İçeriğe atla
Noroxi

CWE-665 · 326 kayıt

Improper Initialization

Bu sınıftaki CVE’ler

326 kayıt

  • A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %93

    linux · linux kernel10 Mar 2022

  • CVE-2013-1675
    58Planlayın

    Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not proper

    OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %7

    mozilla · firefox16 May 2013

  • CVE-2020-27950
    57Planlayın

    A memory initialization issue was addressed.

    OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %17

    apple · ipados8 Ara 2020

  • CVE-2022-46164
    54Planlayın

    Account takeover via prototype vulnerability

    KritikCVSS 9,8Kavram kanıtıEPSS %49

    nodebb · nodebb5 Ara 2022

  • CVE-2022-22719
    51Planlayın

    mod_lua Use of uninitialized value of in r:parsebody

    YüksekCVSS 7,5İstismar yokEPSS %69

    apache · http server14 Mar 2022

  • CVE-2020-28019
    48Planlayın

    Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.

    YüksekCVSS 7,5İstismar yokEPSS %62

    exim · exim6 May 2021

  • CVE-2022-37128
    46Planlayın

    In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.

    KritikCVSS 9,8İstismar yokEPSS %22

    dlink · dir-816 firmware31 Ağu 2022

  • CVE-2019-14271
    45Planlayın

    In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamical

    KritikCVSS 9,8Kavram kanıtıEPSS %19

    docker · docker29 Tem 2019

  • CVE-2008-0062
    42Planlayın

    KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial

    KritikCVSS 9,8İstismar yokEPSS %10

    mit · kerberos 519 Mar 2008

  • CVE-2017-13715
    42Planlayın

    The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thof

    KritikCVSS 9,8İstismar yokEPSS %10

    linux · linux kernel28 Ağu 2017

  • CVE-2015-8367
    41Planlayın

    The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related

    KritikCVSS 9,8İstismar yokEPSS %6

    libraw · libraw14 Oca 2020

  • CVE-2023-1719
    40Planlayın

    Bitrix24 Insecure Global Variable Extraction

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    bitrix24 · bitrix241 Kas 2023

  • CVE-2019-3464
    40Planlayın

    Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that shou

    KritikCVSS 9,8İstismar yokEPSS %5

    pizzashack · rssh6 Şub 2019

  • CVE-2022-21724
    40Planlayın

    Unchecked Class Instantiation when providing Plugin Classes

    KritikCVSS 9,8İstismar yokEPSS %3

    postgresql · postgresql jdbc driver2 Şub 2022

  • CVE-2023-20591
    40Planlayın

    Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to

    KritikCVSS 10,0İstismar yokEPSS %0

    amd · epyc 8024pn firmware13 Ağu 2024

  • CVE-2021-41264
    39İzleyin

    UUPSUpgradeable vulnerability in OpenZeppelin Contracts

    KritikCVSS 9,8İstismar yokEPSS %1

    openzeppelin · contracts12 Kas 2021

  • CVE-2019-10196
    39İzleyin

    A flaw was found in http-proxy-agent, prior to version 2.1.0.

    KritikCVSS 9,8İstismar yokEPSS %1

    http-proxy-agent project · http-proxy-agent19 Mar 2021

  • CVE-2022-36061
    39İzleyin

    Elrond go can execute on same context checks in VM

    KritikCVSS 9,8İstismar yokEPSS %1

    elrond · elrond go6 Eyl 2022

  • CVE-2018-11949
    39İzleyin

    Failure to initialize the extra buffer can lead to an out of buffer access in WLAN function in Snapdragon Auto, Snapdragon Compute, Snapdrag

    KritikCVSS 9,8İstismar yokEPSS %1

    qualcomm · mdm9150 firmware24 May 2019

  • CVE-2022-0947
    39İzleyin

    Arctic Wireless Gateway Firewall vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    abb · arg600a1220na firmware10 May 2022

  • CVE-2026-64775
    39İzleyin

    A memory initialization issue was addressed with improved memory handling.

    KritikCVSS 9,8İstismar yokEPSS %1

    apple · ipados27 Tem 2026

  • CVE-2001-1471
    37İzleyin

    prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which pr

    YüksekCVSS 8,8Kavram kanıtıEPSS %8

    phpbb · phpbb31 Tem 2001

  • CVE-2008-3637
    37İzleyin

    The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized varia

    YüksekCVSS 8,8İstismar yokEPSS %6

    apple · mac os x26 Eyl 2008

  • CVE-2017-5468
    37İzleyin

    An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools.

    KritikCVSS 9,1İstismar yokEPSS %2

    mozilla · firefox11 Haz 2018

  • CVE-2024-36455
    37İzleyin

    Symantec Privileged Access Manager Remote Command Execution vulnerability

    KritikCVSS 9,4İstismar yokEPSS %0

    broadcom · symantec privileged access management15 Tem 2024

Tüm zafiyet sınıfları