CWE-664
33 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-664page 1 of 1
- CVE-2019-16779MEDIUMCVSS 5.8EG 5.82019-12-16
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returni…
- CVE-2019-5816HIGHCVSS 8.82019-06-27
Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.
- CVE-2020-1620MEDIUMCVSS 5.5EG 5.52020-04-08
A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
- CVE-2020-1621MEDIUMCVSS 5.5EG 5.52020-04-08
A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1.
- CVE-2020-1622MEDIUMCVSS 5.5EG 5.52020-04-08
A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Evolved prior to 19.1R1.
- CVE-2020-3175HIGHCVSS 8.6EG 8.62020-02-26
A vulnerability in the resource handling system of Cisco NX-OS Software for Cisco MDS 9000 Series Multilayer Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The v…
- CVE-2020-3504LOWCVSS 3.3EG 3.32020-08-27
A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper ha…
- CVE-2020-36774MEDIUMCVSS 5.5EG 5.52024-02-19
plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).
- CVE-2021-1592MEDIUMCVSS 4.3EG 4.32021-08-25
A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource man…
- CVE-2022-1385LOWCVSS 3.7EG 3.72022-04-19
Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public …
- CVE-2022-2048HIGHCVSS 7.5EG 7.52022-07-07
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial o…
- CVE-2022-20748MEDIUMCVSS 5.3EG 5.32022-05-03
A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability …
- CVE-2022-20856HIGHCVSS 8.6EG 7.52022-09-30
A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to…
- CVE-2022-2191HIGHCVSS 7.5EG 7.52022-07-07
In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.
- CVE-2022-22249MEDIUMCVSS 6.5EG 6.52022-10-18
An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When there…
- CVE-2022-22250MEDIUMCVSS 6.5EG 6.52022-10-18
An Improper Control of a Resource Through its Lifetime vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS and Junos OS Evolved allows unauthenticated adjacent attacker to cause a Denial of Service (DoS). In an EVP…
- CVE-2022-27512MEDIUMCVSS 5.3EG 5.32022-06-16
Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.
- CVE-2022-27518CRITICALCVSS 9.8EG 9.8⚠ KEV2022-12-13
Unauthenticated remote arbitrary code execution
- CVE-2022-28287MEDIUMCVSS 6.5EG 6.52022-12-22
In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. This vulnerability affects Firefox < 99.
- CVE-2022-31153MEDIUMCVSS 6.5EG 6.52022-07-15
OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live networks. This issue a…
- CVE-2022-32846HIGHCVSS 7.5EG 7.52023-02-27
A logic issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sensitive data.
- CVE-2022-46144MEDIUMCVSS 6.5EG 6.52022-12-13
A vulnerability has been identified in SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions < V2.3), SCALANCE SC622-2C (6GK5622-2GS00-2AC2) (All versions >= V2.3 < V3.0), SCALANCE SC626-2C (6GK5626-2GS00-2AC2) (All versions < V2.3), SCALAN…
- CVE-2023-25942MEDIUMCVSS 6.5EG 6.52023-04-04
Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious network user with low privileges could potentially exploit this vulnerability in SMB, leading to a potential denial of serv…
- CVE-2023-44288HIGHCVSS 7.5EG 7.52023-12-05
Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, leading to denial of service.…
- CVE-2023-44295MEDIUMCVSS 6.3EG 6.32023-12-05
Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, a…
- CVE-2023-52387HIGHCVSS 7.5EG 7.52024-02-18
Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-22365MEDIUMCVSS 5.5EG 5.52024-02-06
linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.
- CVE-2024-23639MEDIUMCVSS 5.1EG 5.12024-02-09
Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support for Java, Kotlin and the Groovy language. Enabled but unsecured management endpoints are sus…
- CVE-2024-37139MEDIUMCVSS 6.5EG 6.52024-06-26
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a Resource Through its Lifetime vulnerability in an admin operation. A remote low privileged attacker could potentially e…
- CVE-2024-45383MEDIUMCVSS 5.0EG 5.02024-09-12
A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests…
- CVE-2024-7889HIGHCVSS 7.3EG 7.32024-09-11
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
- CVE-2026-8517HIGHCVSS 8.8EG 8.82026-05-14
Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security sever…
- CVE-2026-8582MEDIUMCVSS 5.3EG 5.32026-05-14
Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Map vulnerabilities like CWE-664 to your infrastructure
EchelonGraph correlates every CVE — across CWE-664 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →