The product does not release or incorrectly releases a resource before it is made available for re-use.
Volume of CVEs assigned to CWE-404 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
743 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8120HIGH An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." T | May 9, 2018 | 7.0 | 95 | YES | YES |
CVE-2018-8639HIGH An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." T | Dec 12, 2018 | 7.8 | 77 | YES | NO |
CVE-2022-44267MEDIUM ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input. | Feb 6, 2023 | 6.5 | 74 | NO | YES |
CVE-2018-8611HIGH An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This a | Dec 12, 2018 | 7.8 | 70 | YES | NO |
CVE-2018-8406HIGH An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Pri | Aug 15, 2018 | 7.8 | 65 | YES | NO |
CVE-2018-8405HIGH An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Pri | Aug 15, 2018 | 7.8 | 64 | YES | NO |
CVE-2017-6627HIGH A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue o | Sep 7, 2017 | 7.5 | 63 | YES | NO |
CVE-2022-2591HIGH A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0. Affected is an unknown function of the file /sistema/flash/reboot. The manipulation leads to denial of | Aug 1, 2022 | 7.5 | 38 | NO | YES |
CVE-2018-8410HIGH An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevation of Privilege Vulnerability | Sep 13, 2018 | 7.8 | 38 | NO | YES |
CVE-2018-8210HIGH A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows Server 2012 | Jun 14, 2018 | 7.8 | 38 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.