CWE-460
19 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-460page 1 of 1
- CVE-2016-9592MEDIUMCVSS 4.3EG 4.32018-04-16
openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation to fail with 'VolumeInUse' error. Since the delete operation is retried every 30 seconds for each vo…
- CVE-2017-15127MEDIUMCVSS 5.5EG 5.52018-01-14
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local denial of service (BUG).
- CVE-2017-9657MEDIUMCVSS 6.5EG 6.52018-04-30
Under specific 802.11 network conditions, a partial re-association of the Philips IntelliVue MX40 Version B.06.18 WLAN monitor to the central monitoring station is possible. In this state, the central monitoring station can indicate the MX…
- CVE-2019-14891MEDIUMCVSS 5.0EG 5.02019-11-25
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condi…
- CVE-2020-14304MEDIUMCVSS 4.4EG 4.42020-09-15
A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of the device. This flaw allows a local user to read uninitialized values from the kernel memory. The highest threat from th…
- CVE-2021-34716MEDIUMCVSS 6.7EG 6.72021-08-18
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating sy…
- CVE-2022-22150HIGHCVSS 8.8EG 8.82022-02-04
A memory corruption vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. A specially-crafted PDF document can trigger an exception which is improperly handled, leaving the engine in an inval…
- CVE-2022-3301LOWCVSS 2.4EG 2.42022-09-26
Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.
- CVE-2022-3707MEDIUMCVSS 5.5EG 5.52023-03-06
A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload, causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a local user to crash …
- CVE-2022-4744HIGHCVSS 7.8EG 7.82023-03-30
A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or po…
- CVE-2023-46393HIGHCVSS 7.5EG 7.52023-10-27
gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet.
- CVE-2024-0316MEDIUMCVSS 6.8EG 6.82024-01-15
Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to send multiple request packets to the containment_notify/preview parameter, whic…
- CVE-2024-12289MEDIUMCVSS 5.9EG 5.92024-12-12
Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulne…
- CVE-2024-20354MEDIUMCVSS 4.7EG 4.72024-03-27
A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnera…
- CVE-2025-30157MEDIUMCVSS 6.5EG 6.52025-03-21
Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a local reply is sent to the external server due to the filter's life …
- CVE-2025-32439MEDIUMCVSS 6.5EG 6.52025-04-15
pleezer is a headless Deezer Connect player. Hook scripts in pleezer can be triggered by various events like track changes and playback state changes. In versions before 0.16.0, these scripts were spawned without proper process cleanup, le…
- CVE-2025-59399LOWCVSS 3.1EG 3.12025-09-15
libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error message generation.
- CVE-2026-40583HIGHCVSS 8.2EG 8.22026-04-21
UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance prechecks, but fails authorization only after state mutation h…
- CVE-2026-48524LOWCVSS 3.7EG 3.72026-05-28
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the un…
Map vulnerabilities like CWE-460 to your infrastructure
EchelonGraph correlates every CVE — across CWE-460 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →