CWE-665
352 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
CVEs (352)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability classified as critical was found in TechPowerUp RealTemp 3.7.0.0. This vulnerability affects unknown code in the library WinRing0x64.sys. The manipulation leads to improper initialization. An attack has t...Show more |
Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack |
Improper initialization in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 181Xeon Bronze 3104 Firmware Xeon Bronze 3106 FirmwareXeon Bronze 3204 Firmware+178 moreJun 17, 2026 Feb 16, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 467Celeron 1000m Firmware Celeron 1005m FirmwareCeleron 1007u Firmware+464 moreJun 17, 2026 Feb 16, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper initialization in the Intel(R) TXT SINIT ACM for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 Feb 1, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a v...Show more |
A malicious / defect bluetooth controller can cause a Denial of Service due to unchecked input in le_read_buffer_size_complete. |
An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero MasterSecret that can decrypt secret data. |
Tokio is a runtime for writing applications with Rust. Starting with version 1.7.0 and prior to versions 1.18.4, 1.20.3, and 1.23.1, when configuring a Windows named pipe server, setting `pipe_mode` will reset `reject_re...Show more |
Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks. |
1Wordpress Popular Posts Project 1Wordpress Popular Posts Jun 17, 2026 Dec 7, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal...Show more |
NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accou...Show more |
1Intel 11Nuc 11 Pro Board Nuc11tnbi30z Firmware Nuc 11 Pro Board Nuc11tnbi50z FirmwareNuc 11 Pro Board Nuc11tnbi70z Firmware+8 moreJun 17, 2026 Nov 11, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper initialization in BIOS firmware for some Intel(R) NUC 11 Pro Kits and Intel(R) NUC 11 Pro Boards before version TNTGL357.0064 may allow an authenticated user to potentially enable escalation of privilege via loc...Show more |
1Openzeppelin 2Contracts Contracts UpgradeableJun 17, 2026 Nov 4, 2022 N/A· v4 5.6 MEDIUM· v3 N/A· v2 OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initializer functions that are invoked separate from contract creation (the most prominent example being mi...Show more |
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result coo...Show more |
1Apple 6Ipados Iphone OsMac Os X+3 moreJun 17, 2026 Sep 23, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Cata...Show more |
Improper Initialization vulnerability in the local server component of EZVIZ CS-C6N-A0-1C2WFR allows a local attacker to read the contents of the memory space containing the encrypted admin password. This issue affects:...Show more |
Elrond go is the go implementation for the Elrond Network protocol. In versions prior to 1.3.35, read only calls between contracts can generate smart contracts results. For example, if contract A calls in read only mode...Show more |
In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end. |
A flaw was found in the Linux kernel’s implementation of reading the SVC RDMA counters. Reading the counter sysctl panics the system. This flaw allows a local attacker with local access to cause a denial of service while...Show more |