CWE-459
191 CVEs • Abstraction: Base
Incomplete Cleanup
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
CVEs (191)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Catalina 10.15. A user may be unable to delete browsing history items. |
The contents of locked notes sometimes appeared in search results. This issue was addressed with improved data cleanup. This issue is fixed in macOS Catalina 10.15. A local user may be able to view a user’s locked notes. |
1Apple 3Iphone Os Mac Os XWatchosJun 17, 2026 Dec 18, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 An issue existed in the pausing of FaceTime video. The issue was resolved with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, watchOS 5.2. A user’s video may not be paused in a FaceTime call if th...Show more |
An issue existed where partially entered passcodes may not clear when the device went to sleep. This issue was addressed by clearing the passcode when a locked device sleeps. This issue is fixed in watchOS 5.2. A partial...Show more |
1Trendmicro 1Deep Security As A Service Jun 17, 2026 Dec 16, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authenticated entity with certain unrestricted AWS execution privileges to escalate t...Show more |
2Oisf Suricata Ids2Libhtp SuricataJun 17, 2026 Oct 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the http_header signature to not alert on a response with a single \r\n ending. |
2Dell Emc2Bsafe Crypto C Micro Edition Rsa Bsafe Crypto CJun 17, 2026 Sep 30, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 RSA BSAFE Crypto-C Micro Edition, all versions prior to 4.1.4, is vulnerable to three (3) different Improper Clearing of Heap Memory Before Release vulnerability, also known as 'Heap Inspection vulnerability'. A maliciou...Show more |
Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have made a copy of the privileged helper which is not removed or updated immediately. Computers may there...Show more |
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data. |
1Cisco 1Application Policy Infrastructure Controller Jun 17, 2026 May 3, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The vulne...Show more |
User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens. |
An exploitable privilege escalation vulnerability exists in the helper service CleanMyMac X, version 4.20, due to improper updating. The application failed to remove the vulnerable components upon upgrading to the latest...Show more |
In FreeBSD before 11.2-STABLE(r343782), 11.2-RELEASE-p9, 12.0-STABLE(r343781), and 12.0-RELEASE-p3, kernel callee-save registers are not properly sanitized before return from system calls, potentially allowing some kerne...Show more |
3Citrix DebianXen3Debian Linux XenXenserverNov 21, 2024 Dec 8, 2018 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 Nov 14, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficiently quick clearing of stale rendered content in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. |
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the server, with predictable filenames, after a "...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Oct 30, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(),...Show more |
1Cisco 1Hyperflex Hx Data Platform Nov 21, 2024 Oct 5, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to insufficient cleanup of installation files....Show more |
RSA BSAFE SSL-J versions prior to 6.2.4 contain a Heap Inspection vulnerability that could allow an attacker with physical access to the system to recover sensitive key material. |
1Ecos 1Secure Boot Stick Firmware Nov 21, 2024 Jun 17, 2018 N/A· v4 4.2 MEDIUM· v3 1.9 LOW· v2 Incomplete Cleanup vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a compromised host PC after a reset. |