CWE-665— Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.— MITRE CWE catalog
361 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-665page 4 of 8
- CVE-2020-26933HIGHCVSS 7.2EG 7.22020-11-18
Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper initialization of th…
- CVE-2020-26957MEDIUMCVSS 6.5EG 6.52020-12-09
OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating …
- CVE-2020-27950CRITICALCVSS 5.5EG 9.0⚠ KEV2020-12-08
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.…
- CVE-2020-28019HIGHCVSS 7.5EG 8.42021-05-06
Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of certain getc functions is mishandled when a client uses BDAT instead of DATA.
- CVE-2020-35342HIGHCVSS 7.5EG 7.52023-08-22
GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.
- CVE-2020-35508MEDIUMCVSS 4.5EG 4.52021-03-26
A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to …
- CVE-2020-3573HIGHCVSS 7.8EG 7.82020-11-06
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation…
- CVE-2020-36432CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matrix::new().
- CVE-2020-3811HIGHCVSS 7.5EG 7.52020-05-26
qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
- CVE-2020-3872MEDIUMCVSS 5.5EG 5.52020-02-27
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to read restricted memory.
- CVE-2020-3919HIGHCVSS 7.8EG 7.82020-04-01
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A malicious application may be able to execute arbitrary code with …
- CVE-2020-4067HIGHCVSS 7.0EG 7.02020-06-29
In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to …
- CVE-2020-5529HIGHCVSS 8.1EG 8.12020-02-11
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android applica…
- CVE-2020-8744HIGHCVSS 7.8EG 7.82020-11-12
Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentia…
- CVE-2020-8918MEDIUMCVSS 6.3EG 6.32020-08-11
An improperly initialized 'migrationAuth' value in Google's go-tpm TPM1.2 library versions prior to 0.3.0 can lead an eavesdropping attacker to discover the auth value for a key created with CreateWrapKey. An attacker listening in on the c…
- CVE-2020-9775MEDIUMCVSS 5.3EG 5.32020-04-01
An issue existed in the handling of tabs displaying picture in picture video. The issue was corrected with improved state handling. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user's private browsing activity may be unexpectedly sav…
- CVE-2020-9833MEDIUMCVSS 5.5EG 5.52020-06-09
A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.5. A local user may be able to read kernel memory.
- CVE-2020-9863HIGHCVSS 7.8EG 7.82020-10-22
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An application may be able to execute arbitrary code with kerne…
- CVE-2020-9964MEDIUMCVSS 5.5EG 5.52020-10-16
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 14.0 and iPadOS 14.0. A local user may be able to read kernel memory.
- CVE-2021-0053MEDIUMCVSS 5.7EG 5.72021-11-17
Improper initialization in firmware for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an authenticated user to potentially enable information disclosure via adjacent access.
- CVE-2021-0061HIGHCVSS 7.8EG 7.82021-08-11
Improper initialization in some Intel(R) Graphics Driver before version 27.20.100.9030 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-0095MEDIUMCVSS 4.4EG 4.42021-06-09
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.
- CVE-2021-0114MEDIUMCVSS 6.7EG 6.72021-08-16
Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
- CVE-2021-0119MEDIUMCVSS 6.2EG 6.22022-02-09
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
- CVE-2021-0120MEDIUMCVSS 5.5EG 5.52021-11-17
Improper initialization in the installer for some Intel(R) Graphics DCH Drivers for Windows 10 before version 27.20.100.9316 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2021-0125MEDIUMCVSS 6.6EG 6.62022-02-09
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
- CVE-2021-0145MEDIUMCVSS 5.5EG 5.52022-02-09
Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2021-0226HIGHCVSS 7.1EG 7.12021-04-22
On Juniper Networks Junos OS Evolved devices, receipt of a specific IPv6 packet may cause an established IPv6 BGP session to terminate, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will crea…
- CVE-2021-0234MEDIUMCVSS 5.8EG 5.82021-04-22
Due to an improper Initialization vulnerability on Juniper Networks Junos OS QFX5100-96S devices with QFX 5e Series image installed, ddos-protection configuration changes will not take effect beyond the default DDoS (Distributed Denial of …
- CVE-2021-0280HIGHCVSS 7.5EG 7.52021-07-15
Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on PTX platforms and QFX10K Series with Paradise (PE) chipset-based line cards, ddos-protection configuration changes made from the CLI will not take effect as ex…
- CVE-2021-0423MEDIUMCVSS 5.5EG 5.52021-09-27
In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat…
- CVE-2021-0435HIGHCVSS 7.5EG 7.52021-04-13
In avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed fo…
- CVE-2021-0449MEDIUMCVSS 4.4EG 4.42021-03-10
In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2021-0450MEDIUMCVSS 4.4EG 4.42021-03-10
In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2021-0451MEDIUMCVSS 4.4EG 4.42021-03-10
In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2021-0452MEDIUMCVSS 4.4EG 4.42021-03-10
In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2021-0453MEDIUMCVSS 4.4EG 4.42021-03-10
In the Titan-M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2021-1661HIGHCVSS 7.8EG 7.82021-01-12
Windows Installer Elevation of Privilege Vulnerability
- CVE-2021-1780MEDIUMCVSS 4.4EG 4.42021-04-02
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 14.4 and iPadOS 14.4. An attacker in a privileged position may be able to perform a denial of service attack.
- CVE-2021-1820MEDIUMCVSS 6.5EG 6.52021-09-08
A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. Processing maliciously crafted web content may result in the disclosure…
- CVE-2021-1857MEDIUMCVSS 6.5EG 6.52021-09-08
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, …
- CVE-2021-1860MEDIUMCVSS 6.5EG 6.52021-09-08
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. A m…
- CVE-2021-20317MEDIUMCVSS 4.4EG 4.42021-09-27
A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of servi…
- CVE-2021-20613HIGHCVSS 7.5EG 7.52022-01-14
Improper initialization vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.16 and prior, FX3U-ENET-L Firmware version 1.16 and prior and FX3U-ENET-P502 Firmware version 1.16 and prior allows a remote unauthenticated attacker to …
- CVE-2021-22283MEDIUMCVSS 6.2EG 6.22023-02-28
Improper Initialization vulnerability in ABB Relion protection relays - 611 series, ABB Relion protection relays - 615 series IEC 4.0 FP1, ABB Relion protection relays - 615 series CN 4.0 FP1, ABB Relion protection relays - 615 series IEC …
- CVE-2021-23223HIGHCVSS 7.8EG 7.82022-08-18
Improper initialization for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2021-26312MEDIUMCVSS 5.5EG 5.52021-11-16
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.
- CVE-2021-26326HIGHCVSS 7.8EG 7.82021-11-16
Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity.
- CVE-2021-26353HIGHCVSS 7.8EG 7.82022-05-10
Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity.
- CVE-2021-28688MEDIUMCVSS 6.5EG 6.52021-04-06
The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite pointers which are in ne…
Map vulnerabilities like CWE-665 to your infrastructure
EchelonGraph correlates every CVE — across CWE-665 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →