CWE-459
191 CVEs • Abstraction: Base
Incomplete Cleanup
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
CVEs (191)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Incomplete cleanup in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable escalation of privilege via adjacent access. |
Eclipse Californium is a Java implementation of RFC7252 - Constrained Application Protocol for IoT Cloud services. In versions prior to 3.7.0, and 2.7.4, Californium is vulnerable to a Denial of Service. Failing handshak...Show more |
The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Successful exploitation of this vulnerability may cause a system restart. |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 1, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 1, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can create orphaned nodes in the Xenstore data base, as the cleanup after the e...Show more |
1Qualcomm 110Apq8009 Firmware Apq8052 FirmwareApq8053 Firmware+107 moreJun 17, 2026 Oct 19, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapd...Show more |
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW,...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 Aug 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU tha...Show more |
2Fedoraproject Powerdns2Fedora RecursorJun 17, 2026 Aug 23, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an...Show more |
1Intel 1Server Platform Services Firmware Jun 17, 2026 Aug 18, 2022 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Incomplete cleanup in a firmware subsystem for Intel(R) SPS before versions SPS_E3_04.08.04.330.0 and SPS_E3_04.01.04.530.0 may allow a privileged user to potentially enable denial of service via local access. |
A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group O...Show more |
5Debian FedoraprojectIntel+2 more7Debian Linux EsxiFedora+4 moreJun 17, 2026 Jun 15, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
3Debian IntelXen5Debian Linux Sgx DcapSgx Psw+2 moreJun 17, 2026 Jun 15, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
5Debian FedoraprojectIntel+2 more7Debian Linux EsxiFedora+4 moreJun 17, 2026 Jun 15, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
5Debian FedoraprojectIntel+2 more7Debian Linux EsxiFedora+4 moreJun 17, 2026 Jun 15, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could r...Show more |
2Netapp Openssl26A250 Firmware A700s FirmwareActive Iq Unified Manager+23 moreJun 17, 2026 May 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long...Show more |
1Johnsoncontrols 3Metasys Application And Data Server Metasys Extended Application And Data ServerMetasys Open Application ServerJun 17, 2026 Apr 15, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Under certain circumstances the session token is not cleared on logout. |
4Debian FedoraprojectLinux+1 more6Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+3 moreJun 17, 2026 Mar 3, 2022 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages...Show more |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreJun 17, 2026 Feb 18, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_sync after the unregister_netdev during removing device. A local user coul...Show more |