CWE-665 · 326 kayıt
Improper Initialization
Bu sınıftaki CVE’ler
326 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
89Hemen | CVE-2022-0847Silahlaştırılmış | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe linux · linux kernel · CWE-665 | Yüksek7,8 | KEV | %92,8 | 10 Mar 2022 |
58Planlayın | CVE-2013-1675Silahlaştırılmış | Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not propermozilla · firefox · CWE-665 | Orta6,5 | KEV | %6,7 | 16 May 2013 |
57Planlayın | CVE-2020-27950Silahlaştırılmış | A memory initialization issue was addressed.apple · ipados · CWE-665 | Orta5,5 | KEV | %16,5 | 8 Ara 2020 |
54Planlayın | CVE-2022-46164Kavram kanıtı | Account takeover via prototype vulnerabilitynodebb · nodebb · CWE-665 | Kritik9,8 | — | %49,0 | 5 Ara 2022 |
51Planlayın | CVE-2022-22719İstismar yok | mod_lua Use of uninitialized value of in r:parsebodyapache · http server · CWE-665 | Yüksek7,5 | — | %69,1 | 14 Mar 2022 |
48Planlayın | CVE-2020-28019İstismar yok | Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.exim · exim · CWE-665 | Yüksek7,5 | — | %61,7 | 6 May 2021 |
46Planlayın | CVE-2022-37128İstismar yok | In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.dlink · dir-816 firmware · CWE-665 | Kritik9,8 | — | %21,7 | 31 Ağu 2022 |
45Planlayın | CVE-2019-14271Kavram kanıtı | In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamicaldocker · docker · CWE-665 | Kritik9,8 | — | %18,8 | 29 Tem 2019 |
42Planlayın | CVE-2008-0062İstismar yok | KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial mit · kerberos 5 · CWE-665 | Kritik9,8 | — | %10,1 | 19 Mar 2008 |
42Planlayın | CVE-2017-13715İstismar yok | The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoflinux · linux kernel · CWE-665 | Kritik9,8 | — | %9,7 | 28 Ağu 2017 |
41Planlayın | CVE-2015-8367İstismar yok | The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related libraw · libraw · CWE-665 | Kritik9,8 | — | %5,6 | 14 Oca 2020 |
40Planlayın | CVE-2023-1719Kavram kanıtı | Bitrix24 Insecure Global Variable Extractionbitrix24 · bitrix24 · CWE-665 | Kritik9,8 | — | %5,0 | 1 Kas 2023 |
40Planlayın | CVE-2019-3464İstismar yok | Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that shoupizzashack · rssh · CWE-665 | Kritik9,8 | — | %4,7 | 6 Şub 2019 |
40Planlayın | CVE-2022-21724İstismar yok | Unchecked Class Instantiation when providing Plugin Classespostgresql · postgresql jdbc driver · CWE-665 | Kritik9,8 | — | %3,1 | 2 Şub 2022 |
40Planlayın | CVE-2023-20591İstismar yok | Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker toamd · epyc 8024pn firmware · CWE-665 | Kritik10,0 | — | %0,3 | 13 Ağu 2024 |
39İzleyin | CVE-2021-41264İstismar yok | UUPSUpgradeable vulnerability in OpenZeppelin Contractsopenzeppelin · contracts · CWE-665 | Kritik9,8 | — | %1,5 | 12 Kas 2021 |
39İzleyin | CVE-2019-10196İstismar yok | A flaw was found in http-proxy-agent, prior to version 2.1.0.http-proxy-agent project · http-proxy-agent · CWE-665 | Kritik9,8 | — | %1,4 | 19 Mar 2021 |
39İzleyin | CVE-2022-36061İstismar yok | Elrond go can execute on same context checks in VMelrond · elrond go · CWE-665 | Kritik9,8 | — | %1,2 | 6 Eyl 2022 |
39İzleyin | CVE-2018-11949İstismar yok | Failure to initialize the extra buffer can lead to an out of buffer access in WLAN function in Snapdragon Auto, Snapdragon Compute, Snapdragqualcomm · mdm9150 firmware · CWE-665 | Kritik9,8 | — | %0,9 | 24 May 2019 |
39İzleyin | CVE-2022-0947İstismar yok | Arctic Wireless Gateway Firewall vulnerabilityabb · arg600a1220na firmware · CWE-665 | Kritik9,8 | — | %0,9 | 10 May 2022 |
39İzleyin | CVE-2026-64775İstismar yok | A memory initialization issue was addressed with improved memory handling.apple · ipados · CWE-665 | Kritik9,8 | — | %0,7 | 27 Tem 2026 |
37İzleyin | CVE-2001-1471Kavram kanıtı | prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prphpbb · phpbb · CWE-665 | Yüksek8,8 | — | %7,7 | 31 Tem 2001 |
37İzleyin | CVE-2008-3637İstismar yok | The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized variaapple · mac os x · CWE-665 | Yüksek8,8 | — | %5,7 | 26 Eyl 2008 |
37İzleyin | CVE-2017-5468İstismar yok | An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools.mozilla · firefox · CWE-665 | Kritik9,1 | — | %2,4 | 11 Haz 2018 |
37İzleyin | CVE-2024-36455İstismar yok | Symantec Privileged Access Manager Remote Command Execution vulnerabilitybroadcom · symantec privileged access management · CWE-665 | Kritik9,4 | — | %0,5 | 15 Tem 2024 |
- CVE-2022-084789Hemen
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %93linux · linux kernel10 Mar 2022
- CVE-2013-167558Planlayın
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not proper
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %7mozilla · firefox16 May 2013
- CVE-2020-2795057Planlayın
A memory initialization issue was addressed.
OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %17apple · ipados8 Ara 2020
- CVE-2022-4616454Planlayın
Account takeover via prototype vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %49nodebb · nodebb5 Ara 2022
- CVE-2022-2271951Planlayın
mod_lua Use of uninitialized value of in r:parsebody
YüksekCVSS 7,5İstismar yokEPSS %69apache · http server14 Mar 2022
- CVE-2020-2801948Planlayın
Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences.
YüksekCVSS 7,5İstismar yokEPSS %62exim · exim6 May 2021
- CVE-2022-3712846Planlayın
In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.
KritikCVSS 9,8İstismar yokEPSS %22dlink · dir-816 firmware31 Ağu 2022
- CVE-2019-1427145Planlayın
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamical
KritikCVSS 9,8Kavram kanıtıEPSS %19docker · docker29 Tem 2019
- CVE-2008-006242Planlayın
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial
KritikCVSS 9,8İstismar yokEPSS %10mit · kerberos 519 Mar 2008
- CVE-2017-1371542Planlayın
The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thof
KritikCVSS 9,8İstismar yokEPSS %10linux · linux kernel28 Ağu 2017
- CVE-2015-836741Planlayın
The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related
KritikCVSS 9,8İstismar yokEPSS %6libraw · libraw14 Oca 2020
- CVE-2023-171940Planlayın
Bitrix24 Insecure Global Variable Extraction
KritikCVSS 9,8Kavram kanıtıEPSS %5bitrix24 · bitrix241 Kas 2023
- CVE-2019-346440Planlayın
Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that shou
KritikCVSS 9,8İstismar yokEPSS %5pizzashack · rssh6 Şub 2019
- CVE-2022-2172440Planlayın
Unchecked Class Instantiation when providing Plugin Classes
KritikCVSS 9,8İstismar yokEPSS %3postgresql · postgresql jdbc driver2 Şub 2022
- CVE-2023-2059140Planlayın
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to
KritikCVSS 10,0İstismar yokEPSS %0amd · epyc 8024pn firmware13 Ağu 2024
- CVE-2021-4126439İzleyin
UUPSUpgradeable vulnerability in OpenZeppelin Contracts
KritikCVSS 9,8İstismar yokEPSS %1openzeppelin · contracts12 Kas 2021
- CVE-2019-1019639İzleyin
A flaw was found in http-proxy-agent, prior to version 2.1.0.
KritikCVSS 9,8İstismar yokEPSS %1http-proxy-agent project · http-proxy-agent19 Mar 2021
- CVE-2022-3606139İzleyin
Elrond go can execute on same context checks in VM
KritikCVSS 9,8İstismar yokEPSS %1elrond · elrond go6 Eyl 2022
- CVE-2018-1194939İzleyin
Failure to initialize the extra buffer can lead to an out of buffer access in WLAN function in Snapdragon Auto, Snapdragon Compute, Snapdrag
KritikCVSS 9,8İstismar yokEPSS %1qualcomm · mdm9150 firmware24 May 2019
- CVE-2022-094739İzleyin
Arctic Wireless Gateway Firewall vulnerability
KritikCVSS 9,8İstismar yokEPSS %1abb · arg600a1220na firmware10 May 2022
- CVE-2026-6477539İzleyin
A memory initialization issue was addressed with improved memory handling.
KritikCVSS 9,8İstismar yokEPSS %1apple · ipados27 Tem 2026
- CVE-2001-147137İzleyin
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which pr
YüksekCVSS 8,8Kavram kanıtıEPSS %8phpbb · phpbb31 Tem 2001
- CVE-2008-363737İzleyin
The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized varia
YüksekCVSS 8,8İstismar yokEPSS %6apple · mac os x26 Eyl 2008
- CVE-2017-546837İzleyin
An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools.
KritikCVSS 9,1İstismar yokEPSS %2mozilla · firefox11 Haz 2018
- CVE-2024-3645537İzleyin
Symantec Privileged Access Manager Remote Command Execution vulnerability
KritikCVSS 9,4İstismar yokEPSS %0broadcom · symantec privileged access management15 Tem 2024