← Back
CWE-665

352 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Initialization

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

JSON object

Loading...

CVEs (352)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intel
1Memory And Storage Tool
Jun 17, 2026
Feb 14, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper initialization in some Intel(R) MAS software before version 2.3 may allow an authenticated user to potentially enable denial of service via local access.
-
-
Jun 17, 2026
Feb 14, 2024
2.3 LOW· v4
4.3 MEDIUM· v3
N/A· v2
Improper initialization for the Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
1Intel
2Killer
Proset/wireless
Jun 17, 2026
Feb 14, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper initialization for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access..
1Redhat
2Jboss Enterprise Application Platform
Jboss Enterprise Application Platform Expansion Pack
Jun 17, 2026
Feb 6, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP ser...Show more
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.Show less
1Scontain
1Scone
Jun 17, 2026
Dec 30, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper initialization of x87 and SSE floating-point configuration registers in the __scone_entry component of SCONE before 5.8.0 for Intel SGX allows a local attacker to compromise the execution integrity of floating-p...Show more
Improper initialization of x87 and SSE floating-point configuration registers in the __scone_entry component of SCONE before 5.8.0 for Intel SGX allows a local attacker to compromise the execution integrity of floating-point operations in an enclave or access sensitive information via side-channel analysis.Show less
1Softiron
1Hypercloud
Jun 17, 2026
Dec 5, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without following the correct initialization process.  In this instance, workloads may be scheduled on these nodes and deploy to a fa...Show more
An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without following the correct initialization process.  In this instance, workloads may be scheduled on these nodes and deploy to a failed or erroneous state, which impacts the availability of these workloads that may be deployed during this time window. This issue impacts HyperCloud versions from 2.0.0 to before 2.0.3. Show less
1Facebook
1Katran
Jun 17, 2026
Nov 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulation and ICMP (v4) Too Big packet generation. After a bpf_xdp_adjust_head call, Katran code didn’t init...Show more
Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulation and ICMP (v4) Too Big packet generation. After a bpf_xdp_adjust_head call, Katran code didn’t initialize the Identification field for the IPv4 header, resulting in writing content of kernel memory in that field of IP header. The issue affected all Katran versions prior to commit 6a03106ac1eab39d0303662963589ecb2374c97fShow less
1Intel
1Aptio V Uefi Firmware Integrator Tools
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
5Optane Memory H20 With Solid State Storage Firmware
Optane Ssd 900p FirmwareOptane Ssd 905p Firmware+2 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper Initialization in firmware for some Intel(R) Optane(TM) SSD products may allow an authenticated user to potentially enable denial of service via local access.
1Intel
1Unison Software
Jun 17, 2026
Nov 14, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper Initialization for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.
1Intel
1Unison Software
Jun 17, 2026
Nov 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper initialization for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.
1Bitrix24
1Bitrix24
Jun 17, 2026
Nov 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim'...Show more
Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.Show less
1Openeuler
1Isula
Jun 17, 2026
Oct 29, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
When the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, the attacker can escape the container.
1Openeuler
1Isula
Jun 17, 2026
Oct 29, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container.
1Openeuler
1Isula
Jun 17, 2026
Oct 29, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
When the isula load command is used to load malicious images, attackers can execute arbitrary code.
1Openeuler
1Isula
Jun 17, 2026
Oct 29, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
1Openeuler
1Icr
Jun 17, 2026
Oct 29, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS.
1Freebsd
1Freebsd
Jun 17, 2026
Oct 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no speculative execution workarounds being installed on CPU 0.
1Amd
101Ryzen 3100 Firmware
Ryzen 3300x FirmwareRyzen 3500 Firmware+98 more
Jun 17, 2026
Sep 20, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
1Amd
125Epyc 7003 Firmware
Epyc 72f3 FirmwareEpyc 7313 Firmware+122 more
Jun 17, 2026
Sep 20, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.