Skip to main content

Threats Tagged 'cwe-459'

View all threats tagged with 'cwe-459'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-459

Threats Tagged 'cwe-459'

Click on any threat for detailed analysis and mitigation recommendations

Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail. This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

Join the discussion

CVE-2026-75945 is a low-severity vulnerability in Arista Networks EOS where a race condition may cause a supplicant to remain authorized after the 'clear dot1x host all' command is issued. This incomplete cleanup issue could lead to a supplicant retaining an authorized state unexpectedly.

Join the discussion

CVE-2026-75944 is a low-severity vulnerability in Arista Networks EOS where a race condition during supplicant re-authentication can cause a stale ACL entry to persist. If the AclAgent service is restarted by an administrator, this stale ACL entry may be applied incorrectly to new supplicants, leading to improper access control enforcement. This issue requires manual intervention (an AclAgent restart) to manifest.

Join the discussion

A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement.

Join the discussion

Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the associated Elasticsearch cluster.

Join the discussion

CVE-2026-77761 is a parser state isolation vulnerability in the misp-stix component of MISP. It causes data from a previously processed STIX document to be retained and mixed into subsequent MISP events when the same parser instance is reused. This affects STIX 1 and STIX 2 parsers, leading to incorrect associations and potential limited information disclosure between events. The vulnerability requires reuse of parser instances and specific document ordering, increasing exploitation complexity. There is no impact on availability or code execution.

Join the discussion

CVE-2026-67442 is an improper access control vulnerability in frangoteam's FUXA web-based Process Visualization software. Versions prior to 1.3.3 have an issue where deleting a role does not fully remove the role identifier from users' role arrays or runtime caches. This can cause users to retain permissions that administrators intended to revoke, leading to residual privileges and inconsistent access control states. The issue is fixed in version 1.3.3.

Join the discussion

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node by racing an invalid block body against the valid canonical body for the same block header hash. ZIP-244 permits the attacker to mutate coinbase scriptSig authentication data while retaining the transaction identifiers, merkle root, and block header hash, so the poisoned body fails later commitment validation but shares the canonical hash. In zebra-state/src/service.rs, queue_and_commit_to_non_finalized_state recorded the hash in non_finalized_block_write_sent_hashes before contextual validation completed and did not remove it when the write task rejected the body. When the honest body later arrived, the cached hash caused KnownBlock::WriteChannel duplicate handling to suppress it, leaving the node stuck one height behind until restart or reorganization. This issue is fixed in version 4.5.0.

Join the discussion

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment subtree roots in Zebra state. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::pop_tip removed a reverted tip block but did not remove subtree entries whose end_height belonged to that block, unlike the cleanup performed by pop_root. When the winning fork later finalized, the abandoned branch's stale subtree data could be written to RocksDB and survive node restarts. The corrupted history can cause z_getsubtreesbyindex consumers such as lightwalletd and light wallets to receive incorrect subtree roots, producing wallet synchronization failures or incorrect wallet state and requiring a full state rebuild for recovery. This issue is fixed in version 4.5.0.

Join the discussion

Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

Join the discussion

Showing 1 to 10 of 37 results

Filters:Tag: cwe-459
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses