CWE-459— Incomplete Cleanup
181 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-459page 1 of 4
- CVE-2000-0552MEDIUMCVSS 5.5EG 5.52000-06-06
ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information.
- CVE-2002-0788MEDIUMCVSS 5.5EG 5.52002-08-12
An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext temporary files that cannot be wiped or deleted due to strong permissions, which could allow certa…
- CVE-2002-2066HIGHCVSS 7.5EG 7.52002-12-31
BestCrypt BCWipe 1.0.7 and 2.0 through 2.35.1 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.
- CVE-2002-2067HIGHCVSS 7.5EG 7.52002-12-31
East-Tec Eraser 2002 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.
- CVE-2002-2068HIGHCVSS 7.5EG 7.52002-12-31
Eraser 5.3 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.
- CVE-2002-2069HIGHCVSS 7.5EG 7.52002-12-31
PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.
- CVE-2002-2070HIGHCVSS 7.5EG 7.52002-12-31
SecureClean 3 build 2.0 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.
- CVE-2005-2293MEDIUMCVSS 5.5EG 5.52005-07-18
Oracle Formsbuilder 9.0.4 stores database usernames and passwords in a temporary file, which is not deleted after it is used, which allows local users to obtain sensitive information.
- CVE-2012-5663HIGHCVSS 7.5EG 7.52019-12-30
The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp).
- CVE-2018-11068MEDIUMCVSS 4.6EG 4.62018-09-11
RSA BSAFE SSL-J versions prior to 6.2.4 contain a Heap Inspection vulnerability that could allow an attacker with physical access to the system to recover sensitive key material.
- CVE-2018-12332MEDIUMCVSS 4.2EG 4.22018-06-17
Incomplete Cleanup vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a compromised host PC after a reset.
- CVE-2018-15407MEDIUMCVSS 5.5EG 5.52018-10-05
A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files. An attacker could e…
- CVE-2018-17467MEDIUMCVSS 4.3EG 4.32018-11-14
Insufficiently quick clearing of stale rendered content in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
- CVE-2018-18281HIGHCVSS 7.8EG 7.82018-10-30
Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(), a stale TLB entry c…
- CVE-2018-18924HIGHCVSS 8.8EG 8.82018-11-04
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the server, with predictable filenames, after a "This file is not a …
- CVE-2018-19961HIGHCVSS 7.8EG 7.82018-12-08
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
- CVE-2019-11514HIGHCVSS 7.5EG 7.52019-04-25
User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens.
- CVE-2019-12902MEDIUMCVSS 6.5EG 6.52019-06-20
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data.
- CVE-2019-13014MEDIUMCVSS 5.5EG 5.52019-08-23
Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged helper which is not removed or updated immediately. Computers may therefore still be vulne…
- CVE-2019-14115MEDIUMCVSS 5.5EG 5.52020-09-08
u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display session which can result in user reading the secure input while touch is in non-secure domain as secure display is active' i…
- CVE-2019-1586MEDIUMCVSS 4.6EG 4.62019-05-03
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The vulnerability is due to …
- CVE-2019-17420MEDIUMCVSS 5.3EG 5.32019-10-10
In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single \r\n ending.
- CVE-2019-18191HIGHCVSS 8.8EG 8.82019-12-16
A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authenticated entity with certain unrestricted AWS execution privileges to escalate to full privileges w…
- CVE-2019-20849MEDIUMCVSS 5.3EG 5.32020-06-19
An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.
- CVE-2019-20850MEDIUMCVSS 5.3EG 5.32020-06-19
An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.
