Vulnerabilities > Operation on a Resource after Expiration or Release

DATE CVE VULNERABILITY TITLE RISK
2022-04-01 CVE-2022-22332 Operation on a Resource after Expiration or Release vulnerability in IBM Partner Engagement Manager 6.2.0
IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token.
network
low complexity
ibm CWE-672
7.5
2021-06-24 CVE-2021-23995 Operation on a Resource after Expiration or Release vulnerability in Mozilla Thunderbird
When Responsive Design Mode was enabled, it used references to objects that were previously freed.
network
low complexity
mozilla CWE-672
8.8
2020-12-11 CVE-2020-13530 Operation on a Resource after Expiration or Release vulnerability in Opener Project Opener 2.3
A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and development commit 8c73bf3.
network
low complexity
opener-project CWE-672
7.5
2020-10-22 CVE-2020-15270 Operation on a Resource after Expiration or Release vulnerability in Parseplatform Parse-Server
Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid.
network
low complexity
parseplatform CWE-672
4.3
2020-09-10 CVE-2020-25221 Operation on a Resource after Expiration or Release vulnerability in multiple products
get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page.
local
low complexity
linux netapp CWE-672
7.8
2020-09-02 CVE-2020-24030 Operation on a Resource after Expiration or Release vulnerability in Forlogic Qualiex 1.0/3.0
ForLogic Qualiex v1 and v3 has weak token expiration.
network
low complexity
forlogic CWE-672
critical
9.8
2020-07-09 CVE-2019-17638 Operation on a Resource after Expiration or Release vulnerability in Eclipse Jetty 9.4.27/9.4.28/9.4.29
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error.
network
low complexity
eclipse CWE-672
critical
9.4
2020-06-29 CVE-2020-12043 Operation on a Resource after Expiration or Release vulnerability in Baxter Sigma Spectrum Infusion System Firmware 8.0
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the WBM remains operational until the WBM is rebooted.
network
low complexity
baxter CWE-672
critical
9.8
2020-04-24 CVE-2019-15794 Operation on a Resource after Expiration or Release vulnerability in multiple products
Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers.
local
low complexity
linux canonical CWE-672
6.7
2019-12-27 CVE-2019-20022 Operation on a Resource after Expiration or Release vulnerability in Libsixel Project Libsixel
An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.
network
low complexity
libsixel-project CWE-672
6.5