CWE-665— Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.— MITRE CWE catalog
361 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-665page 6 of 8
- CVE-2022-30704HIGHCVSS 7.2EG 7.22023-02-16
Improper initialization in the Intel(R) TXT SINIT ACM for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2022-31477MEDIUMCVSS 4.0EG 4.02023-05-10
Improper initialization for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2022-32231HIGHCVSS 7.5EG 7.52023-02-16
Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2022-32579HIGHCVSS 7.2EG 7.22022-08-18
Improper initialization in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via physical access.
- CVE-2022-3259HIGHCVSS 7.4EG 7.42022-12-09
Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.
- CVE-2022-32823MEDIUMCVSS 5.5EG 5.52022-09-23
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be…
- CVE-2022-34153HIGHCVSS 8.2EG 8.22023-02-16
Improper initialization in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-36061MEDIUMCVSS 6.5EG 6.52022-09-06
Elrond go is the go implementation for the Elrond Network protocol. In versions prior to 1.3.35, read only calls between contracts can generate smart contracts results. For example, if contract A calls in read only mode contract B and the …
- CVE-2022-36364HIGHCVSS 8.8EG 8.82022-07-28
Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` connection property; however, the driver does not verify if the class implements the expected interface before instantiati…
- CVE-2022-37128CRITICALCVSS 9.8EG 9.82022-08-31
In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.
- CVE-2022-37334HIGHCVSS 7.8EG 7.82022-11-11
Improper initialization in BIOS firmware for some Intel(R) NUC 11 Pro Kits and Intel(R) NUC 11 Pro Boards before version TNTGL357.0064 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-38083MEDIUMCVSS 6.1EG 6.12023-08-11
Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2022-39284LOWCVSS 2.6EG 2.62022-10-06
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result cookie values are erro…
- CVE-2022-39384MEDIUMCVSS 5.6EG 5.62022-11-04
OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) may …
- CVE-2022-43468HIGHCVSS 7.5EG 7.52022-12-07
External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a re…
- CVE-2022-45109LOWCVSS 3.3EG 3.32023-11-14
Improper initialization for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2022-46164CRITICALCVSS 9.4EG 9.42022-12-05
NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerabi…
- CVE-2022-46301LOWCVSS 1.9EG 1.92023-11-14
Improper Initialization for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.
- CVE-2022-46487HIGHCVSS 7.8EG 7.82023-12-30
Improper initialization of x87 and SSE floating-point configuration registers in the __scone_entry component of SCONE before 5.8.0 for Intel SGX allows a local attacker to compromise the execution integrity of floating-point operations in …
- CVE-2022-46505HIGHCVSS 7.5EG 7.52023-01-18
An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero MasterSecret that can decrypt secret data.
- CVE-2022-48352HIGHCVSS 7.5EG 7.52023-03-27
Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic.
- CVE-2022-48518MEDIUMCVSS 5.5EG 5.52023-07-06
Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofi…
- CVE-2023-0397CRITICALCVSS 9.6EG 9.62023-01-19
A malicious / defect bluetooth controller can cause a Denial of Service due to unchecked input in le_read_buffer_size_complete.
- CVE-2023-1047HIGHCVSS 5.3EG 7.82023-02-26
A vulnerability classified as critical was found in TechPowerUp RealTemp 3.7.0.0. This vulnerability affects unknown code in the library WinRing0x64.sys. The manipulation leads to improper initialization. An attack has to be approached loc…
- CVE-2023-1048HIGHCVSS 5.3EG 7.82023-02-26
A vulnerability, which was classified as critical, has been found in TechPowerUp Ryzen DRAM Calculator 1.2.0.5. This issue affects some unknown processing in the library WinRing0x64.sys. The manipulation leads to improper initialization. L…
- CVE-2023-1513HIGHCVSS 3.3EG 7.52023-03-23
A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak.
- CVE-2023-1719HIGHCVSS 7.5EG 7.52023-11-01
Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and poss…
- CVE-2023-20591MEDIUMCVSS 6.5EG 6.52024-08-13
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and…
- CVE-2023-20594MEDIUMCVSS 4.4EG 4.42023-09-20
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
- CVE-2023-20597MEDIUMCVSS 5.5EG 5.52023-09-20
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
- CVE-2023-22356MEDIUMCVSS 6.0EG 6.02023-08-11
Improper initialization in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2023-22444MEDIUMCVSS 6.0EG 6.02023-08-11
Improper initialization in some Intel(R) NUC 13 Extreme Compute Element, Intel(R) NUC 13 Extreme Kit, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Compute Element, Intel(R) NUC Laptop Kit, Intel(R) NUC…
- CVE-2023-22466MEDIUMCVSS 5.4EG 5.42023-01-04
Tokio is a runtime for writing applications with Rust. Starting with version 1.7.0 and prior to versions 1.18.4, 1.20.3, and 1.23.1, when configuring a Windows named pipe server, setting `pipe_mode` will reset `reject_remote_clients` to `f…
- CVE-2023-23555HIGHCVSS 7.5EG 7.52023-02-01
On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a virtual server, undi…
- CVE-2023-25010HIGHCVSS 7.8EG 7.82023-04-17
A malicious actor may convince a victim to open a malicious USD file that may trigger an uninitialized variable which may result in code execution.
- CVE-2023-26084LOWCVSS 3.7EG 3.72023-03-15
The armv8_dec_aes_gcm_full() API of Arm AArch64cryptolib before 86065c6 fails to the verify the authentication tag of AES-GCM protected data, leading to a man-in-the-middle attack. This occurs because of an improperly initialized variable.
- CVE-2023-27115MEDIUMCVSS 5.5EG 5.52023-03-10
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size.
- CVE-2023-27306MEDIUMCVSS 6.5EG 6.52023-11-14
Improper Initialization in firmware for some Intel(R) Optane(TM) SSD products may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-27322HIGHCVSS 7.8EG 7.82024-05-03
Parallels Desktop Service Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the …
- CVE-2023-27324HIGHCVSS 7.8EG 7.82024-05-03
Parallels Desktop Updater Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the …
- CVE-2023-27325HIGHCVSS 7.8EG 7.82024-05-03
Parallels Desktop Updater Improper Initialization Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the …
- CVE-2023-27887MEDIUMCVSS 6.1EG 6.12023-08-11
Improper initialization in BIOS firmware for some Intel(R) NUCs may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2023-27934HIGHCVSS 8.8EG 8.82023-05-08
A memory initialization issue was addressed. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.
- CVE-2023-28720MEDIUMCVSS 6.1EG 6.52024-02-14
Improper initialization for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access..
- CVE-2023-28737HIGHCVSS 8.8EG 8.82023-11-14
Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-31926HIGHCVSS 7.1EG 7.12023-08-02
System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0.
- CVE-2023-3242HIGHCVSS 8.6EG 8.62023-07-26
Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions.
- CVE-2023-32467MEDIUMCVSS 5.7EG 5.72024-07-10
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, le…
- CVE-2023-35061MEDIUMCVSS 4.3EG 4.32024-02-14
Improper initialization for the Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
- CVE-2023-36490MEDIUMCVSS 5.0EG 5.52024-02-14
Improper initialization in some Intel(R) MAS software before version 2.3 may allow an authenticated user to potentially enable denial of service via local access.
Map vulnerabilities like CWE-665 to your infrastructure
EchelonGraph correlates every CVE — across CWE-665 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →