CWE-775: Missing Release of File Descriptor or Handle after Effective Lifetime

ID CWE-775
Abstraction Variant
Structure Simple
Status Incomplete
Number of CVEs 2
The product does not release a file descriptor or handle after its effective lifetime has ended, i.e., after the file descriptor/handle is no longer needed.

When a file descriptor or handle is not released after use (typically by explicitly closing it), attackers can cause a denial of service by consuming all available file descriptors/handles, or otherwise preventing other system processes from obtaining their own file descriptors/handles.

Modes of Introduction

Phase Note
Implementation

Relationships

View Weakness
# ID View Status # ID Name Abstraction Structure Status
CWE-1000 Research Concepts Draft CWE-772 Missing Release of Resource after Effective Lifetime Base Simple Draft
CWE-1305 CISQ Quality Measures (2020) Incomplete CWE-404 Improper Resource Shutdown or Release Class Simple Draft
CWE-1340 CISQ Data Protection Measures Incomplete CWE-404 Improper Resource Shutdown or Release Class Simple Draft

CVEs Published

CVSS Severity

CVSS Severity - By Year

CVSS Base Score

# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...
Loading...