CWE-665
352 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
CVEs (352)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Intel 2Lapbc510 Firmware Lapbc710 FirmwareJun 17, 2026 Aug 18, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Improper initialization in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via physical access. |
1Intel 2Lapbc510 Firmware Lapbc710 FirmwareJun 17, 2026 Aug 18, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper initialization in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable an escalation of privilege via local access. |
Improper initialization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access. |
1Intel 5Killer Wi Fi 6e Ax1675 Firmware Killer Wi Fi 6e Ax1690 FirmwareProset Wi Fi 6e Ax210 Firmware+2 moreJun 17, 2026 Aug 18, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper initialization for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access. |
Use after free in WebUI in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI i...Show more |
Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` connection property; however, the driver does not verify if the class implements the expected interface...Show more |
1Unicorn Engine 1Unicorn Engine Jun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unicorn Engine v2.0.0-rc7 contains memory leaks caused by an incomplete unicorn engine initialization. |
A memory initialization issue was addressed. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to gain root privileges. |
A memory initialization issue was addressed. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to gain root privileges. |
1Abb 24Arc600a2323na Firmware Arc600a2324na FirmwareArc600a2325na Firmware+21 moreJun 17, 2026 May 10, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 A vulnerability in ABB ARG600 Wireless Gateway series that could allow an attacker to exploit the vulnerability by remotely connecting to the serial port gateway, and/or protocol converter, depending on the configuration...Show more |
1Amd 23Epyc 72f3 Firmware Epyc 7313 FirmwareEpyc 7313p Firmware+20 moreJun 17, 2026 May 10, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity. |
1Cisco 2Catalyst Digital Building Series Switches Firmware Ios RommonJun 17, 2026 Apr 15, 2022 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Multiple vulnerabilities that affect Cisco Catalyst Digital Building Series Switches and Cisco Catalyst Micro Switches could allow an attacker to execute persistent code at boot time or to permanently prevent the device...Show more |
Multiple vulnerabilities that affect Cisco Catalyst Digital Building Series Switches and Cisco Catalyst Micro Switches could allow an attacker to execute persistent code at boot time or to permanently prevent the device...Show more |
Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on EX4650 devices, packets received on the management interface (em0) but not destined to the device, may be improperly forwarded to an egress...Show more |
A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6.4.7 and below, version 7.0.3 and below allows attacker to gain administrative privileges via placin...Show more |
3Debian FedoraprojectUclouvain3Debian Linux FedoraOpenjpegJun 17, 2026 Mar 29, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory,...Show more |
1Apple 3Garageband Logic Pro XMacosJun 17, 2026 Mar 18, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A memory initialization issue was addressed with improved memory handling. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected applic...Show more |
5Apache AppleDebian+2 more7Debian Linux FedoraHttp Server+4 moreJun 17, 2026 Mar 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. |
7Fedoraproject LinuxNetapp+4 more29Codeready Linux Builder Enterprise LinuxEnterprise Linux Eus+26 moreJun 17, 2026 Mar 10, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values....Show more |
1Schneider Electric 1Interactive Graphical Scada System Data Server Jun 17, 2026 Feb 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-665: Improper Initialization vulnerability exists that could cause information exposure when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0....Show more |