CWE-404— Improper Resource Shutdown or Release
685 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-404page 8 of 14
- CVE-2024-12659MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been classified as problematic. Affected is the function 0x8001E004 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation l…
- CVE-2024-12660MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been declared as problematic. Affected by this vulnerability is the function 0x8001E018 in the library AscRegistryFilter.sys of the component IOCTL Handler…
- CVE-2024-12661MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been rated as problematic. Affected by this issue is the function 0x8001E024 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manip…
- CVE-2024-12662MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability classified as problematic has been found in IObit Advanced SystemCare Utimate up to 17.0.0. This affects the function 0x8001E040 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to…
- CVE-2024-13009HIGHCVSS 7.2EG 7.22025-05-08
In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.
- CVE-2024-13978LOWCVSS 2.5EG 2.52025-08-01
A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the file tools/tiff2pdf.c of the component fax2ps. The manipulation leads to null p…
- CVE-2024-20905LOWCVSS 2.7EG 2.72024-02-17
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC). Supported versions that are affected are Prior to 9.2.8.0. Easily exploitable vulnerability allows high privilege…
- CVE-2024-20966MEDIUMCVSS 4.9EG 4.92024-02-17
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker wit…
- CVE-2024-20995LOWCVSS 2.4EG 2.42024-04-16
Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having DBA privilege …
- CVE-2024-21052MEDIUMCVSS 4.9EG 4.92024-04-16
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.34 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multip…
- CVE-2024-21253LOWCVSS 2.3EG 2.32024-10-15
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22. Easily exploitable vulnerability allows high privileged attacker with logon to the inf…
- CVE-2024-2180MEDIUMCVSS 5.5EG 5.52024-03-15
Zemana AntiLogger v2.74.204.664 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x80002020 IOCTL code of the zam64.sys and zamguard64.sys drivers
- CVE-2024-22019HIGHCVSS 7.5EG 7.52024-02-20
A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a sin…
- CVE-2024-22025MEDIUMCVSS 6.5EG 6.52024-03-19
A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL. The vulnerability stems from the fact that…
- CVE-2024-22105MEDIUMCVSS 5.5EG 5.52024-07-02
Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error.
- CVE-2024-23248HIGHCVSS 7.1EG 6.52024-03-08
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Processing a file may lead to a denial-of-service or potentially disclose memory contents.
- CVE-2024-23249HIGHCVSS 7.1EG 6.22024-03-08
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Processing a file may lead to a denial-of-service or potentially disclose memory contents.
- CVE-2024-2363MEDIUMCVSS 5.3EG 5.32024-03-10
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in AOL AIM Triton 1.0.4. It has been declared as problematic. This vulnerability affects unknown code of the component Invite Handler. The manipulation of the argument CSeq leads to…
- CVE-2024-23930MEDIUMCVSS 4.3EG 6.52025-01-31
This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. The specific flaw exist…
- CVE-2024-25087MEDIUMCVSS 5.5EG 5.52024-07-02
Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.7.0 allows local attackers to cause a Windows blue screen error.
- CVE-2024-26757MEDIUMCVSS 5.5EG 5.52024-04-03
In the Linux kernel, the following vulnerability has been resolved: md: Don't ignore read-only array in md_check_recovery() Usually if the array is not read-write, md_check_recovery() won't register new sync_thread in the first place. An…
- CVE-2024-27527HIGHCVSS 7.5EG 7.52024-11-08
wasm3 139076a is vulnerable to Denial of Service (DoS).
- CVE-2024-2760MEDIUMCVSS 5.5EG 5.52024-04-23
Bkav Home v7816, build 2403161130 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x222240 IOCTL code of the BkavSDFlt.sys driver.
- CVE-2024-28252HIGHCVSS 7.5EG 7.52024-03-15
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. If you have a NetFraming based CoreWCF service, extra system resources could be consumed by connections being left established instead of closing…
- CVE-2024-2995MEDIUMCVSS 5.4EG 5.42024-03-27
A vulnerability was found in NUUO Camera up to 20240319 and classified as problematic. This issue affects some unknown processing of the file /deletefile.php. The manipulation of the argument filename leads to denial of service. The attack…
- CVE-2024-31611CRITICALCVSS 9.1EG 9.12024-06-10
SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.
- CVE-2024-33844HIGHCVSS 7.5EG 7.52024-05-03
The 'control' in Parrot ANAFI USA firmware 1.10.4 does not check the MAV_MISSION_TYPE(0, 1, 2, 255), which allows attacker to cut off the connection between a controller and the drone by sending MAVLink MISSION_COUNT command with a wrong M…
- CVE-2024-3652MEDIUMCVSS 6.5EG 6.52024-04-11
The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default proposal handler causes an assertion failure and crashes and…
- CVE-2024-36856HIGHCVSS 7.5EG 7.52024-06-12
RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can exhaust system memory and crash the daemon by establishing and maintaining a vast number of long-lived malicious publi…
- CVE-2024-3764LOWCVSS 2.7EG 5.32024-04-14
** DISPUTED ** A vulnerability classified as problematic has been found in Tuya SDK up to 5.0.x. Affected is an unknown function of the component MQTT Packet Handler. The manipulation leads to denial of service. It is possible to launch th…
- CVE-2024-38271MEDIUMCVSS 4.8EG 4.82024-06-26
There exists a vulnerability in Quick Share/Nearby, where an attacker can force a victim to stay connected to a temporary hotspot created for the sharing. As part of the sequence of packets in a Quick Share connection over Bluetooth, the a…
- CVE-2024-39721HIGHCVSS 7.5EG 7.52024-10-31
An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and can be set to /dev/random, which is blocking, causing the goroutin…
- CVE-2024-4013MEDIUMCVSS 5.6EG 5.62024-06-06
A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) from RAM to NVM before powering down, resulting in the ability to replay unsaved messages. Note that as of June 2024, the…
- CVE-2024-4292MEDIUMCVSS 6.5EG 6.52024-04-27
A vulnerability classified as critical has been found in Contemporary Controls BASrouter BACnet BASRT-B 2.7.2. Affected is an unknown function of the component Device-Communication-Control Service. The manipulation with the input 55ff05003…
- CVE-2024-44201MEDIUMCVSS 5.5EG 5.52024-12-12
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, iPadOS 17.7.3, macOS Sequoia 15.1, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. Processing a malicious crafted file may lead to a denial-…
- CVE-2024-45182MEDIUMCVSS 5.5EG 5.52024-09-12
An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause an arbitrary address read, resulting in Denial of Service.
- CVE-2024-46752MEDIUMCVSS 5.5EG 5.52024-09-18
In the Linux kernel, the following vulnerability has been resolved: btrfs: replace BUG_ON() with error handling at update_ref_for_cow() Instead of a BUG_ON() just return an error, log an error message and abort the transaction in case we…
- CVE-2024-47213HIGHCVSS 7.5EG 7.52025-04-03
An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and trying to validate it, Enrich crashes and attempts to restart indefinitely. A…
- CVE-2024-4791HIGHCVSS 7.5EG 7.52024-05-14
A vulnerability classified as critical was found in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2. This vulnerability affects unknown code of the component Application Protocol Data Unit. The manipulation leads to denial of se…
- CVE-2024-47972MEDIUMCVSS 4.0EG 4.02024-10-07
Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the performance of the resource.
- CVE-2024-5095MEDIUMCVSS 6.5EG 6.52024-05-19
A vulnerability classified as problematic has been found in Victor Zsviot Camera 8.26.31. This affects an unknown part of the component MQTT Packet Handler. The manipulation leads to denial of service. It is possible to initiate the attack…
- CVE-2024-51179HIGHCVSS 7.5EG 7.52024-11-12
An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as the User Plane Function (UPF) and the Session Management Function (SMF), The Packet Data Unit (PDU) …
- CVE-2024-55553HIGHCVSS 7.5EG 7.52025-01-06
In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket's buffer size, default 4K on most OSes. An attacker can use this to trigger re-parsing …
- CVE-2024-56757MEDIUMCVSS 5.5EG 5.52025-01-06
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: add intf release flow when usb disconnect MediaTek claim an special usb intr interface for ISO data transmission. The interface need to be re…
- CVE-2024-57493MEDIUMCVSS 5.5EG 5.52025-04-18
An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the setsockopt function.
- CVE-2024-57618HIGHCVSS 7.5EG 7.52025-01-14
An issue in the bind_col_exp component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- CVE-2024-57623HIGHCVSS 7.5EG 7.52025-01-14
An issue in the HEAP_malloc component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- CVE-2024-57654HIGHCVSS 7.5EG 7.52025-01-14
An issue in the qst_vec_get_int64 component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- CVE-2024-57659HIGHCVSS 7.5EG 7.52025-01-14
An issue in the sqlg_parallel_ts_seq component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- CVE-2024-57661HIGHCVSS 7.5EG 7.52025-01-14
An issue in the sqlo_df component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
Map vulnerabilities like CWE-404 to your infrastructure
EchelonGraph correlates every CVE — across CWE-404 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →