CVEbaza.plSłownik CWECWE-226
Common Weakness Enumeration

CWE-226

Sensitive Information in Resource Not Removed Before Reuse

Kategoria: BaseCVE: 36
Opis

Produkt zwalnia zasób, taki jak pamięć lub plik, aby mógł być ponownie użyty, ale nie usuwa ani nie zeruje informacji zawartych w zasobie przed wykonaniem krytycznego przejścia stanu lub udostępnieniem zasobu do ponownego użytku przez inne obiekty. Może to prowadzić do ujawnienia poufnych danych poprzez dostęp do zasobu przez nieautoryzowane podmioty.

Description (EN)

The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.

Podatności CVE z CWE-226 (36)
9.2
CVSS
CRITICAL
CVE-2026-74791

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to access previously authorized template content from earlier renders without triggering TemplateLoader.Load() again.

pub. 2026-08-16
8.7
CVSS
HIGH
CVE-2019-25560

Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted MP3 file with an oversized buffer and trigger the crash by opening the file through the Browse song functionality.

pub. 2026-03-21
8.6
CVSS
HIGH
CVE-2022-39393

Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator where when a linear memory is reused for another instance the initial heap snapshot of the prior instance can be visible, erroneously to the next instance. This bug has been patched and users should upgrade to Wasmtime 2.0.2 and 1.0.2. Other mitigations include disabling the pooling allocator and disabling the `memory-init-cow`.

pub. 2022-11-10
8.3
CVSS
HIGH
CVE-2024-21850

Sensitive information in resource not removed before reuse in some Intel(R) TDX Seamldr module software before version 1.5.02.00 may allow a privileged user to potentially enable escalation of privilege via local access.

pub. 2024-11-13
8.2
CVSS
HIGH
CVE-2026-13585

Podatność w sterowniku ASUS System Control Interface oraz ASUS Business Manager umożliwia lokalnemu administratorowi ujawnienie wrażliwych danych poprzez spreparowane żądania IOCTL, a w poważniejszych przypadkach może doprowadzić do odmowy usługi (DoS) na systemie. Wynika z braku limitów alokacji zasobów oraz nieprawidłowego czyszczenia wrażliwych danych przed ponownym użyciem zasobu.

pub. 2026-07-15
7.9
CVSS
HIGH
CVE-2025-0647

In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.

pub. 2026-01-14
7.5
CVSS
HIGH
CVE-2026-47247

Podatność w bibliotece libheif (przed wersją 1.22.0) pozwala na wyciek zawartości pamięci sterty procesu jako widocznych wartości pikseli w dekodowanych obrazach gridowych. Atakujący może odczytać wrażliwe dane z pamięci serwera, w tym wskaźniki funkcji bibliotecznych wystarczające do obejścia mechanizmu ASLR.

pub. 2026-07-21
7.5
CVSS
HIGH
CVE-2024-38275

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

pub. 2024-06-18
7.5
CVSS
HIGH
CVE-2023-41138

The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process.

pub. 2023-11-09
7.5
CVSS
HIGH
CVE-2018-7166

In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory. This method is intended to be safe and only return initialized, or cleared, memory. The third argument specifying `encoding` can be passed as a number, this is misinterpreted by `Buffer's` internal "fill" method as the `start` to a fill operation. This flaw may be abused where `Buffer.alloc()` arguments are derived from user input to return uncleared memory blocks that may contain sensitive information.

pub. 2018-08-21
7.4
CVSS
HIGH
CVE-2026-5795

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals. A subsequent request using the same thread inherits the ThreadLocal values, leading to a broken access control and privilege escalation.

pub. 2026-04-08
7.1
CVSS
HIGH
CVE-2026-32960

SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed before reuse. An attacker may login to the device without knowing the password by sending a crafted packet.

pub. 2026-04-20
6.9
CVSS
MEDIUM
CVE-2019-25645

WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 zawiera podatność DoS, która pozwala lokalnym atakującym spowodować crash aplikacji poprzez przetwarzanie nieprawidłowo sformatowanych plików AVI. Atakujący mogą utworzyć specjalnie przygotowany plik AVI z przeładowanym buforem i załadować go poprzez funkcję Convert to iPhone, aby wyzwolić crash aplikacji.

pub. 2026-03-24
6.9
CVSS
MEDIUM
CVE-2019-25617

Ease Audio Converter 5.30 zawiera podatność denial of service w funkcji Audio Cutter, która pozwala lokalnym atakującym na zawieszenie aplikacji poprzez przetwarzanie zmodyfikowanych plików MP4. Atakujący mogą utworzyć spreparowany plik MP4 zawierający oversized buffer i załadować go przez interfejs Audio Cutter, aby wyzwolić crash aplikacji.

pub. 2026-03-22
6.9
CVSS
MEDIUM
CVE-2019-25553

CEWE PHOTO IMPORTER 6.4.3 zawiera lukę denial of service, która pozwala lokalnym atakującym zapaść aplikację poprzez importowanie specjalnie przygotowanego pliku obrazu. Atakujący mogą utworzyć zniekształcony plik JPG z przeznaczonym buforem i wywołać crash poprzez funkcjonalność importu podczas przepływu przetwarzania obrazu.

pub. 2026-03-21
6.9
CVSS
MEDIUM
CVE-2019-25563

PCHelpWareV2 1.0.0.5 zawiera podatność DoS umożliwiającą atakującym z dostępem lokalnym rozwalenie aplikacji poprzez dostarczenie zniekształconego pliku obrazu. Atakujący mogą wyzwolić podatność za pomocą funkcji Create SC, wybierając crafted plik BMP z oversized bufferem, co powoduje crash aplikacji.

pub. 2026-03-21
6.9
CVSS
MEDIUM
CVE-2019-25571

MediaMonkey 4.1.23 zawiera lukę denial of service pozwalającą lokalnym atakującym na awarie aplikacji przez otwarcie specjalnie przygotowanego pliku MP3 zawierającego nadmiernie długi ciąg URL. Atakujący mogą utworzyć złośliwy plik MP3 z buforem zawierającym 4000 bajtów danych dołączonych do URL, co powoduje awarię aplikacji podczas otwierania pliku poprzez dialog File > Open URL.

pub. 2026-03-21
6.8
CVSS
MEDIUM
CVE-2019-25657

AnyBurn 4.3 x86 zawiera podatność denial of service, która pozwala atakującym z dostępem lokalnym na spowodowanie awarii aplikacji poprzez podanie nadmiernie długiego ciągu znaków do funkcji konwersji obrazu. Atakujący mogą wkleić duży buffer w pola pliku obrazu źródłowego lub docelowego i kliknąć „Convert Now", aby wyzwolić crash.

pub. 2026-04-05
6.5
CVSS
MEDIUM
CVE-2025-2522

The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in buffer reuse which may cause incorrect system behavior. Honeywell also recommends updating to the most recent version of Honeywell Experion PKS:520.2 TCU9 HF1 and 530.1 TCU3 HF1 and OneWireless: 322.5 and 331.1.  The affected Experion PKS products are C300, FIM4, FIM8, UOC, CN100, HCA, C300PM, and C200E. The Experion PKS versions affected are 520.1 before 520.2 TCU9 HF1 and 530 before 530 TCU3. The OneWireless WDM affected versions are 322.1 through 322.4 and 330.1 through 330.3.

pub. 2025-07-10
6.3
CVSS
MEDIUM
CVE-2026-74250

In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.

pub. 2026-08-14
Pokazano 20 z 36 podatności
Informacje
ID: CWE-226
Typ: Base
Podatności: 36
MITRE CWE ↗
← Słownik CWE