- CVE-2019-25016HIGHCVSS 8.8EG 8.82021-01-28
In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user to execute specific…
- CVE-2019-3733MEDIUMCVSS 4.9EG 4.92019-09-30
RSA BSAFE Crypto-C Micro Edition, all versions prior to 4.1.4, is vulnerable to three (3) different Improper Clearing of Heap Memory Before Release vulnerability, also known as 'Heap Inspection vulnerability'. A malicious remote user could…
- CVE-2019-5011MEDIUMCVSS 5.5EG 5.52019-03-21
An exploitable privilege escalation vulnerability exists in the helper service CleanMyMac X, version 4.20, due to improper updating. The application failed to remove the vulnerable components upon upgrading to the latest version, leaving t…
- CVE-2019-5595MEDIUMCVSS 5.5EG 5.52019-02-12
In FreeBSD before 11.2-STABLE(r343782), 11.2-RELEASE-p9, 12.0-STABLE(r343781), and 12.0-RELEASE-p3, kernel callee-save registers are not properly sanitized before return from system calls, potentially allowing some kernel data used in the …
- CVE-2019-8548LOWCVSS 2.4EG 2.42019-12-18
An issue existed where partially entered passcodes may not clear when the device went to sleep. This issue was addressed by clearing the passcode when a locked device sleeps. This issue is fixed in watchOS 5.2. A partially entered passcode…
- CVE-2019-8550MEDIUMCVSS 4.3EG 4.32019-12-18
An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A user’s video may not be paused in a FaceTime call if they exit the FaceT…
- CVE-2019-8730LOWCVSS 3.3EG 3.32019-12-18
The contents of locked notes sometimes appeared in search results. This issue was addressed with improved data cleanup. This issue is fixed in macOS Catalina 10.15. A local user may be able to view a user’s locked notes.
- CVE-2019-8732LOWCVSS 2.4EG 2.42020-10-27
The issue was addressed with improved data deletion. This issue is fixed in iOS 13. Deleted calls remained visible on the device.
- CVE-2019-8768MEDIUMCVSS 5.3EG 5.32019-12-18
"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Catalina 10.15. A user may be unable to delete browsing history items.
- CVE-2020-0183HIGHCVSS 7.8EG 7.82020-06-11
In handleMessage of BluetoothManagerService, there is an incomplete reset. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersion…
- CVE-2020-0258MEDIUMCVSS 5.5EG 5.52020-08-11
In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local information disclosure in the application that is started next with no additional execution privileges needed. User interaction is not needed…
- CVE-2020-0286HIGHCVSS 7.5EG 7.52020-09-18
In Bluetooth AVRCP, there is a possible leak of audio metadata due to residual data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: …
- CVE-2020-0543MEDIUMCVSS 5.5EG 5.52020-06-15
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2020-10685MEDIUMCVSS 5.0EG 5.02020-05-11
A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules whi…
- CVE-2020-12414MEDIUMCVSS 6.5EG 6.52020-07-09
IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnera…
- CVE-2020-12494MEDIUMCVSS 5.3EG 5.32020-06-16
Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent thro…
- CVE-2020-12624MEDIUMCVSS 6.5EG 6.52020-05-03
The League application before 2020-05-02 on Android sends a bearer token in an HTTP Authorization header to an arbitrary web site that hosts an external image because an OkHttp object is reused, which allows remote attackers to hijack sess…
- CVE-2020-12857HIGHCVSS 7.5EG 7.52020-05-18
Caching of GATT characteristic values (TempID) in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to long-term re-identify an Android device running COVIDSafe.
- CVE-2020-13346MEDIUMCVSS 6.5EG 6.52020-10-07
Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
- CVE-2020-13451CRITICALCVSS 9.8EG 9.82021-01-07
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.
- CVE-2020-14451HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local Storage to remain after a logout, aka MMSA-2020-0013.
- CVE-2020-15024MEDIUMCVSS 5.5EG 5.52020-09-10
An issue was discovered in the Login Password feature of the Password Manager component in Avast Antivirus 20.1.5069.562. An entered password continues to be stored in Windows main memory after a logout, and after a Lock Vault operation.
- CVE-2020-24458MEDIUMCVSS 5.2EG 5.22021-02-17
Incomplete cleanup in some Intel(R) PROSet/Wireless WiFi and Killer (TM) drivers before version 22.0 may allow a privileged user to potentially enable information disclosure and denial of service<b> </b>via adjacent access.
- CVE-2020-24489HIGHCVSS 8.8EG 8.82021-06-09
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-27888HIGHCVSS 7.5EG 7.52020-10-27
An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point returning wirelessly from a disconnected state. This may provi…
Map vulnerabilities like CWE-459 to your infrastructure
EchelonGraph correlates every CVE — across CWE-459 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →