CWE-909 · 80 kayıt
Missing Initialization of Resource
Bu sınıftaki CVE’ler
80 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-22704İstismar yok | The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expezabbix · zabbix-agent2 · CWE-909 | Kritik9,8 | — | %1,3 | 6 Oca 2022 |
36İzleyin | CVE-2021-23994İstismar yok | A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write.mozilla · firefox · CWE-909 | Yüksek8,8 | — | %1,8 | 24 Haz 2021 |
36İzleyin | CVE-2020-12523İstismar yok | Phoenix Contact mGuard Devices versions before 8.8.3: LAN ports get functional after reboot even if they are disabled in the device configurationphoenixcontact · tc mguard rs4000 4g vzw vpn firmware · CWE-909 | Kritik9,1 | — | %0,9 | 17 Ara 2020 |
36İzleyin | CVE-2026-40687İstismar yok | In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write thatexim · exim · CWE-909 | Kritik9,1 | — | %0,7 | 30 Nis 2026 |
35İzleyin | CVE-2021-29980İstismar yok | Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable cramozilla · firefox · CWE-909 | Yüksek8,8 | — | %1,4 | 17 Ağu 2021 |
35İzleyin | CVE-2020-11741İstismar yok | An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information axen · xen · CWE-909 | Yüksek8,8 | — | %0,4 | 14 Nis 2020 |
34İzleyin | CVE-2025-8117İstismar yok | Account Takeover via Reset Password Functionality in PAD CMSwidzialni · pad cms · CWE-909 | Yüksek8,7 | — | %0,3 | 30 Eyl 2025 |
32İzleyin | CVE-2018-10811İstismar yok | strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.strongswan · strongswan · CWE-909 | Yüksek7,5 | — | %6,2 | 19 Haz 2018 |
31İzleyin | CVE-2019-3804İstismar yok | It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack.cockpit-project · cockpit · CWE-909 | Yüksek7,5 | — | %4,9 | 26 Mar 2019 |
31İzleyin | CVE-2019-12410İstismar yok | While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, leftapache · arrow · CWE-909 | Yüksek7,5 | — | %4,6 | 8 Kas 2019 |
31İzleyin | CVE-2019-19553İstismar yok | In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash.wireshark · wireshark · CWE-909 | Yüksek7,5 | — | %4,1 | 4 Ara 2019 |
31İzleyin | CVE-2019-12408İstismar yok | It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had apache · arrow · CWE-909 | Yüksek7,5 | — | %3,3 | 8 Kas 2019 |
31İzleyin | CVE-2019-16714İstismar yok | In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack mlinux · linux kernel · CWE-909 | Yüksek7,5 | — | %2,7 | 23 Eyl 2019 |
31İzleyin | CVE-2021-36386İstismar yok | report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow maifetchmail · fetchmail · CWE-909 | Yüksek7,5 | — | %2,6 | 30 Tem 2021 |
31İzleyin | CVE-2018-21247İstismar yok | An issue was discovered in LibVNCServer before 0.9.13.libvnc project · libvncserver · CWE-909 | Yüksek7,5 | — | %2,5 | 17 Haz 2020 |
31İzleyin | CVE-2021-36513İstismar yok | An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to viewsignalwire · freeswitch · CWE-909 | Yüksek7,5 | — | %1,9 | 18 Eki 2021 |
31İzleyin | CVE-2022-29968Kavram kanıtı | An issue was discovered in the Linux kernel through 5.17.5.linux · linux kernel · CWE-909 | Yüksek7,8 | — | %1,1 | 2 May 2022 |
31İzleyin | CVE-2005-1036İstismar yok | FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allowfreebsd · freebsd · CWE-909 | Yüksek7,8 | — | %0,4 | 2 May 2005 |
31İzleyin | CVE-2024-43873İstismar yok | vhost/vsock: always initialize seqpacket_allowlinux · linux kernel · CWE-909 | Yüksek7,8 | — | %0,2 | 20 Ağu 2024 |
30İzleyin | CVE-2021-31919İstismar yok | An issue was discovered in the rkyv crate before 0.6.0 for Rust.rkyv project · rkyv · CWE-909 | Yüksek7,5 | — | %1,1 | 29 Nis 2021 |
30İzleyin | CVE-2019-25054İstismar yok | An issue was discovered in the pnet crate before 0.27.2 for Rust.pnet project · pnet · CWE-909 | Yüksek7,5 | — | %1,0 | 26 Ara 2021 |
30İzleyin | CVE-2021-39966İstismar yok | There is an Uninitialized AOD driver structure in Smartphones.Successful exploitation of this vulnerability may affect service confidentialihuawei · emui · CWE-909 | Yüksek7,5 | — | %0,7 | 3 Oca 2022 |
30İzleyin | CVE-2021-0947İstismar yok | The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKMgoogle · android · CWE-909 | Yüksek7,5 | — | %0,3 | 24 Ağu 2022 |
30İzleyin | CVE-2021-0946İstismar yok | The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolicgoogle · android · CWE-909 | Yüksek7,5 | — | %0,3 | 24 Ağu 2022 |
28İzleyin | CVE-2020-12352Kavram kanıtı | Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.bluez · bluez · CWE-909 | Orta6,5 | — | %5,7 | 23 Kas 2020 |
- CVE-2022-2270439İzleyin
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expe
KritikCVSS 9,8İstismar yokEPSS %1zabbix · zabbix-agent26 Oca 2022
- CVE-2021-2399436İzleyin
A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write.
YüksekCVSS 8,8İstismar yokEPSS %2mozilla · firefox24 Haz 2021
- CVE-2020-1252336İzleyin
Phoenix Contact mGuard Devices versions before 8.8.3: LAN ports get functional after reboot even if they are disabled in the device configuration
KritikCVSS 9,1İstismar yokEPSS %1phoenixcontact · tc mguard rs4000 4g vzw vpn firmware17 Ara 2020
- CVE-2026-4068736İzleyin
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that
KritikCVSS 9,1İstismar yokEPSS %1exim · exim30 Nis 2026
- CVE-2021-2998035İzleyin
Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable cra
YüksekCVSS 8,8İstismar yokEPSS %1mozilla · firefox17 Ağu 2021
- CVE-2020-1174135İzleyin
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information a
YüksekCVSS 8,8İstismar yokEPSS %0xen · xen14 Nis 2020
- CVE-2025-811734İzleyin
Account Takeover via Reset Password Functionality in PAD CMS
YüksekCVSS 8,7İstismar yokEPSS %0widzialni · pad cms30 Eyl 2025
- CVE-2018-1081132İzleyin
strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.
YüksekCVSS 7,5İstismar yokEPSS %6strongswan · strongswan19 Haz 2018
- CVE-2019-380431İzleyin
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack.
YüksekCVSS 7,5İstismar yokEPSS %5cockpit-project · cockpit26 Mar 2019
- CVE-2019-1241031İzleyin
While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left
YüksekCVSS 7,5İstismar yokEPSS %5apache · arrow8 Kas 2019
- CVE-2019-1955331İzleyin
In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash.
YüksekCVSS 7,5İstismar yokEPSS %4wireshark · wireshark4 Ara 2019
- CVE-2019-1240831İzleyin
It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had
YüksekCVSS 7,5İstismar yokEPSS %3apache · arrow8 Kas 2019
- CVE-2019-1671431İzleyin
In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack m
YüksekCVSS 7,5İstismar yokEPSS %3linux · linux kernel23 Eyl 2019
- CVE-2021-3638631İzleyin
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mai
YüksekCVSS 7,5İstismar yokEPSS %3fetchmail · fetchmail30 Tem 2021
- CVE-2018-2124731İzleyin
An issue was discovered in LibVNCServer before 0.9.13.
YüksekCVSS 7,5İstismar yokEPSS %2libvnc project · libvncserver17 Haz 2020
- CVE-2021-3651331İzleyin
An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view
YüksekCVSS 7,5İstismar yokEPSS %2signalwire · freeswitch18 Eki 2021
- CVE-2022-2996831İzleyin
An issue was discovered in the Linux kernel through 5.17.5.
YüksekCVSS 7,8Kavram kanıtıEPSS %1linux · linux kernel2 May 2022
- CVE-2005-103631İzleyin
FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allow
YüksekCVSS 7,8İstismar yokEPSS %0freebsd · freebsd2 May 2005
- CVE-2024-4387331İzleyin
vhost/vsock: always initialize seqpacket_allow
YüksekCVSS 7,8İstismar yokEPSS %0linux · linux kernel20 Ağu 2024
- CVE-2021-3191930İzleyin
An issue was discovered in the rkyv crate before 0.6.0 for Rust.
YüksekCVSS 7,5İstismar yokEPSS %1rkyv project · rkyv29 Nis 2021
- CVE-2019-2505430İzleyin
An issue was discovered in the pnet crate before 0.27.2 for Rust.
YüksekCVSS 7,5İstismar yokEPSS %1pnet project · pnet26 Ara 2021
- CVE-2021-3996630İzleyin
There is an Uninitialized AOD driver structure in Smartphones.Successful exploitation of this vulnerability may affect service confidentiali
YüksekCVSS 7,5İstismar yokEPSS %1huawei · emui3 Oca 2022
- CVE-2021-094730İzleyin
The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM
YüksekCVSS 7,5İstismar yokEPSS %0google · android24 Ağu 2022
- CVE-2021-094630İzleyin
The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolic
YüksekCVSS 7,5İstismar yokEPSS %0google · android24 Ağu 2022
- CVE-2020-1235228İzleyin
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
OrtaCVSS 6,5Kavram kanıtıEPSS %6bluez · bluez23 Kas 2020