CWE-665
352 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
CVEs (352)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apache CanonicalDebian+1 more4Camel Debian LinuxHtmlunit+1 moreJun 17, 2026 Feb 11, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded...Show more |
USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 have an information leakage vulnerability. Due to improper processing of the initi...Show more |
The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization. |
Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
hdf/dataobject.c in libmysofa before 0.8 has an uninitialized use of memory, as demonstrated by mysofa2json. |
A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with system privileges. |
1Apple 4Iphone Os Mac Os XTvos+1 moreJun 17, 2026 Dec 18, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to elevate privileges. |
1Apple 4Iphone Os Mac Os XTvos+1 moreJun 17, 2026 Dec 18, 2019 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory lay...Show more |
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A local user may be able to read kernel memory. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraGlibc+1 moreJun 17, 2026 Nov 19, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to re...Show more |
1Intel 1Software Guard Extensions Sdk Jun 17, 2026 Nov 14, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Insufficient initialization in Intel(R) SGX SDK Windows versions 2.4.100.51291 and earlier, and Linux versions 2.6.100.51363 and earlier, may allow an authenticated user to enable information disclosure, escalation of pr...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Nov 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists when the Windows Remote Procedure Call (RPC) runtime improperly initializes objects in memory, aka 'Windows Remote Procedure Call Information Disclosure Vulnerability'. |
1Redhat 2Enterprise Linux Enterprise MrgNov 21, 2024 Nov 6, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace. |
4Canonical DebianLibvnc Project+1 more9Debian Linux LibvncserverSimatic Itc1500 Firmware+6 moreJun 17, 2026 Oct 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with...Show more |
1Mozilla 2Firefox Firefox EsrJun 17, 2026 Sep 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security (HSTS) settings recei...Show more |
In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initialize the resp data structure, which might allow attackers to obtain sensitive information from kernel s...Show more |
A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected dev...Show more |
An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'. |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Sep 11, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. |
3Debian DockerOpensuse3Debian Linux DockerLeapJun 17, 2026 Jul 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container. |