CWE-665— Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.— MITRE CWE catalog
361 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-665page 5 of 8
- CVE-2021-29609MEDIUMCVSS 5.3EG 5.32021-05-14
TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseAdd` results in allowing attackers to exploit undefined behavior (dereferencing null pointers) as well as write outside of bounds of hea…
- CVE-2021-29610LOWCVSS 3.6EG 3.62021-05-14
TensorFlow is an end-to-end open source platform for machine learning. The validation in `tf.raw_ops.QuantizeAndDequantizeV2` allows invalid values for `axis` argument:. The validation(https://github.com/tensorflow/tensorflow/blob/eccb7ec4…
- CVE-2021-29611LOWCVSS 3.6EG 3.62021-05-14
TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseReshape` results in a denial of service based on a `CHECK`-failure. The implementation(https://github.com/tensorflow/tensorflow/blob/e87…
- CVE-2021-29613MEDIUMCVSS 6.3EG 6.32021-05-14
TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `tf.raw_ops.CTCLoss` allows an attacker to trigger an OOB read from heap. The fix will be included in TensorFlow 2.5.0. We will also cherrypick…
- CVE-2021-29614HIGHCVSS 7.1EG 7.12021-05-14
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.io.decode_raw` produces incorrect results and crashes the Python interpreter when combining `fixed_length` and wider datatypes. The implementa…
- CVE-2021-30962MEDIUMCVSS 5.5EG 5.52021-08-24
A memory initialization issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Big Sur 11.6.2. Parsing a maliciously crafted audio file may lead to disclosure of user information.
- CVE-2021-33130MEDIUMCVSS 4.6EG 4.62022-05-12
Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated user to potentially enable information disclosure via physical access.
- CVE-2021-3329CRITICALCVSS 9.6EG 9.62023-02-26
Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack
- CVE-2021-33634MEDIUMCVSS 6.3EG 6.32023-10-29
iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS.
- CVE-2021-33635CRITICALCVSS 9.8EG 9.82023-10-29
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
- CVE-2021-33636HIGHCVSS 8.4EG 8.42023-10-29
When the isula load command is used to load malicious images, attackers can execute arbitrary code.
- CVE-2021-33637HIGHCVSS 8.4EG 8.42023-10-29
When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container.
- CVE-2021-33638HIGHCVSS 8.4EG 8.42023-10-29
When the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, the attacker can escape the container.
- CVE-2021-34697MEDIUMCVSS 5.8EG 5.82021-09-23
A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct denial of service (DoS) attacks to or through the affected device. …
- CVE-2021-34703MEDIUMCVSS 6.8EG 6.82021-09-23
A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and Cisco IOS XE Software could allow an attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.…
- CVE-2021-3565MEDIUMCVSS 5.9EG 5.92021-06-04
A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highe…
- CVE-2021-35995LOWCVSS 3.3EG 3.32021-09-02
Adobe After Effects version 18.2.1 (and earlier) is affected by an Improper input validation vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory in…
- CVE-2021-36006LOWCVSS 3.3EG 3.32021-08-20
Adobe Photoshop versions 21.2.9 (and earlier) and 22.4.2 (and earlier) are affected by an Improper input validation vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to discl…
- CVE-2021-36319LOWCVSS 3.3EG 3.32021-11-20
Dell Networking OS10 versions 10.4.3.x, 10.5.0.x and 10.5.1.x contain an information exposure vulnerability. A low privileged authenticated malicious user can gain access to SNMP authentication failure messages.
- CVE-2021-38647CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-15
Open Management Infrastructure Remote Code Execution Vulnerability
- CVE-2021-39636MEDIUMCVSS 4.4EG 4.42021-12-15
In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is…
- CVE-2021-40025HIGHCVSS 7.5EG 7.52022-01-10
The eID module has a vulnerability that causes the memory to be used without being initialized,Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2021-41264CRITICALCVSS 9.8EG 9.82021-11-12
OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. A fix is included in ve…
- CVE-2021-4218MEDIUMCVSS 5.5EG 5.52022-08-24
A flaw was found in the Linux kernel’s implementation of reading the SVC RDMA counters. Reading the counter sysctl panics the system. This flaw allows a local attacker with local access to cause a denial of service while the system reboo…
- CVE-2021-44169HIGHCVSS 8.2EG 8.82022-04-06
A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6.4.7 and below, version 7.0.3 and below allows attacker to gain administrative privileges via placing a malicious execu…
- CVE-2021-46283MEDIUMCVSS 5.5EG 5.52022-01-11
nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denial of service (NULL pointer dereference and general protection fault) because of the missing initialization for nft_set_…
- CVE-2021-46320HIGHCVSS 7.5EG 7.52022-02-04
In OpenZeppelin <=v4.4.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) may be reentered if they make an untrusted non-view external call. Once an initializer has …
- CVE-2021-46932MEDIUMCVSS 5.5EG 5.52024-02-27
In the Linux kernel, the following vulnerability has been resolved: Input: appletouch - initialize work before device registration Syzbot has reported warning in __flush_work(). This warning is caused by work->func == NULL, which means m…
- CVE-2021-47194HIGHCVSS 7.8EG 7.82024-04-10
In the Linux kernel, the following vulnerability has been resolved: cfg80211: call cfg80211_stop_ap when switch from P2P_GO type If the userspace tools switch from NL80211_IFTYPE_P2P_GO to NL80211_IFTYPE_ADHOC via send_msg(NL80211_CMD_SE…
- CVE-2022-0847CRITICALCVSS 7.8EG 9.0⚠ KEV2022-03-10
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged lo…
- CVE-2022-0947CRITICALCVSS 9.0EG 9.82022-05-10
A vulnerability in ABB ARG600 Wireless Gateway series that could allow an attacker to exploit the vulnerability by remotely connecting to the serial port gateway, and/or protocol converter, depending on the configuration.
- CVE-2022-1122MEDIUMCVSS 5.5EG 5.52022-03-29
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on …
- CVE-2022-20015MEDIUMCVSS 4.4EG 4.42022-01-04
In kd_camera_hw driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch I…
- CVE-2022-20661MEDIUMCVSS 4.6EG 4.62022-04-15
Multiple vulnerabilities that affect Cisco Catalyst Digital Building Series Switches and Cisco Catalyst Micro Switches could allow an attacker to execute persistent code at boot time or to permanently prevent the device from booting, resul…
- CVE-2022-20731MEDIUMCVSS 4.6EG 6.82022-04-15
Multiple vulnerabilities that affect Cisco Catalyst Digital Building Series Switches and Cisco Catalyst Micro Switches could allow an attacker to execute persistent code at boot time or to permanently prevent the device from booting, resul…
- CVE-2022-21724HIGHCVSS 7.0EG 7.02022-02-02
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url o…
- CVE-2022-22164MEDIUMCVSS 6.5EG 6.52022-01-19
An Improper Initialization vulnerability in Juniper Networks Junos OS Evolved may cause a commit operation for disabling the telnet service to not take effect as expected, resulting in the telnet service staying enabled. When it is not int…
- CVE-2022-22169MEDIUMCVSS 5.9EG 5.92022-01-19
An Improper Initialization vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker who sends specific packets in certain orders and at specific timings to force OSPFv3 to unex…
- CVE-2022-22186HIGHCVSS 7.2EG 7.22022-04-14
Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on EX4650 devices, packets received on the management interface (em0) but not destined to the device, may be improperly forwarded to an egress interface, instead …
- CVE-2022-22657HIGHCVSS 7.8EG 7.82022-03-18
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination o…
- CVE-2022-22719HIGHCVSS 7.5EG 8.62022-03-14
A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
- CVE-2022-22815MEDIUMCVSS 6.5EG 6.52022-01-10
path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
- CVE-2022-24316HIGHCVSS 7.5EG 7.52022-02-09
A CWE-665: Improper Initialization vulnerability exists that could cause information exposure when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)
- CVE-2022-24378MEDIUMCVSS 5.5EG 5.52022-08-18
Improper initialization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-2472HIGHCVSS 7.6EG 7.62022-09-15
Improper Initialization vulnerability in the local server component of EZVIZ CS-C6N-A0-1C2WFR allows a local attacker to read the contents of the memory space containing the encrypted admin password. This issue affects: EZVIZ CS-C6N-A0-1C2…
- CVE-2022-2620HIGHCVSS 8.8EG 8.82022-08-12
Use after free in WebUI in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
- CVE-2022-26721HIGHCVSS 7.8EG 7.82022-05-26
A memory initialization issue was addressed. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to gain root privileges.
- CVE-2022-26722HIGHCVSS 7.8EG 7.82022-05-26
A memory initialization issue was addressed. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to gain root privileges.
- CVE-2022-27493HIGHCVSS 7.8EG 7.82022-08-18
Improper initialization in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable an escalation of privilege via local access.
- CVE-2022-29695HIGHCVSS 7.5EG 7.52022-06-02
Unicorn Engine v2.0.0-rc7 contains memory leaks caused by an incomplete unicorn engine initialization.
Map vulnerabilities like CWE-665 to your infrastructure
EchelonGraph correlates every CVE — across CWE-665 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →