← Back
CWE-665

357 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Improper Initialization

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

JSON object

Loading...

CVEs (357)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openeuler
1Isula
Jun 17, 2026
Oct 29, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
1Openeuler
1Icr
Jun 17, 2026
Oct 29, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS.
1Freebsd
1Freebsd
Jun 17, 2026
Oct 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no speculative execution workarounds being installed on CPU 0.
1Amd
101Ryzen 3100 Firmware
Ryzen 3300x FirmwareRyzen 3500 Firmware+98 more
Jun 17, 2026
Sep 20, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
1Amd
125Epyc 7003 Firmware
Epyc 72f3 FirmwareEpyc 7313 Firmware+122 more
Jun 17, 2026
Sep 20, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
1Splunk
1Splunk
Jun 17, 2026
Aug 30, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse t...Show more
In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse this reference and subsequently install malicious code to achieve privilege escalation on the Windows machine.Show less
1Gnu
1Binutils
Jun 17, 2026
Aug 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.
1Jenkins
1Gogs
Jun 17, 2026
Aug 16, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of jobs.
1Intel
24Nuc 11 Pro Board Nuc11tnbi30z Firmware
Nuc 11 Pro Board Nuc11tnbi3 FirmwareNuc 11 Pro Board Nuc11tnbi50z Firmware+21 more
Jun 17, 2026
Aug 11, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper initialization in BIOS firmware for some Intel(R) NUCs may allow a privileged user to potentially enable information disclosure via local access.
1Intel
111Nuc 11 Compute Element Cm11ebc4w Firmware
Nuc 11 Compute Element Cm11ebi38w FirmwareNuc 11 Compute Element Cm11ebi58w Firmware+108 more
Jun 17, 2026
Aug 11, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper initialization in some Intel(R) NUC 13 Extreme Compute Element, Intel(R) NUC 13 Extreme Kit, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Compute Element, Intel(R) NUC Lapto...Show more
Improper initialization in some Intel(R) NUC 13 Extreme Compute Element, Intel(R) NUC 13 Extreme Kit, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Compute Element, Intel(R) NUC Laptop Kit, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board and Intel(R) NUC Pro Mini PC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.Show less
1Intel
211Nuc 11 Compute Element Cm11ebc4w Firmware
Nuc 11 Compute Element Cm11ebi38w FirmwareNuc 11 Compute Element Cm11ebi58w Firmware+208 more
Jun 17, 2026
Aug 11, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper initialization in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.
1Intel
237Core I5 7640x Firmware
Core I7 3820 FirmwareCore I7 3920xm Firmware+234 more
Jun 17, 2026
Aug 11, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
1Broadcom
1Brocade Fabric Operating System
Jun 17, 2026
Aug 2, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0.
1Br Automation
1Automation Runtime
Jun 17, 2026
Jul 26, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions.
1Openenclave
1Openenclave
Jun 17, 2026
Jul 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Open Enclave is a hardware-agnostic open source library for developing applications that utilize Hardware-based Trusted Execution Environments, also known as Enclaves. There are two issues that are mitigated in version 0...Show more
Open Enclave is a hardware-agnostic open source library for developing applications that utilize Hardware-based Trusted Execution Environments, also known as Enclaves. There are two issues that are mitigated in version 0.19.3. First, Open Enclave SDK does not properly sanitize the `MXCSR` register on enclave entry. This makes applications vulnerable to MXCSR Configuration Dependent Timing (MCDT) attacks, where incorrect `MXCSR` values can impact instruction retirement by at most one cycle, depending on the (secret) data operand value. Please find more details in the guidance from Intel in the references. Second, Open Enclave SDK does not sanitize x86's alignment check flag `RFLAGS.AC` on enclave entry. This opens up the possibility for a side-channel attacker to be notified for every unaligned memory access performed by the enclave. The issue has been addressed in version 0.19.3 and the current master branch. Users will need to recompile their applications against the patched libraries to be protected from this vulnerability. There are no known workarounds for this vulnerability.Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jul 6, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon...Show more
Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.Show less
1Intel
35Cm11ebc4w Firmware
Cm11ebi38w FirmwareCm11ebi58w Firmware+32 more
Jun 17, 2026
May 10, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper initialization for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.
1Apple
1Macos
Jun 17, 2026
May 8, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A memory initialization issue was addressed. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.
1Autodesk
1Maya Usd
Jun 17, 2026
Apr 17, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A malicious actor may convince a victim to open a malicious USD file that may trigger an uninitialized variable which may result in code execution.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Mar 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic.