Перейти к содержимому
Noroxi

CWE-665 · 326 записей

Improper Initialization

CVE этого класса

326 записей

  • CVE-2022-0847
    89Срочно

    A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 93 %

    linux · linux kernel10 мар. 2022 г.

  • CVE-2013-1675
    58В плане

    Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not proper

    СредняяCVSS 6,5KEVГотовый эксплойтEPSS 7 %

    mozilla · firefox16 мая 2013 г.

  • CVE-2020-27950
    57В плане

    A memory initialization issue was addressed.

    СредняяCVSS 5,5KEVГотовый эксплойтEPSS 17 %

    apple · ipados8 дек. 2020 г.

  • CVE-2022-46164
    54В плане

    Account takeover via prototype vulnerability

    КритическаяCVSS 9,8Proof of conceptEPSS 49 %

    nodebb · nodebb5 дек. 2022 г.

  • CVE-2022-22719
    51В плане

    mod_lua Use of uninitialized value of in r:parsebody

    ВысокаяCVSS 7,5Эксплойта нетEPSS 69 %

    apache · http server14 мар. 2022 г.

  • CVE-2020-28019
    48В плане

    Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 62 %

    exim · exim6 мая 2021 г.

  • CVE-2022-37128
    46В плане

    In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.

    КритическаяCVSS 9,8Эксплойта нетEPSS 22 %

    dlink · dir-816 firmware31 авг. 2022 г.

  • CVE-2019-14271
    45В плане

    In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamical

    КритическаяCVSS 9,8Proof of conceptEPSS 19 %

    docker · docker29 июл. 2019 г.

  • CVE-2008-0062
    42В плане

    KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial

    КритическаяCVSS 9,8Эксплойта нетEPSS 10 %

    mit · kerberos 519 мар. 2008 г.

  • CVE-2017-13715
    42В плане

    The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thof

    КритическаяCVSS 9,8Эксплойта нетEPSS 10 %

    linux · linux kernel28 авг. 2017 г.

  • CVE-2015-8367
    41В плане

    The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    libraw · libraw14 янв. 2020 г.

  • CVE-2023-1719
    40В плане

    Bitrix24 Insecure Global Variable Extraction

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    bitrix24 · bitrix241 нояб. 2023 г.

  • CVE-2019-3464
    40В плане

    Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that shou

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    pizzashack · rssh6 февр. 2019 г.

  • CVE-2022-21724
    40В плане

    Unchecked Class Instantiation when providing Plugin Classes

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    postgresql · postgresql jdbc driver2 февр. 2022 г.

  • CVE-2023-20591
    40В плане

    Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    amd · epyc 8024pn firmware13 авг. 2024 г.

  • CVE-2021-41264
    39Наблюдать

    UUPSUpgradeable vulnerability in OpenZeppelin Contracts

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    openzeppelin · contracts12 нояб. 2021 г.

  • CVE-2019-10196
    39Наблюдать

    A flaw was found in http-proxy-agent, prior to version 2.1.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    http-proxy-agent project · http-proxy-agent19 мар. 2021 г.

  • CVE-2022-36061
    39Наблюдать

    Elrond go can execute on same context checks in VM

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    elrond · elrond go6 сент. 2022 г.

  • CVE-2018-11949
    39Наблюдать

    Failure to initialize the extra buffer can lead to an out of buffer access in WLAN function in Snapdragon Auto, Snapdragon Compute, Snapdrag

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    qualcomm · mdm9150 firmware24 мая 2019 г.

  • CVE-2022-0947
    39Наблюдать

    Arctic Wireless Gateway Firewall vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    abb · arg600a1220na firmware10 мая 2022 г.

  • CVE-2026-64775
    39Наблюдать

    A memory initialization issue was addressed with improved memory handling.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    apple · ipados27 июл. 2026 г.

  • CVE-2001-1471
    37Наблюдать

    prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which pr

    ВысокаяCVSS 8,8Proof of conceptEPSS 8 %

    phpbb · phpbb31 июл. 2001 г.

  • CVE-2008-3637
    37Наблюдать

    The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized varia

    ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %

    apple · mac os x26 сент. 2008 г.

  • CVE-2017-5468
    37Наблюдать

    An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools.

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    mozilla · firefox11 июн. 2018 г.

  • CVE-2024-36455
    37Наблюдать

    Symantec Privileged Access Manager Remote Command Execution vulnerability

    КритическаяCVSS 9,4Эксплойта нетEPSS 0 %

    broadcom · symantec privileged access management15 июл. 2024 г.

Все классы уязвимостей