CWE-404: CWE-404

127
Total CVEs
0
Critical
36
High
5.7
Avg CVSS

Yearly Trend

2026
36
2025
59
2024
18
2023
9
2022
2

Top Affected Vendors

1 Open5gs 18
2 Free5gc 9
3 Iobit 6
4 Tenda 5
5 Gpac 4
6 Linux 4
7 Apple 4
8 F5 3
9 Asrmicro 3
10 Birkir 3

All CWE-404 CVEs (127)

CVE-2022-49745
5.5

This CVE addresses a resource leak vulnerability in the Linux kernel's FPGA Intel Max 10 BMC Secure Update driver (m10bmc-sec). The driver fails to pr...

Mar 27, 2025
CVE-2024-57879
5.5

A resource leak vulnerability in the Linux kernel's Bluetooth ISO (isochronous) subsystem where the hdev device reference isn't properly released on e...

Jan 11, 2025
CVE-2025-0223
5.5

This vulnerability in IObit Protected Folder allows local attackers to cause a denial of service (system crash) through a null pointer dereference in ...

Jan 5, 2025
CVE-2025-0221
5.5

A local null pointer dereference vulnerability in IOBit Protected Folder's pffilter.sys driver allows attackers to cause denial of service (system cra...

Jan 5, 2025
CVE-2024-12661
5.5

This vulnerability in IObit Advanced SystemCare Ultimate allows local attackers to trigger a null pointer dereference in the AscRegistryFilter.sys dri...

Dec 16, 2024
CVE-2024-12659
5.5

This vulnerability in IObit Advanced SystemCare Ultimate allows local attackers to trigger a null pointer dereference in the AscRegistryFilter.sys dri...

Dec 16, 2024
CVE-2024-12656
5.5

This vulnerability is a null pointer dereference in FabulaTech USB over Network Client's ftusbbus2.sys driver, specifically in the IOCTL handler funct...

Dec 16, 2024
CVE-2024-12654
5.5

This vulnerability in FabulaTech USB over Network allows local attackers to trigger a null pointer dereference in the ftusbbus2.sys driver via a speci...

Dec 16, 2024
CVE-2024-44201
5.5

This CVE describes a memory handling vulnerability in Apple operating systems where processing a maliciously crafted file can cause a denial-of-servic...

Dec 12, 2024
CVE-2024-46752
5.5

This CVE addresses a kernel panic vulnerability in the Linux kernel's Btrfs filesystem. When handling relocation tree extent buffers without proper ba...

Sep 18, 2024
CVE-2024-25087
5.5

A local Denial of Service vulnerability in Jungo WinDriver allows attackers with local access to cause a Windows blue screen error (BSOD), crashing th...

Jul 2, 2024
CVE-2023-1677
5.5

A local denial-of-service vulnerability exists in DriverGenius 9.70.0.346's kernel driver mydrivers64.sys. Attackers can trigger a system crash by sen...

Mar 28, 2023
CVE-2023-1644
5.5

This vulnerability in IObit Malware Fighter's IMFCameraProtect.sys driver allows local attackers to trigger a denial of service through improper IOCTL...

Mar 26, 2023
CVE-2023-1642
5.5

A local denial-of-service vulnerability exists in IObit Malware Fighter's kernel driver ObCallbackProcess.sys. Attackers with local access can trigger...

Mar 26, 2023
CVE-2023-1640
5.5

This vulnerability in IObit Malware Fighter's kernel driver allows local attackers to trigger a denial of service condition by sending specially craft...

Mar 26, 2023
CVE-2023-1639
5.5

This vulnerability in IObit Malware Fighter's kernel driver allows local attackers to trigger a denial of service condition through a specific IOCTL c...

Mar 26, 2023
CVE-2025-13564
5.4

CVE-2025-13564 is an arbitrary file deletion vulnerability in SourceCodester Pre-School Management System 1.0. Attackers can remotely manipulate the f...

Nov 23, 2025
CVE-2025-49482
5.4

This CVE describes an improper resource shutdown vulnerability in ASR180x and ASR190x TR069 modules that can lead to resource leaks. The vulnerability...

Jul 1, 2025
CVE-2025-49491
5.4

This CVE describes an improper resource shutdown vulnerability in ASR's traffic_stat modules on Linux systems, allowing resource leak exposure. It aff...

Jul 1, 2025
CVE-2025-49489
5.4

This CVE describes an improper resource shutdown vulnerability in ASR Falcon_Linux, Kestrel, and Lapwing_Linux products on Linux systems. It allows re...

Jul 1, 2025
CVE-2026-2525
5.3

A denial-of-service vulnerability exists in Free5GC's PFCP UDP Endpoint component, allowing remote attackers to crash the service by sending specially...

Feb 16, 2026
CVE-2026-2108
5.3

An unauthenticated denial-of-service vulnerability in jsbroks COCO Annotator allows remote attackers to flood the task queue via the /api/info/long_ta...

Feb 7, 2026
CVE-2026-2062
5.3

This CVE describes a null pointer dereference vulnerability in Open5GS PGW S5U Address Handler that can cause denial of service. Attackers can remotel...

Feb 6, 2026
CVE-2026-1975
5.3

A null pointer dereference vulnerability in Free5GC's pfcp_reports.go allows remote attackers to cause denial of service by triggering the identityTri...

Feb 6, 2026
CVE-2026-1976
5.3

A null pointer dereference vulnerability in Free5GC's SMF component allows remote attackers to cause denial of service by exploiting the SessionDeleti...

Feb 6, 2026
CVE-2026-1973
5.3

A null pointer dereference vulnerability in Free5GC's SMF component allows remote attackers to cause denial of service by exploiting the establishPfcp...

Feb 6, 2026
CVE-2026-1974
5.3

A denial-of-service vulnerability exists in Free5GC's SMF component where the ResolveNodeIdToIp function can be manipulated by remote attackers. This ...

Feb 6, 2026
CVE-2026-1739
5.3

A null pointer dereference vulnerability in Free5GC's Policy Control Function (PCF) allows remote attackers to cause denial of service by crashing the...

Feb 2, 2026
CVE-2026-1684
5.3

A denial-of-service vulnerability exists in Free5GC SMF's PFCP UDP Endpoint component, specifically in the HandleReports function. Attackers can remot...

Jan 30, 2026
CVE-2026-1682
5.3

A null pointer dereference vulnerability in Free5GC SMF's PFCP UDP endpoint allows remote attackers to cause denial of service by sending specially cr...

Jan 30, 2026
CVE-2026-1683
5.3

A denial-of-service vulnerability exists in Free5GC SMF's PFCP handler that allows remote attackers to crash the service by sending specially crafted ...

Jan 30, 2026
CVE-2026-1586
5.3

A denial-of-service vulnerability exists in Open5GS SGWC component where remote attackers can manipulate the ogs_gtp2_f_teid_to_ip function to crash t...

Jan 29, 2026
CVE-2026-1587
5.3

A denial-of-service vulnerability exists in Open5GS SGWC component where the sgwc_s11_handle_modify_bearer_request function can be remotely triggered ...

Jan 29, 2026
CVE-2026-1521
5.3

A remote denial-of-service vulnerability exists in Open5GS SGWC component where manipulation of the sgwc_s5c_handle_bearer_resource_failure_indication...

Jan 28, 2026
CVE-2026-1173
5.3

A denial-of-service vulnerability exists in birkir prime's GraphQL array-based query batch handler. Attackers can remotely exploit this by sending spe...

Jan 19, 2026
CVE-2026-1172
5.3

A denial-of-service vulnerability exists in birkir prime's GraphQL Directive Handler component, allowing remote attackers to crash the service via man...

Jan 19, 2026
CVE-2026-1171
5.3

This vulnerability in birkir prime's GraphQL Field Handler allows remote attackers to cause denial of service through manipulation of the /graphql end...

Jan 19, 2026
CVE-2025-15539
5.3

A denial-of-service vulnerability exists in Open5GS SGWC component where remote attackers can crash the service by sending malicious S11 protocol mess...

Jan 19, 2026
CVE-2025-15528
5.3

A denial-of-service vulnerability exists in Open5GS's GTPv2 Bearer Response Handler component. Attackers can remotely crash affected systems by sendin...

Jan 16, 2026
CVE-2025-15529
5.3

A denial-of-service vulnerability exists in Open5GS's SGWC component where remote attackers can manipulate the sgwc_s5c_handle_create_session_response...

Jan 16, 2026
CVE-2025-15229
5.3

A buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to cause denial of service by manipulating the LISTLEN parameter in the ...

Dec 30, 2025
CVE-2025-8805
5.3

A denial-of-service vulnerability exists in Open5GS SMF component where the smf_gsm_state_wait_pfcp_deletion function can be manipulated remotely to c...

Aug 10, 2025
CVE-2025-8803
5.3

This vulnerability in Open5GS AMF component allows remote attackers to cause denial of service by exploiting a flaw in the gmm_state_de_registered/gmm...

Aug 10, 2025
CVE-2025-8802
5.3

A denial-of-service vulnerability in Open5GS SMF component allows remote attackers to crash the service by manipulating stream arguments in the smf_st...

Aug 10, 2025
CVE-2025-8801
5.3

This vulnerability in Open5GS AMF component allows remote attackers to cause denial of service by exploiting a flaw in the gmm_state_exception functio...

Aug 10, 2025
CVE-2025-8800
5.3

A denial-of-service vulnerability exists in Open5GS AMF component where the esm_handle_pdn_connectivity_request function can be manipulated by remote ...

Aug 10, 2025
CVE-2025-7797
5.3

A null pointer dereference vulnerability in GPAC's DASH client allows remote attackers to cause denial of service by manipulating the base_init_url ar...

Jul 18, 2025
CVE-2025-5935
5.3

A denial-of-service vulnerability in Open5GS AMF/MME component allows remote attackers to crash the service by manipulating the ran_ue_id argument in ...

Jun 10, 2025
CVE-2024-38271
4.8

This vulnerability in Quick Share/Nearby allows an attacker to force a victim's device to remain connected to the attacker's WiFi network after a file...

Jun 26, 2024
CVE-2026-21975
4.5

This vulnerability in Oracle Database Server's Java VM component allows authenticated high-privilege attackers with network access via Oracle Net to c...

Jan 20, 2026

About CWE-404 (CWE-404)

Our database tracks 127 CVEs classified as CWE-404, with 0 rated critical and 36 rated high severity. The average CVSS score for CWE-404 vulnerabilities is 5.7.

External reference: View CWE-404 on MITRE CWE →

Monitor CWE-404 Vulnerabilities

Get alerted when new CWE-404 CVEs affect your infrastructure.

Start Monitoring Free