CWE-403 · 7 records
Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')
CVEs in this class
7 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-21626Weaponized | runc container breakout through process.cwd trickery and leaked fdslinuxfoundation · runc · CWE-403 | High8.6 | — | 18.9% | Jan 31, 2024 |
37Monitor | CVE-2026-40042No exploit | Pachno 1.0.6 Wiki TextParser XML External Entity Injectionpachno · pachno · CWE-403 | Critical9.3 | — | 0.6% | Apr 13, 2026 |
37Monitor | CVE-2025-15114No exploit | Ksenia Security lares Home Automation 1.6 PIN Exposure Vulnerabilitykseniasecurity · lares firmware · CWE-403 | Critical9.3 | — | 0.5% | Dec 30, 2025 |
35Monitor | CVE-2026-16526No exploit | Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerabilityred hat · red hat enterprise linux 10 · CWE-403 | High8.8 | — | 0.6% | Jul 30, 2026 |
34Monitor | CVE-2024-58280No exploit | CMSimple 5.15 Remote Command Execution via Extensions Configurationcmsimple · cmsimple · CWE-403 | High8.6 | — | 0.9% | Dec 10, 2025 |
29Monitor | CVE-2025-3032No exploit | Leaking file descriptors from the fork servermozilla · firefox · CWE-403 | High7.4 | — | 0.4% | Apr 1, 2025 |
17Monitor | CVE-2026-33263No exploit | When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor haopen-xchange gmbh · ox dovecot pro · CWE-403 | Medium4.3 | — | 0.6% | Aug 28, 2026 |
- CVE-2024-2162640Plan
runc container breakout through process.cwd trickery and leaked fds
HighCVSS 8.6WeaponizedEPSS 19%linuxfoundation · runcJan 31, 2024
- CVE-2026-4004237Monitor
Pachno 1.0.6 Wiki TextParser XML External Entity Injection
CriticalCVSS 9.3No exploitEPSS 1%pachno · pachnoApr 13, 2026
- CVE-2025-1511437Monitor
Ksenia Security lares Home Automation 1.6 PIN Exposure Vulnerability
CriticalCVSS 9.3No exploitEPSS 1%kseniasecurity · lares firmwareDec 30, 2025
- CVE-2026-1652635Monitor
Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability
HighCVSS 8.8No exploitEPSS 1%red hat · red hat enterprise linux 10Jul 30, 2026
- CVE-2024-5828034Monitor
CMSimple 5.15 Remote Command Execution via Extensions Configuration
HighCVSS 8.6No exploitEPSS 1%cmsimple · cmsimpleDec 10, 2025
- CVE-2025-303229Monitor
Leaking file descriptors from the fork server
HighCVSS 7.4No exploitEPSS 0%mozilla · firefoxApr 1, 2025
- CVE-2026-3326317Monitor
When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor ha
MediumCVSS 4.3No exploitEPSS 1%open-xchange gmbh · ox dovecot proAug 28, 2026