to denial of service. It is recomme…
- CVE-2022-3646MEDIUMCVSS 3.1EG 5.32022-10-21
A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function nilfs_attach_log_writer of the file fs/nilfs2/segment.c of the component BPF. The manipulation leads to memory leak. The …
- CVE-2022-3647HIGHCVSS 3.1EG 7.52022-10-21
** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of servi…
- CVE-2022-3663MEDIUMCVSS 5.3EG 5.52022-10-26
A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. This issue affects the function AP4_StsdAtom of the file Ap4StsdAtom.cpp of the component MP4fragment. The manipulation leads to null pointer dereference. The…
- CVE-2022-3668MEDIUMCVSS 5.3EG 5.52022-10-26
A vulnerability has been found in Axiomatic Bento4 and classified as problematic. This vulnerability affects the function AP4_AtomFactory::CreateAtomFromStream of the component mp4edit. The manipulation leads to memory leak. The attack can…
- CVE-2022-3669MEDIUMCVSS 5.3EG 5.52022-10-26
A vulnerability was found in Axiomatic Bento4 and classified as problematic. This issue affects the function AP4_AvccAtom::Create of the component mp4edit. The manipulation leads to memory leak. The attack may be initiated remotely. The ex…
- CVE-2022-3684HIGHCVSS 7.5EG 7.52023-03-28
A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web services become busy rendering the application unresponsive. This issue affects: All SDM600 ve…
- CVE-2022-37133HIGHCVSS 7.5EG 7.52022-08-22
D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end.
- CVE-2022-3807MEDIUMCVSS 4.3EG 6.52022-11-01
A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Incomplete Fix CVE-2019-13238. The manipulation leads to resource consumption. The attac…
- CVE-2022-3809MEDIUMCVSS 4.3EG 6.52022-11-02
A vulnerability was found in Axiomatic Bento4 and classified as problematic. Affected by this issue is the function ParseCommandLine of the file Mp4Tag/Mp4Tag.cpp of the component mp4tag. The manipulation leads to denial of service. The at…
- CVE-2022-3810MEDIUMCVSS 4.3EG 6.52022-11-02
A vulnerability was found in Axiomatic Bento4. It has been classified as problematic. This affects the function AP4_File::AP4_File of the file Mp42Hevc.cpp of the component mp42hevc. The manipulation leads to denial of service. It is possi…
- CVE-2022-3812MEDIUMCVSS 4.3EG 6.52022-11-01
A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is the function AP4_ContainerAtom::AP4_ContainerAtom of the component mp4encrypt. The manipulation leads to memory leak. The attack may…
- CVE-2022-3813MEDIUMCVSS 4.3EG 6.52022-11-01
A vulnerability classified as problematic has been found in Axiomatic Bento4. This affects an unknown part of the component mp4edit. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has bee…
- CVE-2022-3814MEDIUMCVSS 4.3EG 6.52022-11-01
A vulnerability classified as problematic was found in Axiomatic Bento4. This vulnerability affects unknown code of the component mp4decrypt. The manipulation leads to memory leak. The attack can be initiated remotely. The exploit has been…
- CVE-2022-3815MEDIUMCVSS 4.3EG 6.52022-11-01
A vulnerability, which was classified as problematic, has been found in Axiomatic Bento4. This issue affects some unknown processing of the component mp4decrypt. The manipulation leads to memory leak. The attack may be initiated remotely. …
- CVE-2022-3816MEDIUMCVSS 4.3EG 6.52022-11-01
A vulnerability, which was classified as problematic, was found in Axiomatic Bento4. Affected is an unknown function of the component mp4decrypt. The manipulation leads to memory leak. It is possible to launch the attack remotely. The expl…
- CVE-2022-3817MEDIUMCVSS 4.3EG 6.52022-11-01
A vulnerability has been found in Axiomatic Bento4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component mp4mux. The manipulation leads to memory leak. The attack can be launched remotel…
- CVE-2022-39368HIGHCVSS 8.2EG 8.22022-11-10
Eclipse Californium is a Java implementation of RFC7252 - Constrained Application Protocol for IoT Cloud services. In versions prior to 3.7.0, and 2.7.4, Californium is vulnerable to a Denial of Service. Failing handshakes don't cleanup co…
- CVE-2022-3957MEDIUMCVSS 4.3EG 6.52022-11-11
A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory…
- CVE-2022-39949MEDIUMCVSS 4.4EG 5.52022-11-02
An improper control of a resource through its lifetime vulnerability [CWE-664] in FortiEDR CollectorWindows 4.0.0 through 4.1, 5.0.0 through 5.0.3.751, 5.1.0 may allow a privileged user to terminate the FortiEDR processes with special tool…
- CVE-2022-4066HIGHCVSS 3.5EG 8.22022-11-19
A vulnerability was found in davidmoreno onion. It has been rated as problematic. Affected by this issue is the function onion_response_flush of the file src/onion/response.c of the component Log Handler. The manipulation leads to allocati…
- CVE-2022-40890HIGHCVSS 7.5EG 7.52022-09-29
A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.
- CVE-2022-4246HIGHCVSS 4.3EG 7.52022-12-01
A vulnerability classified as problematic has been found in Kakao PotPlayer. This affects an unknown part of the component MID File Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The e…
- CVE-2022-4296MEDIUMCVSS 6.5EG 6.52022-12-06
A vulnerability classified as problematic has been found in TP-Link TL-WR740N. Affected is an unknown function of the component ARP Handler. The manipulation leads to resource consumption. The attack needs to be done within the local netwo…
- CVE-2022-44267HIGHCVSS 6.5EG 8.62023-02-06
ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input.
- CVE-2022-44552HIGHCVSS 7.5EG 7.52022-11-09
The lock screen module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
- CVE-2022-4565MEDIUMCVSS 4.3EG 4.32022-12-16
A vulnerability classified as problematic was found in Dromara HuTool up to 5.8.10. This vulnerability affects unknown code of the file cn.hutool.core.util.ZipUtil.java. The manipulation leads to resource consumption. The attack can be ini…
- CVE-2022-46314HIGHCVSS 7.5EG 7.52022-12-20
The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.
- CVE-2022-48489HIGHCVSS 7.5EG 7.52023-06-19
Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.
- CVE-2022-48499HIGHCVSS 7.5EG 7.52023-06-19
Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.
- CVE-2022-48500HIGHCVSS 7.5EG 7.52023-06-19
Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.
- CVE-2022-48661MEDIUMCVSS 5.5EG 5.52024-04-28
In the Linux kernel, the following vulnerability has been resolved: gpio: mockup: Fix potential resource leakage when register a chip If creation of software node fails, the locally allocated string array is left unfreed. Free it on erro…
- CVE-2022-49745MEDIUMCVSS 5.5EG 5.52025-03-27
In the Linux kernel, the following vulnerability has been resolved: fpga: m10bmc-sec: Fix probe rollback Handle probe error rollbacks properly to avoid leaks.
- CVE-2022-4981LOWCVSS 3.3EG 3.32025-10-21
A vulnerability was detected in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeerList of the file /dcmqrcnf.cc of the component dcmqrscp. The manipulation results in null pointer dereference. The atta…
- CVE-2023-0029HIGHCVSS 5.3EG 7.52023-01-01
A vulnerability was found in Multilaser RE708 RE1200R4GC-2T2R-V3_v3411b_MUL029B. It has been rated as problematic. This issue affects some unknown processing of the component Telnet Service. The manipulation leads to denial of service. The…
- CVE-2023-0412MEDIUMCVSS 6.3EG 6.52023-01-26
TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
- CVE-2023-0413MEDIUMCVSS 6.3EG 6.52023-01-26
Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
Map vulnerabilities like CWE-404 to your infrastructure
EchelonGraph correlates every CVE — across CWE-404 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →