CWE-404
742 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.
CVEs (742)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability classified as problematic has been found in Kiddoware Kids Place. This affects the Home Button Protection. A repeated pressing of the button causes a local denial of service. It is recommended to upgrade...Show more |
TeamViewer Linux versions before 15.28 do not properly execute a deletion command for the connection password in case of a process crash. Knowledge of the crash event and the TeamViewer ID as well as either possession of...Show more |
4Fedoraproject IscNetapp+1 more11Bind FedoraH300e Firmware+8 moreJun 17, 2026 Mar 23, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an...Show more |
Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to bypass the intended anonymity feature and obtain information regarding the onion services visited b...Show more |
4Debian FedoraprojectPuma+1 more4Debian Linux FedoraPuma+1 moreJun 17, 2026 Feb 11, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Puma is a Ruby/Rack web server built for parallelism. Prior to `puma` version `5.6.2`, `puma` may not always call `close` on the response body. Rails, prior to version `7.0.2.2`, depended on the response body being close...Show more |
A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated victim. The authenticat...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 Jan 25, 2022 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile and an HTTP profile are configured on a virtual server, undiscl...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Jan 25, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 arm: guest_physmap_remove_page not removing the p2m mappings The functions to remove one or more entries from a guest p2m pagetable on Arm (p2m_remove_mapping, guest_physmap_remove_page, and p2m_set_entry with mfn set to...Show more |
Duktape v2.99.99 was discovered to contain a SEGV vulnerability via the component duk_push_tval in duktape/duk_api_stack.c. |
HDF5 1.13.1-1 is affected by: segmentation fault, which causes a Denial of Service. |
2Debian Golang2Debian Linux GoJun 17, 2026 Jan 1, 2022 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network connection as a consequence of erroneous closing of file descriptor 0 after file-descriptor exhaustio...Show more |
In onNullBinding of ManagedServices.java, there is a possible permission bypass due to an incorrectly unbound service. This could lead to local escalation of privilege with no additional execution privileges needed. User...Show more |
The TCP Server module in toxcore before 0.2.8 doesn't free the TCP priority queue under certain conditions, which allows a remote attacker to exhaust the system's memory, causing a denial of service (DoS). |
1F Secure 5Atlant Elements Endpoint ProtectionInternet Gatekeeper+2 moreJun 17, 2026 Nov 26, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability affecting F-Secure antivirus engine was discovered whereby unpacking UPX file can lead to denial-of-service. The vulnerability can be exploited remotely by an attacker. A successful attack will result in...Show more |
Belledonne Belle-sip before 5.0.20 can crash applications such as Linphone via " \ " in the display name of a From header. |
A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling of...Show more |
1Deferred Image Processing Project 1Deferred Image Processing Jun 17, 2026 Aug 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service via the FAL API because of /var/transient disk consumption. |
2Debian Nvidia2Debian Linux Gpu Display DriverJun 17, 2026 Jul 22, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or...Show more |
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it doesn't release some resources during driver unload requests from guests. This flaw allows a malicious guest to perform ope...Show more |
1Phoenixcontact 15Fl Nat Smn 8tx M Firmware Fl Nat Smn 8tx FirmwareFl Switch Smcs 14tx/2fx Sm Firmware+12 moreJun 17, 2026 Jun 25, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected...Show more |