CWE-404— Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.— MITRE CWE catalog
758 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-404page 7 of 16
- CVE-2023-34059HIGHCVSS 7.4EG 7.42023-10-27
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.
- CVE-2023-34969MEDIUMCVSS 6.5EG 6.52023-06-08
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivilege…
- CVE-2023-3760MEDIUMCVSS 4.3EG 4.32023-07-19
A vulnerability has been found in Intergard SGS 8.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. The manipulation leads to denial of service. The atta…
- CVE-2023-4463HIGHCVSS 7.5EG 7.52023-12-29
A vulnerability classified as problematic was found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60. This vulnerability affects unknown code of the component HTTP Header Handler. The manipulation of the argument Cookie leads to denial of …
- CVE-2023-45802MEDIUMCVSS 5.9EG 5.92023-10-23
When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests a…
- CVE-2023-4882HIGHCVSS 7.5EG 7.52023-10-03
DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, ca…
- CVE-2023-51332MEDIUMCVSS 4.3EG 4.32025-02-20
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large …
- CVE-2023-5255HIGHCVSS 7.5EG 7.52023-10-03
For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
- CVE-2023-5259MEDIUMCVSS 4.9EG 4.92023-09-29
A vulnerability classified as problematic was found in ForU CMS. This vulnerability affects unknown code of the file /admin/cms_admin.php. The manipulation of the argument del leads to denial of service. The attack can be initiated remotel…
- CVE-2023-5324MEDIUMCVSS 6.5EG 6.52023-10-01
A vulnerability has been found in eeroOS up to 6.16.4-11 and classified as critical. This vulnerability affects unknown code of the component Ethernet Interface. The manipulation leads to denial of service. The attack needs to be approache…
- CVE-2023-5459HIGHCVSS 7.5EG 7.52023-10-09
A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to denial of service. The expl…
- CVE-2023-5462HIGHCVSS 7.5EG 7.52023-10-09
A vulnerability was found in XINJE XD5E-30R-E 3.5.3b. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Modbus Handler. The manipulation leads to denial of service. The exploit ha…
- CVE-2023-6180MEDIUMCVSS 5.3EG 5.32023-12-05
The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by resource exhaustion. The set_ex_data function used by the library did not deallocate memory u…
- CVE-2023-6450MEDIUMCVSS 5.5EG 5.52024-01-19
An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resulting in a denial of service.
- CVE-2023-7209HIGHCVSS 7.5EG 7.52024-01-07
A vulnerability was found in Uniway Router up to 2.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boaform/device_reset.cgi of the component Device Reset Handler. The manipulation leads t…
- CVE-2024-0261HIGHCVSS 7.5EG 7.52024-01-07
A vulnerability has been found in Sentex FTPDMIN 0.96 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component RNFR Command Handler. The manipulation leads to denial of service. The attack …
- CVE-2024-0263HIGHCVSS 7.5EG 7.52024-01-07
A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to denial of service. It is possible to initiate…
- CVE-2024-0418MEDIUMCVSS 5.3EG 5.32024-01-11
A vulnerability has been found in iSharer and upRedSun File Sharing Wizard up to 1.5.0 and classified as problematic. This vulnerability affects unknown code of the component GET Request Handler. The manipulation leads to denial of service…
- CVE-2024-0419MEDIUMCVSS 5.3EG 5.32024-01-11
A vulnerability was found in Jasper httpdx up to 1.5.4 and classified as problematic. This issue affects some unknown processing of the component HTTP POST Request Handler. The manipulation leads to denial of service. The attack may be ini…
- CVE-2024-0546MEDIUMCVSS 5.3EG 5.32024-01-15
A vulnerability, which was classified as problematic, has been found in EasyFTP 1.7.0. This issue affects some unknown processing of the component LIST Command Handler. The manipulation leads to denial of service. The attack may be initiat…
- CVE-2024-0547MEDIUMCVSS 5.3EG 5.32024-01-15
A vulnerability has been found in Ability FTP Server 2.34 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component APPE Command Handler. The manipulation leads to denial of service. The att…
- CVE-2024-0548MEDIUMCVSS 5.3EG 5.32024-01-15
A vulnerability was found in FreeFloat FTP Server 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the component SIZE Command Handler. The manipulation leads to denial of service. The attack may be…
- CVE-2024-0693MEDIUMCVSS 5.3EG 5.32024-01-18
A vulnerability classified as problematic was found in EFS Easy File Sharing FTP 2.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username leads to denial of service. The attack can be launc…
- CVE-2024-0695MEDIUMCVSS 4.3EG 4.32024-01-18
A vulnerability, which was classified as problematic, has been found in EFS Easy Chat Server 3.1. Affected by this issue is some unknown functionality of the component HTTP GET Request Handler. The manipulation of the argument USERNAME lea…
- CVE-2024-0723MEDIUMCVSS 5.3EG 5.32024-01-19
A vulnerability was found in freeSSHd 1.0.9 on Windows. It has been classified as problematic. This affects an unknown part. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been …
- CVE-2024-0725MEDIUMCVSS 5.3EG 5.32024-01-19
A vulnerability was found in ProSSHD 1.2 on Windows. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disc…
- CVE-2024-0731MEDIUMCVSS 5.3EG 5.32024-01-19
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as problematic. This vulnerability affects unknown code of the component PUT Command Handler. The manipulation leads to denial of service. The attack can be initiated …
- CVE-2024-0732MEDIUMCVSS 5.3EG 5.32024-01-19
A vulnerability was found in PCMan FTP Server 2.0.7 and classified as problematic. This issue affects some unknown processing of the component STOR Command Handler. The manipulation leads to denial of service. The attack may be initiated r…
- CVE-2024-0736MEDIUMCVSS 5.3EG 5.32024-01-19
A vulnerability classified as problematic has been found in EFS Easy File Sharing FTP 3.6. This affects an unknown part of the component Login. The manipulation of the argument password leads to denial of service. It is possible to initiat…
- CVE-2024-0737MEDIUMCVSS 5.3EG 5.32024-01-19
A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Login. The manipulation of the argument user leads to denial of service. The attack can be in…
- CVE-2024-0885MEDIUMCVSS 5.3EG 5.32024-01-25
A vulnerability classified as problematic has been found in SpyCamLizard 1.230. Affected is an unknown function of the component HTTP GET Request Handler. The manipulation leads to denial of service. It is possible to launch the attack rem…
- CVE-2024-0886LOWCVSS 3.3EG 3.32024-01-25
A vulnerability classified as problematic was found in Poikosoft EZ CD Audio Converter 8.0.7. Affected by this vulnerability is an unknown functionality of the component Activation Handler. The manipulation of the argument Key leads to den…
- CVE-2024-0887MEDIUMCVSS 5.3EG 5.32024-01-25
A vulnerability, which was classified as problematic, has been found in Mafiatic Blue Server 1.1. Affected by this issue is some unknown functionality of the component Connection Handler. The manipulation leads to denial of service. The at…
- CVE-2024-0888MEDIUMCVSS 5.3EG 5.32024-01-25
A vulnerability, which was classified as problematic, was found in BORGChat 1.0.0 Build 438. This affects an unknown part of the component Service Port 7551. The manipulation leads to denial of service. It is possible to initiate the attac…
- CVE-2024-0889MEDIUMCVSS 5.3EG 5.32024-01-25
A vulnerability was found in Kmint21 Golden FTP Server 2.02b and classified as problematic. This issue affects some unknown processing of the component PASV Command Handler. The manipulation leads to denial of service. The attack may be in…
- CVE-2024-1016MEDIUMCVSS 5.3EG 5.32024-01-29
A vulnerability was found in Solar FTP Server 2.1.1/2.1.2. It has been declared as problematic. This vulnerability affects unknown code of the component PASV Command Handler. The manipulation leads to denial of service. The attack can be i…
- CVE-2024-1017MEDIUMCVSS 5.3EG 5.32024-01-29
A vulnerability was found in Gabriels FTP Server 1.2. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument USERNAME leads to denial of service. The attack may be initiated remotely.…
- CVE-2024-11097LOWCVSS 3.3EG 3.32024-11-12
A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Main Menu. The manipulation leads to infinite loop. Attacking loc…
- CVE-2024-11586MEDIUMCVSS 4.0EG 4.02024-11-23
Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected.
- CVE-2024-11588HIGHCVSS 3.5EG 7.52024-11-21
A vulnerability was found in AVL-DiTEST-DiagDev libdoip 1.0.0. It has been rated as problematic. This issue affects the function DoIPConnection::reactOnReceivedTcpMessage of the file DoIPConnection.cpp. The manipulation leads to null point…
- CVE-2024-11650MEDIUMCVSS 6.5EG 6.52024-11-25
A vulnerability was found in Tenda i9 1.0.0.8(3828) and classified as critical. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation leads to null pointer dereference. The attack may be initiated remo…
- CVE-2024-1184LOWCVSS 3.3EG 3.32024-02-02
A vulnerability was found in Nsasoft Network Sleuth 3.0.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. The manipulation leads to denial of service. It is p…
- CVE-2024-1185LOWCVSS 3.3EG 3.32024-02-02
A vulnerability classified as problematic has been found in Nsasoft NBMonitor Network Bandwidth Monitor 1.6.5.0. This affects an unknown part of the component Registration Handler. The manipulation leads to denial of service. The attack ne…
- CVE-2024-1186LOWCVSS 3.3EG 3.32024-02-02
A vulnerability classified as problematic was found in Munsoft Easy Archive Recovery 2.0. This vulnerability affects unknown code of the component Registration Key Handler. The manipulation leads to denial of service. An attack has to be a…
- CVE-2024-1187LOWCVSS 3.3EG 3.32024-02-02
A vulnerability, which was classified as problematic, has been found in Munsoft Easy Outlook Express Recovery 2.0. This issue affects some unknown processing of the component Registration Key Handler. The manipulation leads to denial of se…
- CVE-2024-1188LOWCVSS 3.3EG 3.32024-02-02
A vulnerability, which was classified as problematic, was found in Rizone Soft Notepad3 1.0.2.350. Affected is an unknown function of the component Encryption Passphrase Handler. The manipulation leads to denial of service. Attacking local…
- CVE-2024-1189MEDIUMCVSS 5.3EG 5.32024-02-02
A vulnerability has been found in AMPPS 2.7 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Encryption Passphrase Handler. The manipulation leads to denial of service. The attack c…
- CVE-2024-1190LOWCVSS 3.3EG 3.32024-02-02
A vulnerability was found in Global Scape CuteFTP 9.3.0.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument Host/Username/Password leads to denial of service. The attack n…
- CVE-2024-1191LOWCVSS 3.3EG 3.32024-02-29
A vulnerability was found in Hyper CdCatalog 2.3.1. It has been classified as problematic. This affects an unknown part of the component HCF File Handler. The manipulation leads to denial of service. An attack has to be approached locally.…
- CVE-2024-1192LOWCVSS 3.3EG 3.32024-02-29
A vulnerability was found in South River WebDrive 18.00.5057. It has been declared as problematic. This vulnerability affects unknown code of the component New Secure WebDAV. The manipulation leads to denial of service. Local access is req…
Map vulnerabilities like CWE-404 to your infrastructure
EchelonGraph correlates every CVE — across CWE-404 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →