İçeriğe atla
Noroxi

CWE-909 · 80 kayıt

Missing Initialization of Resource

Bu sınıftaki CVE’ler

80 kayıt

  • CVE-2022-22704
    39İzleyin

    The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expe

    KritikCVSS 9,8İstismar yokEPSS %1

    zabbix · zabbix-agent26 Oca 2022

  • CVE-2021-23994
    36İzleyin

    A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write.

    YüksekCVSS 8,8İstismar yokEPSS %2

    mozilla · firefox24 Haz 2021

  • CVE-2020-12523
    36İzleyin

    Phoenix Contact mGuard Devices versions before 8.8.3: LAN ports get functional after reboot even if they are disabled in the device configuration

    KritikCVSS 9,1İstismar yokEPSS %1

    phoenixcontact · tc mguard rs4000 4g vzw vpn firmware17 Ara 2020

  • CVE-2026-40687
    36İzleyin

    In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that

    KritikCVSS 9,1İstismar yokEPSS %1

    exim · exim30 Nis 2026

  • CVE-2021-29980
    35İzleyin

    Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable cra

    YüksekCVSS 8,8İstismar yokEPSS %1

    mozilla · firefox17 Ağu 2021

  • CVE-2020-11741
    35İzleyin

    An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information a

    YüksekCVSS 8,8İstismar yokEPSS %0

    xen · xen14 Nis 2020

  • CVE-2025-8117
    34İzleyin

    Account Takeover via Reset Password Functionality in PAD CMS

    YüksekCVSS 8,7İstismar yokEPSS %0

    widzialni · pad cms30 Eyl 2025

  • CVE-2018-10811
    32İzleyin

    strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.

    YüksekCVSS 7,5İstismar yokEPSS %6

    strongswan · strongswan19 Haz 2018

  • CVE-2019-3804
    31İzleyin

    It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack.

    YüksekCVSS 7,5İstismar yokEPSS %5

    cockpit-project · cockpit26 Mar 2019

  • CVE-2019-12410
    31İzleyin

    While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left

    YüksekCVSS 7,5İstismar yokEPSS %5

    apache · arrow8 Kas 2019

  • CVE-2019-19553
    31İzleyin

    In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash.

    YüksekCVSS 7,5İstismar yokEPSS %4

    wireshark · wireshark4 Ara 2019

  • CVE-2019-12408
    31İzleyin

    It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had

    YüksekCVSS 7,5İstismar yokEPSS %3

    apache · arrow8 Kas 2019

  • CVE-2019-16714
    31İzleyin

    In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack m

    YüksekCVSS 7,5İstismar yokEPSS %3

    linux · linux kernel23 Eyl 2019

  • CVE-2021-36386
    31İzleyin

    report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mai

    YüksekCVSS 7,5İstismar yokEPSS %3

    fetchmail · fetchmail30 Tem 2021

  • CVE-2018-21247
    31İzleyin

    An issue was discovered in LibVNCServer before 0.9.13.

    YüksekCVSS 7,5İstismar yokEPSS %2

    libvnc project · libvncserver17 Haz 2020

  • CVE-2021-36513
    31İzleyin

    An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view

    YüksekCVSS 7,5İstismar yokEPSS %2

    signalwire · freeswitch18 Eki 2021

  • CVE-2022-29968
    31İzleyin

    An issue was discovered in the Linux kernel through 5.17.5.

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    linux · linux kernel2 May 2022

  • CVE-2005-1036
    31İzleyin

    FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allow

    YüksekCVSS 7,8İstismar yokEPSS %0

    freebsd · freebsd2 May 2005

  • CVE-2024-43873
    31İzleyin

    vhost/vsock: always initialize seqpacket_allow

    YüksekCVSS 7,8İstismar yokEPSS %0

    linux · linux kernel20 Ağu 2024

  • CVE-2021-31919
    30İzleyin

    An issue was discovered in the rkyv crate before 0.6.0 for Rust.

    YüksekCVSS 7,5İstismar yokEPSS %1

    rkyv project · rkyv29 Nis 2021

  • CVE-2019-25054
    30İzleyin

    An issue was discovered in the pnet crate before 0.27.2 for Rust.

    YüksekCVSS 7,5İstismar yokEPSS %1

    pnet project · pnet26 Ara 2021

  • CVE-2021-39966
    30İzleyin

    There is an Uninitialized AOD driver structure in Smartphones.Successful exploitation of this vulnerability may affect service confidentiali

    YüksekCVSS 7,5İstismar yokEPSS %1

    huawei · emui3 Oca 2022

  • CVE-2021-0947
    30İzleyin

    The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM

    YüksekCVSS 7,5İstismar yokEPSS %0

    google · android24 Ağu 2022

  • CVE-2021-0946
    30İzleyin

    The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolic

    YüksekCVSS 7,5İstismar yokEPSS %0

    google · android24 Ağu 2022

  • CVE-2020-12352
    28İzleyin

    Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

    OrtaCVSS 6,5Kavram kanıtıEPSS %6

    bluez · bluez23 Kas 2020

Tüm zafiyet sınıfları