← Back
CWE-459

191 CVEs • Abstraction: Base

Incomplete Cleanup

The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

JSON object

Loading...

CVEs (191)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Mac Os X
Jun 17, 2026
Dec 18, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Catalina 10.15. A user may be unable to delete browsing history items.
1Apple
1Mac Os X
Jun 17, 2026
Dec 18, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The contents of locked notes sometimes appeared in search results. This issue was addressed with improved data cleanup. This issue is fixed in macOS Catalina 10.15. A local user may be able to view a user’s locked notes.
1Apple
3Iphone Os
Mac Os XWatchos
Jun 17, 2026
Dec 18, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A user’s video may not be paused in a FaceTime call if th...Show more
An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A user’s video may not be paused in a FaceTime call if they exit the FaceTime app while the call is ringing.Show less
1Apple
1Watchos
Jun 17, 2026
Dec 18, 2019
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
An issue existed where partially entered passcodes may not clear when the device went to sleep. This issue was addressed by clearing the passcode when a locked device sleeps. This issue is fixed in watchOS 5.2. A partial...Show more
An issue existed where partially entered passcodes may not clear when the device went to sleep. This issue was addressed by clearing the passcode when a locked device sleeps. This issue is fixed in watchOS 5.2. A partially entered passcode may not clear when the device goes to sleep.Show less
1Trendmicro
1Deep Security As A Service
Jun 17, 2026
Dec 16, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authenticated entity with certain unrestricted AWS execution privileges to escalate t...Show more
A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authenticated entity with certain unrestricted AWS execution privileges to escalate to full privileges within the target AWS account.Show less
2Oisf
Suricata Ids
2Libhtp
Suricata
Jun 17, 2026
Oct 10, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single \r\n ending.
2Dell
Emc
2Bsafe Crypto C Micro Edition
Rsa Bsafe Crypto C
Jun 17, 2026
Sep 30, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
RSA BSAFE Crypto-C Micro Edition, all versions prior to 4.1.4, is vulnerable to three (3) different Improper Clearing of Heap Memory Before Release vulnerability, also known as 'Heap Inspection vulnerability'. A maliciou...Show more
RSA BSAFE Crypto-C Micro Edition, all versions prior to 4.1.4, is vulnerable to three (3) different Improper Clearing of Heap Memory Before Release vulnerability, also known as 'Heap Inspection vulnerability'. A malicious remote user could potentially exploit this vulnerability to extract information leaving data at risk of exposure.Show less
1Obdev
1Little Snitch
Jun 17, 2026
Aug 23, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged helper which is not removed or updated immediately. Computers may there...Show more
Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged helper which is not removed or updated immediately. Computers may therefore still be vulnerable after upgrading to 4.4.0. Version 4.4.1 fixes this issue by removing the operating system's copy during the upgrade.Show less
1Pydio
1Cells
Jun 17, 2026
Jun 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data.
1Cisco
1Application Policy Infrastructure Controller
Jun 17, 2026
May 3, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The vulne...Show more
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The vulnerability is due to insecure removal of cleartext encryption keys stored on local partitions in the hard drive of an affected device. An attacker could exploit this vulnerability by retrieving data from the physical disk on the affected partition(s). A successful exploit could allow the attacker to retrieve encryption keys, possibly allowing the attacker to further decrypt other data and sensitive information on the device, which could lead to the disclosure of confidential information.Show less
1Flarum
1Flarum
Jun 17, 2026
Apr 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens.
1Macpaw
1Cleanmymac X
Jun 17, 2026
Mar 21, 2019
N/A· v4
5.5 MEDIUM· v3
6.6 MEDIUM· v2
An exploitable privilege escalation vulnerability exists in the helper service CleanMyMac X, version 4.20, due to improper updating. The application failed to remove the vulnerable components upon upgrading to the latest...Show more
An exploitable privilege escalation vulnerability exists in the helper service CleanMyMac X, version 4.20, due to improper updating. The application failed to remove the vulnerable components upon upgrading to the latest version, leaving the user open to attack. A user with local access can use this vulnerability to modify the file system as root. An attacker would need local access to the machine for a successful exploit.Show less
1Freebsd
1Freebsd
Jun 17, 2026
Feb 12, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In FreeBSD before 11.2-STABLE(r343782), 11.2-RELEASE-p9, 12.0-STABLE(r343781), and 12.0-RELEASE-p3, kernel callee-save registers are not properly sanitized before return from system calls, potentially allowing some kerne...Show more
In FreeBSD before 11.2-STABLE(r343782), 11.2-RELEASE-p9, 12.0-STABLE(r343781), and 12.0-RELEASE-p3, kernel callee-save registers are not properly sanitized before return from system calls, potentially allowing some kernel data used in the system call to be exposed.Show less
3Citrix
DebianXen
3Debian Linux
XenXenserver
Nov 21, 2024
Dec 8, 2018
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
Nov 21, 2024
Nov 14, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficiently quick clearing of stale rendered content in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
1Projeqtor
1Projeqtor
Nov 21, 2024
Nov 4, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the server, with predictable filenames, after a "...Show more
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the server, with predictable filenames, after a "This file is not a valid image" error message.Show less
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Nov 21, 2024
Oct 30, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(),...Show more
Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(), a stale TLB entry can remain for a short time that permits access to a physical page after it has been released back to the page allocator and reused. This is fixed in the following kernel versions: 4.9.135, 4.14.78, 4.18.16, 4.19.Show less
1Cisco
1Hyperflex Hx Data Platform
Nov 21, 2024
Oct 5, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files....Show more
A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files. An attacker could exploit this vulnerability by accessing the residual installation files on an affected system. A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system.Show less
1Dell
1Bsafe Ssl J
Nov 21, 2024
Sep 11, 2018
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
RSA BSAFE SSL-J versions prior to 6.2.4 contain a Heap Inspection vulnerability that could allow an attacker with physical access to the system to recover sensitive key material.
1Ecos
1Secure Boot Stick Firmware
Nov 21, 2024
Jun 17, 2018
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
Incomplete Cleanup vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a compromised host PC after a reset.