CWE-672
82 CVEs • Abstraction: Class
Operation on a Resource after Expiration or Release
The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.
CVEs (82)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Juniper 2Junos Junos Os EvolvedJun 17, 2026 Apr 14, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 An Operation on a Resource after Expiration or Release vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker with an establi...Show more |
1Philips 4Myvue SpeechVue Motion+1 moreJun 17, 2026 Apr 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key. |
1Ibm 1Partner Engagement Manager Jun 17, 2026 Apr 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token. IBM X-Force ID: 219131. |
1Siemens 48Simatic Drive Controller Cpu 1504d Tf Firmware Simatic Drive Controller Cpu 1507d Tf FirmwareSimatic Et 200sp Open Controller Cpu 1515sp Pc2 Firmware+45 moreJun 17, 2026 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIP...Show more |
1Siemens 48Simatic Drive Controller Cpu 1504d Tf Firmware Simatic Drive Controller Cpu 1507d Tf FirmwareSimatic Et 200sp Open Controller Cpu 1515sp Pc2 Firmware+45 moreJun 17, 2026 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Jun 24, 2021 N/A· v4 8.8 HIGH· v3 5.1 MEDIUM· v2 When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firef...Show more |
A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A large number of network requests in a small span of time can cause the...Show more |
1Parseplatform 1Parse Server Jun 17, 2026 Oct 22, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid. This allows clients with expired sessions to still receive subscription objects. It is not possible...Show more |
2Linux Netapp6Cloud Backup Hci Compute NodeLinux Kernel+3 moreJun 17, 2026 Sep 10, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall...Show more |
ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access to sensitive data via token reuse. NOTE: as of 2025-10-14, the Supplier's perspective is that this...Show more |
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP respon...Show more |
1Baxter 1Sigma Spectrum Infusion System Firmware Jun 17, 2026 Jun 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the WBM remains operational until the WBM is rebooted. |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Apr 30, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful exec...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Apr 24, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers. On error the original value is not r...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Apr 24, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd referencing a file from the lower filesystem without taking an additi...Show more |
2Libsixel Project Saitoha2Libsixel LibsixelJun 17, 2026 Dec 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3. |
2Opensuse Tigervnc2Leap TigervncJun 17, 2026 Dec 26, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack memory in ZRLEDecoder. If decoding routine would throw an exception, ZRLEDecoder may try to access st...Show more |
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in sc_pkcs15_decode_prkdf_entry. |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, after a subsystem reset, iwpriv is not giving correct information. |