CWE-459
191 CVEs • Abstraction: Base
Incomplete Cleanup
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
CVEs (191)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse. |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Jan 25, 2022 N/A· v4 4.6 MEDIUM· v3 4.7 MEDIUM· v2 Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical devices exposed to x86 HVM guests involves an iterative operation in particular when cleaning up after the guest's use of...Show more |
A vulnerability was found in the Linux kernel's KVM subsystem in arch/x86/kvm/lapic.c kvm_free_lapic when a failure allocation was detected. In this flaw the KVM subsystem may crash the kernel due to mishandling of memor...Show more |
1Zeroize Derive Project 1Zeroize Derive Jun 17, 2026 Dec 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust. Dropped memory is not zeroed out for an enum. |
There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected. |
There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to kernel restart. |
There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected. |
The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the...Show more |
A component of the HarmonyOS has a Incomplete Cleanup vulnerability. Local attackers may exploit this vulnerability to cause memory exhaustion. |
1Ericsson 1Operations Support System Radio And Core Firmware Jun 17, 2026 Oct 14, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and passwords are left in the system undeleted but in folders accessible by top privileged accounts only....Show more |
1Ait Pro 1Bulletproof Security Jun 17, 2026 Sep 17, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the si...Show more |
There is an Incomplete Cleanup Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass. |
1Thalesgroup 1Sentinel Ldk Run Time Environment Jun 17, 2026 Jun 16, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows incoming connections from private networks using TCP Port 1947. While uninstallin...Show more |
2Debian Intel214Atom X5 E3930 Atom X5 E3940Atom X7 E3950+211 moreJun 17, 2026 Jun 9, 2021 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access. |
3Debian LinuxStarwindsoftware3Debian Linux Linux KernelStarwind Virtual SanJun 17, 2026 Apr 14, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf. fuse_do_getattr() calls make_bad_inode() in inappropriate situations, causing a system crash. NOTE: t...Show more |
Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attacker who can locally read user's files obtain JWT tokens for user's account due to insufficient cache...Show more |
1Intel 2Killer Proset/wireless WifiJun 17, 2026 Feb 17, 2021 N/A· v4 5.2 MEDIUM· v3 4.1 MEDIUM· v2 Incomplete cleanup in some Intel(R) PROSet/Wireless WiFi and Killer (TM) drivers before version 22.0 may allow a privileged user to potentially enable information disclosure and denial of service<b> </b>via adjacent...Show more |
In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user...Show more |
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros. |
1Ui 2Unifi Controller Firmware Unifi Meshing Access Point FirmwareJun 17, 2026 Oct 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Ubiquiti UniFi Meshing Access Point UAP-AC-M 4.3.21.11325 and UniFi Controller 6.0.28 devices. Cached credentials are not erased from an access point returning wirelessly from a disconnected st...Show more |