CWE-664— Improper Control of a Resource Through its Lifetime
The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.— MITRE CWE catalog
57 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-664page 2 of 2
- CVE-2026-79603MEDIUMCVSS 4.3EG 4.32026-09-08
x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush, t…
- CVE-2021-1592MEDIUMCVSS 4.3EG 4.32021-08-25
A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource man…
- CVE-2026-86203LOWCVSS 3.7EG 3.72026-09-09
PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing …
- CVE-2022-1385LOWCVSS 3.7EG 3.72022-04-19
Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users to join the workspace and access information from the public …
- CVE-2020-3504LOWCVSS 3.3EG 3.32020-08-27
A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper ha…
- CVE-2026-79289LOWCVSS 3.1EG 3.12026-08-25
Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security …
- CVE-2026-19380LOWCVSS 2.3EG 2.32026-08-10
A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local access is required to ap…
Map vulnerabilities like CWE-664 to your infrastructure
EchelonGraph correlates every CVE — across CWE-664 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →