Skip to content
Noroxi

CWE-460 · 25 records

Improper Cleanup on Thrown Exception

CVEs in this class

25 records

  • A memory corruption vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543.

    HighCVSS 8.8No exploitEPSS 2%

    foxit · pdf readerFeb 4, 2022

  • UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt

    HighCVSS 8.8No exploitEPSS 1%

    ultradag · ultradagApr 21, 2026

  • CVE-2022-4744
    31Monitor

    A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_

    HighCVSS 7.8No exploitEPSS 0%

    linux · linux kernelMar 30, 2023

  • Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks

    HighCVSS 7.5No exploitEPSS 1%

    Sep 21, 2026

  • gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' pass

    HighCVSS 7.5No exploitEPSS 0%

    gougucms · gougucmsOct 27, 2023

  • Envoy crashes when HTTP ext_proc processes local replies

    HighCVSS 7.5No exploitEPSS 0%

    envoyproxy · envoyMar 21, 2025

  • CVE-2024-0316
    30Monitor

    Improper cleanup vulnerability in FireEye Endpoint Security

    HighCVSS 7.5No exploitEPSS 0%

    fireeye · endpoint securityJan 15, 2024

  • Cisco Expressway Series and TelePresence Video Communication Server Remote Code Execution Vulnerability

    HighCVSS 7.2No exploitEPSS 2%

    cisco · expresswayAug 18, 2021

  • A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adj

    HighCVSS 7.4No exploitEPSS 0%

    cisco · wireless lan controller softwareMar 27, 2024

  • Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive

    MediumCVSS 6.9No exploitEPSS 0%

    snipeitapp · snipe-itSep 9, 2026

  • Cisco IOS-XR NCS 5500 and NCS 5700 Egress Packet Network Interfaces Aligner Interrupt Denial of Service Vulnerability

    MediumCVSS 6.8No exploitEPSS 0%

    cisco · cisco ios xr softwareMar 11, 2026

  • Ghidra before 12.1.4 Denial of Service via Unreleased Lock in OptionsDB

    MediumCVSS 6.8No exploitEPSS 0%

    nationalsecurityagency · ghidraSep 23, 2026

  • CVE-2017-9657
    26Monitor

    Under specific 802.11 network conditions, a partial re-association of the Philips IntelliVue MX40 Version B.06.18 WLAN monitor to the centra

    MediumCVSS 6.5No exploitEPSS 1%

    philips · intellivue mx40 firmwareApr 30, 2018

  • pleezer allows resource exhaustion through uncollected hook script processes

    MediumCVSS 6.5No exploitEPSS 0%

    roderickvd · pleezerApr 15, 2025

  • GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed

    MediumCVSS 6.2No exploitEPSS 0%

    gnu · binutilsMar 6, 2026

  • Boundary Controller Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service

    MediumCVSS 5.9No exploitEPSS 0%

    hashicorp · boundaryDec 12, 2024

  • A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.

    MediumCVSS 5.5No exploitEPSS 0%

    linux · linux kernelJan 14, 2018

  • CVE-2022-3707
    22Monitor

    A double-free memory flaw was found in the Linux kernel.

    MediumCVSS 5.5No exploitEPSS 0%

    linux · linux kernelMar 6, 2023

  • Syft improper temporary file cleanup

    MediumCVSS 5.3No exploitEPSS 1%

    anchore · syftMar 26, 2026

  • A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup.

    MediumCVSS 5.0No exploitEPSS 1%

    kubernetes · cri-oNov 25, 2019

  • CVE-2016-9592
    17Monitor

    openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation t

    MediumCVSS 4.3No exploitEPSS 1%

    redhat · openshiftApr 16, 2018

  • A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of the device.

    MediumCVSS 4.4No exploitEPSS 0%

    linux · linux kernelSep 15, 2020

  • PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

    LowCVSS 3.7No exploitEPSS 0%

    pyjwt project · pyjwtMay 28, 2026

  • libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error message generation.

    LowCVSS 3.1No exploitEPSS 0%

    everest · libocppSep 15, 2025

  • Improper Cleanup on Thrown Exception in ikus060/rdiffweb

    LowCVSS 2.4No exploitEPSS 1%

    ikus-soft · rdiffwebSep 26, 2022

All vulnerability classes