CWE-665— Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.— MITRE CWE catalog
370 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-665page 1 of 8
- CVE-2021-38647CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-15
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
- CVE-2022-0847CRITICALCVSS 7.8EG 9.0⚠ KEV2022-03-10
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged lo…
- CVE-2013-1675CRITICALCVSS 6.5EG 9.0⚠ KEV2013-05-16
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNew…
- CVE-2020-27950CRITICALCVSS 5.5EG 9.0⚠ KEV2020-12-08
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.…
- CVE-2026-64775CRITICALCVSS 9.8EG 9.82026-07-27
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be …
- CVE-2024-39864CRITICALCVSS 9.8EG 9.82024-07-05
The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integration.api.port global setting) for internal portal integrations and for testing purposes. By d…
- CVE-2021-33635CRITICALCVSS 9.8EG 9.82023-10-29
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
- CVE-2022-37128CRITICALCVSS 9.8EG 9.82022-08-31
In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.
- CVE-2021-41264CRITICALCVSS 9.8EG 9.82021-11-12
OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. A fix is included in ve…
- CVE-2020-36432CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matrix::new().
- CVE-2019-10196CRITICALCVSS 9.8EG 9.82021-03-19
A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all…
- CVE-2015-8367CRITICALCVSS 9.8EG 9.82020-01-14
The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.
- CVE-2019-14271CRITICALCVSS 9.8EG 9.82019-07-29
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.
- CVE-2018-11949CRITICALCVSS 9.8EG 9.82019-05-24
Failure to initialize the extra buffer can lead to an out of buffer access in WLAN function in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9150, MDM9206, MDM9607, MDM9640…
- CVE-2019-3464CRITICALCVSS 9.8EG 9.82019-02-06
Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell c…
- CVE-2017-13715CRITICALCVSS 9.8EG 9.82017-08-29
The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are initialized, which allows remote attackers to cause a denial of service (system crash) or pos…
- CVE-2022-0947CRITICALCVSS 9.0EG 9.82022-05-10
A vulnerability in ABB ARG600 Wireless Gateway series that could allow an attacker to exploit the vulnerability by remotely connecting to the serial port gateway, and/or protocol converter, depending on the configuration.
- CVE-2021-3329CRITICALCVSS 9.6EG 9.62023-02-26
Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack
- CVE-2023-0397CRITICALCVSS 9.6EG 9.62023-01-19
A malicious / defect bluetooth controller can cause a Denial of Service due to unchecked input in le_read_buffer_size_complete.
- CVE-2024-36455CRITICALCVSS 9.4EG 9.42024-07-15
An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
- CVE-2022-46164CRITICALCVSS 9.4EG 9.42022-12-05
NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerabi…
- CVE-2024-54129CRITICALCVSS 9.2EG 9.22024-12-05
The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vulnerability exists in the version ION-DTN BPv7 implementation version 4.1.3 when receiving a bundle with an improper …
- CVE-2017-5468CRITICALCVSS 9.1EG 9.12018-06-11
An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can result in a non-exploitable crash when manually triggered during debugging. This vulnerability affects Firefox < 53.
- CVE-2025-55118HIGHCVSS 8.9EG 8.92025-09-16
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting …
- CVE-2024-21807HIGHCVSS 8.8EG 8.82024-08-14
Improper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-28737HIGHCVSS 8.8EG 8.82023-11-14
Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-27934HIGHCVSS 8.8EG 8.82023-05-08
A memory initialization issue was addressed. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.
- CVE-2022-2620HIGHCVSS 8.8EG 8.82022-08-12
Use after free in WebUI in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
- CVE-2022-36364HIGHCVSS 8.8EG 8.82022-07-28
Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` connection property; however, the driver does not verify if the class implements the expected interface before instantiati…
- CVE-2019-20063HIGHCVSS 8.8EG 8.82019-12-29
hdf/dataobject.c in libmysofa before 0.8 has an uninitialized use of memory, as demonstrated by mysofa2json.
- CVE-2018-14282HIGHCVSS 8.8EG 8.82018-07-31
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open …
- CVE-2018-10484HIGHCVSS 8.8EG 8.82018-05-17
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open…
- CVE-2017-12736HIGHCVSS 8.8EG 8.82017-12-26
After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions. This could allow an attacker located in the adjacent network of the targeted device to perform unauthori…
- CVE-2017-12262HIGHCVSS 8.8EG 8.82017-11-02
A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow an unauthenticated, adjacent attacker to gain privileged access to services only available …
- CVE-2008-3637HIGHCVSS 8.8EG 8.82008-09-26
The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized variable, which allows remote attackers to execute arbitrary code via a crafted applet, related to an "e…
- CVE-2001-1471HIGHCVSS 8.8EG 8.82001-07-31
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being pro…
- CVE-2021-44169HIGHCVSS 8.2EG 8.82022-04-06
A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6.4.7 and below, version 7.0.3 and below allows attacker to gain administrative privileges via placing a malicious execu…
- CVE-2023-3242HIGHCVSS 8.6EG 8.62023-07-26
Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions.
- CVE-2019-1840HIGHCVSS 8.6EG 8.62019-04-18
A vulnerability in the DHCPv6 input packet processor of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to restart the server and cause a denial of service (DoS) condition on the affected system. The vulnerabi…
- CVE-2019-6230HIGHCVSS 8.6EG 8.62019-03-05
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3,macOS Mojave 10.14.3,tvOS 12.1.2,watchOS 5.1.3. A malicious application may be able to break out of its sandbox.
- CVE-2022-22719HIGHCVSS 7.5EG 8.62022-03-14
A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
- CVE-2018-10915HIGHCVSS 8.5EG 8.52018-08-09
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters…
- CVE-2021-33638HIGHCVSS 8.4EG 8.42023-10-29
When the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, the attacker can escape the container.
- CVE-2021-33637HIGHCVSS 8.4EG 8.42023-10-29
When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container.
- CVE-2021-33636HIGHCVSS 8.4EG 8.42023-10-29
When the isula load command is used to load malicious images, attackers can execute arbitrary code.
- CVE-2020-28019HIGHCVSS 7.5EG 8.42021-05-06
Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of certain getc functions is mishandled when a client uses BDAT instead of DATA.
- CVE-2026-87616HIGHCVSS 8.3EG 8.32026-09-09
Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sa…
- CVE-2024-22064HIGHCVSS 8.3EG 8.32024-05-14
ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devices connecting over …
- CVE-2022-34153HIGHCVSS 8.2EG 8.22023-02-16
Improper initialization in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-12301HIGHCVSS 8.2EG 8.22020-08-13
Improper initialization in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially enable escalation of privilege via local access.
Map vulnerabilities like CWE-665 to your infrastructure
EchelonGraph correlates every CVE — across CWE-665 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →