Vulnerabilities > Incomplete Cleanup

DATE CVE VULNERABILITY TITLE RISK
2021-06-16 CVE-2021-32928 Incomplete Cleanup vulnerability in Thalesgroup Sentinel LDK Run-Time Environment 7.6
The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows incoming connections from private networks using TCP Port 1947.
network
low complexity
thalesgroup CWE-459
critical
9.8
2021-06-09 CVE-2020-24489 Incomplete Cleanup vulnerability in multiple products
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel debian CWE-459
8.8
2021-04-14 CVE-2020-36322 Incomplete Cleanup vulnerability in multiple products
An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf.
local
low complexity
linux debian starwindsoftware CWE-459
5.5
2021-04-06 CVE-2021-26833 Incomplete Cleanup vulnerability in Timelybills 1.21.115/1.7.0
Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attacker who can locally read user's files obtain JWT tokens for user's account due to insufficient cache clearing mechanisms.
network
high complexity
timelybills CWE-459
5.9
2021-02-17 CVE-2020-24458 Incomplete Cleanup vulnerability in Intel Killer and Proset/Wireless Wifi
Incomplete cleanup in some Intel(R) PROSet/Wireless WiFi and Killer (TM) drivers before version 22.0 may allow a privileged user to potentially enable information disclosure and denial of service<b>&nbsp;</b>via adjacent access.
low complexity
intel CWE-459
5.2
2021-01-07 CVE-2020-13451 Incomplete Cleanup vulnerability in Thecodingmachine Gotenberg
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.
network
low complexity
thecodingmachine CWE-459
critical
9.8
2020-10-27 CVE-2019-8732 Incomplete Cleanup vulnerability in Apple Iphone OS
The issue was addressed with improved data deletion.
low complexity
apple CWE-459
2.4
2020-10-07 CVE-2020-13346 Incomplete Cleanup vulnerability in Gitlab
Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
network
low complexity
gitlab CWE-459
6.5
2020-10-02 CVE-2020-5987 Incomplete Cleanup vulnerability in Nvidia Virtual GPU Manager
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin in which guest-supplied parameters remain writable by the guest after the plugin has validated them, which may lead to the guest being able to pass invalid parameters to plugin handlers, which may lead to denial of service or escalation of privileges.
local
low complexity
nvidia CWE-459
7.8
2020-09-18 CVE-2020-0286 Incomplete Cleanup vulnerability in Google Android 11.0
In Bluetooth AVRCP, there is a possible leak of audio metadata due to residual data.
network
low complexity
google CWE-459
7.5