CWE-665 · 326 записей
Improper Initialization
CVE этого класса
326 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
89Срочно | CVE-2022-0847Готовый эксплойт | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe linux · linux kernel · CWE-665 | Высокая7,8 | KEV | 92,8 % | 10 мар. 2022 г. |
58В плане | CVE-2013-1675Готовый эксплойт | Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not propermozilla · firefox · CWE-665 | Средняя6,5 | KEV | 6,7 % | 16 мая 2013 г. |
57В плане | CVE-2020-27950Готовый эксплойт | A memory initialization issue was addressed.apple · ipados · CWE-665 | Средняя5,5 | KEV | 16,5 % | 8 дек. 2020 г. |
54В плане | CVE-2022-46164Proof of concept | Account takeover via prototype vulnerabilitynodebb · nodebb · CWE-665 | Критическая9,8 | — | 49,0 % | 5 дек. 2022 г. |
51В плане | CVE-2022-22719Эксплойта нет | mod_lua Use of uninitialized value of in r:parsebodyapache · http server · CWE-665 | Высокая7,5 | — | 69,1 % | 14 мар. 2022 г. |
48В плане | CVE-2020-28019Эксплойта нет | Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.exim · exim · CWE-665 | Высокая7,5 | — | 61,7 % | 6 мая 2021 г. |
46В плане | CVE-2022-37128Эксплойта нет | In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.dlink · dir-816 firmware · CWE-665 | Критическая9,8 | — | 21,7 % | 31 авг. 2022 г. |
45В плане | CVE-2019-14271Proof of concept | In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamicaldocker · docker · CWE-665 | Критическая9,8 | — | 18,8 % | 29 июл. 2019 г. |
42В плане | CVE-2008-0062Эксплойта нет | KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial mit · kerberos 5 · CWE-665 | Критическая9,8 | — | 10,1 % | 19 мар. 2008 г. |
42В плане | CVE-2017-13715Эксплойта нет | The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoflinux · linux kernel · CWE-665 | Критическая9,8 | — | 9,7 % | 28 авг. 2017 г. |
41В плане | CVE-2015-8367Эксплойта нет | The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related libraw · libraw · CWE-665 | Критическая9,8 | — | 5,6 % | 14 янв. 2020 г. |
40В плане | CVE-2023-1719Proof of concept | Bitrix24 Insecure Global Variable Extractionbitrix24 · bitrix24 · CWE-665 | Критическая9,8 | — | 5,0 % | 1 нояб. 2023 г. |
40В плане | CVE-2019-3464Эксплойта нет | Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that shoupizzashack · rssh · CWE-665 | Критическая9,8 | — | 4,7 % | 6 февр. 2019 г. |
40В плане | CVE-2022-21724Эксплойта нет | Unchecked Class Instantiation when providing Plugin Classespostgresql · postgresql jdbc driver · CWE-665 | Критическая9,8 | — | 3,1 % | 2 февр. 2022 г. |
40В плане | CVE-2023-20591Эксплойта нет | Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker toamd · epyc 8024pn firmware · CWE-665 | Критическая10,0 | — | 0,3 % | 13 авг. 2024 г. |
39Наблюдать | CVE-2021-41264Эксплойта нет | UUPSUpgradeable vulnerability in OpenZeppelin Contractsopenzeppelin · contracts · CWE-665 | Критическая9,8 | — | 1,5 % | 12 нояб. 2021 г. |
39Наблюдать | CVE-2019-10196Эксплойта нет | A flaw was found in http-proxy-agent, prior to version 2.1.0.http-proxy-agent project · http-proxy-agent · CWE-665 | Критическая9,8 | — | 1,4 % | 19 мар. 2021 г. |
39Наблюдать | CVE-2022-36061Эксплойта нет | Elrond go can execute on same context checks in VMelrond · elrond go · CWE-665 | Критическая9,8 | — | 1,2 % | 6 сент. 2022 г. |
39Наблюдать | CVE-2018-11949Эксплойта нет | Failure to initialize the extra buffer can lead to an out of buffer access in WLAN function in Snapdragon Auto, Snapdragon Compute, Snapdragqualcomm · mdm9150 firmware · CWE-665 | Критическая9,8 | — | 0,9 % | 24 мая 2019 г. |
39Наблюдать | CVE-2022-0947Эксплойта нет | Arctic Wireless Gateway Firewall vulnerabilityabb · arg600a1220na firmware · CWE-665 | Критическая9,8 | — | 0,9 % | 10 мая 2022 г. |
39Наблюдать | CVE-2026-64775Эксплойта нет | A memory initialization issue was addressed with improved memory handling.apple · ipados · CWE-665 | Критическая9,8 | — | 0,7 % | 27 июл. 2026 г. |
37Наблюдать | CVE-2001-1471Proof of concept | prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prphpbb · phpbb · CWE-665 | Высокая8,8 | — | 7,7 % | 31 июл. 2001 г. |
37Наблюдать | CVE-2008-3637Эксплойта нет | The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized variaapple · mac os x · CWE-665 | Высокая8,8 | — | 5,7 % | 26 сент. 2008 г. |
37Наблюдать | CVE-2017-5468Эксплойта нет | An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools.mozilla · firefox · CWE-665 | Критическая9,1 | — | 2,4 % | 11 июн. 2018 г. |
37Наблюдать | CVE-2024-36455Эксплойта нет | Symantec Privileged Access Manager Remote Command Execution vulnerabilitybroadcom · symantec privileged access management · CWE-665 | Критическая9,4 | — | 0,5 % | 15 июл. 2024 г. |
- CVE-2022-084789Срочно
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 93 %linux · linux kernel10 мар. 2022 г.
- CVE-2013-167558В плане
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not proper
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 7 %mozilla · firefox16 мая 2013 г.
- CVE-2020-2795057В плане
A memory initialization issue was addressed.
СредняяCVSS 5,5KEVГотовый эксплойтEPSS 17 %apple · ipados8 дек. 2020 г.
- CVE-2022-4616454В плане
Account takeover via prototype vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 49 %nodebb · nodebb5 дек. 2022 г.
- CVE-2022-2271951В плане
mod_lua Use of uninitialized value of in r:parsebody
ВысокаяCVSS 7,5Эксплойта нетEPSS 69 %apache · http server14 мар. 2022 г.
- CVE-2020-2801948В плане
Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.
ВысокаяCVSS 7,5Эксплойта нетEPSS 62 %exim · exim6 мая 2021 г.
- CVE-2022-3712846В плане
In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.
КритическаяCVSS 9,8Эксплойта нетEPSS 22 %dlink · dir-816 firmware31 авг. 2022 г.
- CVE-2019-1427145В плане
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamical
КритическаяCVSS 9,8Proof of conceptEPSS 19 %docker · docker29 июл. 2019 г.
- CVE-2008-006242В плане
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %mit · kerberos 519 мар. 2008 г.
- CVE-2017-1371542В плане
The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thof
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %linux · linux kernel28 авг. 2017 г.
- CVE-2015-836741В плане
The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %libraw · libraw14 янв. 2020 г.
- CVE-2023-171940В плане
Bitrix24 Insecure Global Variable Extraction
КритическаяCVSS 9,8Proof of conceptEPSS 5 %bitrix24 · bitrix241 нояб. 2023 г.
- CVE-2019-346440В плане
Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that shou
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %pizzashack · rssh6 февр. 2019 г.
- CVE-2022-2172440В плане
Unchecked Class Instantiation when providing Plugin Classes
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %postgresql · postgresql jdbc driver2 февр. 2022 г.
- CVE-2023-2059140В плане
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %amd · epyc 8024pn firmware13 авг. 2024 г.
- CVE-2021-4126439Наблюдать
UUPSUpgradeable vulnerability in OpenZeppelin Contracts
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openzeppelin · contracts12 нояб. 2021 г.
- CVE-2019-1019639Наблюдать
A flaw was found in http-proxy-agent, prior to version 2.1.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %http-proxy-agent project · http-proxy-agent19 мар. 2021 г.
- CVE-2022-3606139Наблюдать
Elrond go can execute on same context checks in VM
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %elrond · elrond go6 сент. 2022 г.
- CVE-2018-1194939Наблюдать
Failure to initialize the extra buffer can lead to an out of buffer access in WLAN function in Snapdragon Auto, Snapdragon Compute, Snapdrag
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · mdm9150 firmware24 мая 2019 г.
- CVE-2022-094739Наблюдать
Arctic Wireless Gateway Firewall vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %abb · arg600a1220na firmware10 мая 2022 г.
- CVE-2026-6477539Наблюдать
A memory initialization issue was addressed with improved memory handling.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apple · ipados27 июл. 2026 г.
- CVE-2001-147137Наблюдать
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which pr
ВысокаяCVSS 8,8Proof of conceptEPSS 8 %phpbb · phpbb31 июл. 2001 г.
- CVE-2008-363737Наблюдать
The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized varia
ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %apple · mac os x26 сент. 2008 г.
- CVE-2017-546837Наблюдать
An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %mozilla · firefox11 июн. 2018 г.
- CVE-2024-3645537Наблюдать
Symantec Privileged Access Manager Remote Command Execution vulnerability
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %broadcom · symantec privileged access management15 июл. 2024 г.