CWE-665— Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.— MITRE CWE catalog
370 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-665page 5 of 8
- CVE-2020-25662MEDIUMCVSS 5.3EG 6.52020-11-05
A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack memory when handling certain AMP packets. This flaw allows a remote attacker in an ad…
- CVE-2017-12164MEDIUMCVSS 4.1EG 6.42018-07-26
A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as another user' to unlock their screen.
- CVE-2021-33634MEDIUMCVSS 6.3EG 6.32023-10-29
iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS.
- CVE-2021-29613MEDIUMCVSS 6.3EG 6.32021-05-14
TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `tf.raw_ops.CTCLoss` allows an attacker to trigger an OOB read from heap. The fix will be included in TensorFlow 2.5.0. We will also cherrypick…
- CVE-2020-8918MEDIUMCVSS 6.3EG 6.32020-08-11
An improperly initialized 'migrationAuth' value in Google's go-tpm TPM1.2 library versions prior to 0.3.0 can lead an eavesdropping attacker to discover the auth value for a key created with CreateWrapKey. An attacker listening in on the c…
- CVE-2017-12847MEDIUMCVSS 6.3EG 6.32017-08-23
Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for nagios.lock modification b…
- CVE-2021-22283MEDIUMCVSS 6.2EG 6.22023-02-28
Improper Initialization vulnerability in ABB Relion protection relays - 611 series, ABB Relion protection relays - 615 series IEC 4.0 FP1, ABB Relion protection relays - 615 series CN 4.0 FP1, ABB Relion protection relays - 615 series IEC …
- CVE-2021-0119MEDIUMCVSS 6.2EG 6.22022-02-09
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
- CVE-2025-46553MEDIUMCVSS 6.1EG 6.12025-05-05
@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, an…
- CVE-2023-27887MEDIUMCVSS 6.1EG 6.12023-08-11
Improper initialization in BIOS firmware for some Intel(R) NUCs may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2022-38083MEDIUMCVSS 6.1EG 6.12023-08-11
Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2023-22444MEDIUMCVSS 6.0EG 6.02023-08-11
Improper initialization in some Intel(R) NUC 13 Extreme Compute Element, Intel(R) NUC 13 Extreme Kit, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Compute Element, Intel(R) NUC Laptop Kit, Intel(R) NUC…
- CVE-2023-22356MEDIUMCVSS 6.0EG 6.02023-08-11
Improper initialization in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2016-6836MEDIUMCVSS 6.0EG 6.02016-12-10
The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveraging failure to initialize the txcq_descr object.
- CVE-2026-12233MEDIUMCVSS 5.9EG 5.92026-08-12
The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its credential-store mutex as a plain zero-filled static struct k_mutex credential_lock; and never called k_mutex_init() on it…
- CVE-2024-12289MEDIUMCVSS 5.9EG 5.92024-12-12
Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulne…
- CVE-2024-32916MEDIUMCVSS 5.9EG 5.92024-06-13
In fvp_freq_histogram_init of fvp.c, there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2022-22169MEDIUMCVSS 5.9EG 5.92022-01-19
An Improper Initialization vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker who sends specific packets in certain orders and at specific timings to force OSPFv3 to unex…
- CVE-2021-3565MEDIUMCVSS 5.9EG 5.92021-06-04
A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highe…
- CVE-2021-34697MEDIUMCVSS 5.8EG 5.82021-09-23
A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct denial of service (DoS) attacks to or through the affected device. …
- CVE-2021-0234MEDIUMCVSS 5.8EG 5.82021-04-22
Due to an improper Initialization vulnerability on Juniper Networks Junos OS QFX5100-96S devices with QFX 5e Series image installed, ddos-protection configuration changes will not take effect beyond the default DDoS (Distributed Denial of …
- CVE-2026-12539MEDIUMCVSS 5.7EG 5.72026-06-18
Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon restarts, so a restart-surviving sandbox forwards ICMP to arb…
- CVE-2023-32467MEDIUMCVSS 5.7EG 5.72024-07-10
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, le…
- CVE-2021-0053MEDIUMCVSS 5.7EG 5.72021-11-17
Improper initialization in firmware for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an authenticated user to potentially enable information disclosure via adjacent access.
- CVE-2026-20734MEDIUMCVSS 5.6EG 5.62026-08-11
Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined…
- CVE-2025-35991MEDIUMCVSS 5.6EG 5.62026-05-12
Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data…
- CVE-2025-5745MEDIUMCVSS 5.6EG 5.62025-06-05
The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers…
- CVE-2025-5702MEDIUMCVSS 5.6EG 5.62025-06-05
The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers …
- CVE-2022-39384MEDIUMCVSS 5.6EG 5.62022-11-04
OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initializer functions that are invoked separate from contract creation (the most prominent example being minimal proxies) may …
- CVE-2025-21906MEDIUMCVSS 5.5EG 5.52025-04-01
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: clean up ROC on failure If the firmware fails to start the session protection, then we do call iwl_mvm_roc_finished() here, but that won't do anythin…
- CVE-2025-25947MEDIUMCVSS 5.5EG 5.52025-02-19
An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file.
- CVE-2024-46697MEDIUMCVSS 5.5EG 5.52024-09-13
In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure that nfsd4_fattr_args.context is zeroed out If nfsd4_encode_fattr4 ends up doing a "goto out" before we get to checking for the security label, then args.co…
- CVE-2024-45018MEDIUMCVSS 5.5EG 5.52024-09-11
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: initialise extack before use Fix missing initialisation of extack in flow offload.
- CVE-2024-44947MEDIUMCVSS 5.5EG 5.52024-09-02
In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store(), unlike fuse_do_readpage(), does not enable page zeroing (because it can be used to…
- CVE-2024-42078MEDIUMCVSS 5.5EG 5.52024-07-29
In the Linux kernel, the following vulnerability has been resolved: nfsd: initialise nfsd_info.mutex early. nfsd_info.mutex can be dereferenced by svc_pool_stats_start() immediately after the new netns is created. Currently this can tri…
- CVE-2024-39485MEDIUMCVSS 5.5EG 5.52024-07-05
In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Properly re-initialise notifier entry in unregister The notifier_entry of a notifier is not re-initialised after unregistering the notifier. This lead…
- CVE-2024-39301MEDIUMCVSS 5.5EG 5.52024-06-25
In the Linux kernel, the following vulnerability has been resolved: net/9p: fix uninit-value in p9_client_rpc() Syzbot with the help of KMSAN reported the following error: BUG: KMSAN: uninit-value in trace_9p_client_res include/trace/ev…
- CVE-2024-38558MEDIUMCVSS 5.5EG 5.52024-06-19
In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix overwriting ct original tuple for ICMPv6 OVS_PACKET_CMD_EXECUTE has 3 main attributes: - OVS_PACKET_ATTR_KEY - Packet metadata in a netlink format…
- CVE-2024-32930MEDIUMCVSS 5.5EG 5.52024-06-13
In plugin_ipc_handler of slc_plugin.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure of 4 bytes of stack memory with no additional execution privileges needed. User in…
- CVE-2023-45315MEDIUMCVSS 5.5EG 5.52024-05-16
Improper initialization in some Intel(R) Power Gadget software for Windwos all versions may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2021-46932MEDIUMCVSS 5.5EG 5.52024-02-27
In the Linux kernel, the following vulnerability has been resolved: Input: appletouch - initialize work before device registration Syzbot has reported warning in __flush_work(). This warning is caused by work->func == NULL, which means m…
- CVE-2023-5370MEDIUMCVSS 5.5EG 5.52023-10-04
On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no speculative execution workarounds being installed on CPU 0.
- CVE-2023-20597MEDIUMCVSS 5.5EG 5.52023-09-20
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
- CVE-2022-48518MEDIUMCVSS 5.5EG 5.52023-07-06
Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofi…
- CVE-2023-27115MEDIUMCVSS 5.5EG 5.52023-03-10
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size.
- CVE-2022-32823MEDIUMCVSS 5.5EG 5.52022-09-23
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be…
- CVE-2021-4218MEDIUMCVSS 5.5EG 5.52022-08-24
A flaw was found in the Linux kernel’s implementation of reading the SVC RDMA counters. Reading the counter sysctl panics the system. This flaw allows a local attacker with local access to cause a denial of service while the system reboo…
- CVE-2022-24378MEDIUMCVSS 5.5EG 5.52022-08-18
Improper initialization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-1122MEDIUMCVSS 5.5EG 5.52022-03-29
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on …
- CVE-2021-0145MEDIUMCVSS 5.5EG 5.52022-02-09
Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Map vulnerabilities like CWE-665 to your infrastructure
EchelonGraph correlates every CVE — across CWE-665 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →