CWE-665— Improper Initialization
The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.— MITRE CWE catalog
370 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-665page 7 of 8
- CVE-2020-9775MEDIUMCVSS 5.3EG 5.32020-04-01
An issue existed in the handling of tabs displaying picture in picture video. The issue was corrected with improved state handling. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user's private browsing activity may be unexpectedly sav…
- CVE-2016-1000109MEDIUMCVSS 5.3EG 5.32020-02-19
HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attack…
- CVE-2018-2934MEDIUMCVSS 5.3EG 5.32018-07-18
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticate…
- CVE-2020-16901MEDIUMCVSS 5.0EG 5.02020-10-16
<p>An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.</p> <p>To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who …
- CVE-2019-6190MEDIUMCVSS 5.0EG 5.02020-02-14
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep…
- CVE-2018-8121MEDIUMCVSS 4.7EG 4.72018-06-14
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique …
- CVE-2018-0901MEDIUMCVSS 4.7EG 4.72018-03-14
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows…
- CVE-2018-0897MEDIUMCVSS 4.7EG 4.72018-03-14
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows…
- CVE-2018-0895MEDIUMCVSS 4.7EG 4.72018-03-14
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows…
- CVE-2018-0810MEDIUMCVSS 4.7EG 4.72018-02-15
The Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2, and Windows Server 2012 allows an information disclosure vulnerability due to the way memory is initialized, aka "Windows Kernel Information Disclosure Vulnerability". Th…
- CVE-2018-0746MEDIUMCVSS 4.7EG 4.72018-01-04
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory…
- CVE-2018-0745MEDIUMCVSS 4.7EG 4.72018-01-04
The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Windows Information Disclosure Vulne…
- CVE-2017-14159MEDIUMCVSS 4.7EG 4.72017-09-05
slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification befo…
- CVE-2021-33130MEDIUMCVSS 4.6EG 4.62022-05-12
Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated user to potentially enable information disclosure via physical access.
- CVE-2022-20661MEDIUMCVSS 4.6EG 4.62022-04-15
Multiple vulnerabilities that affect Cisco Catalyst Digital Building Series Switches and Cisco Catalyst Micro Switches could allow an attacker to execute persistent code at boot time or to permanently prevent the device from booting, resul…
- CVE-2020-35508MEDIUMCVSS 4.5EG 4.52021-03-26
A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to …
- CVE-2025-12902MEDIUMCVSS 4.4EG 4.42025-11-07
Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authorized access to a locked Storage Device or create a Denial of Service.
- CVE-2023-20594MEDIUMCVSS 4.4EG 4.42023-09-20
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
- CVE-2022-20015MEDIUMCVSS 4.4EG 4.42022-01-04
In kd_camera_hw driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch I…
- CVE-2021-39636MEDIUMCVSS 4.4EG 4.42021-12-15
In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is…
- CVE-2021-20317MEDIUMCVSS 4.4EG 4.42021-09-27
A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of servi…
- CVE-2021-0095MEDIUMCVSS 4.4EG 4.42021-06-09
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.
- CVE-2020-24507MEDIUMCVSS 4.4EG 4.42021-06-09
Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user to potentially enable information discl…
- CVE-2021-1780MEDIUMCVSS 4.4EG 4.42021-04-02
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 14.4 and iPadOS 14.4. An attacker in a privileged position may be able to perform a denial of service attack.
- CVE-2021-0453MEDIUMCVSS 4.4EG 4.42021-03-10
In the Titan-M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2021-0452MEDIUMCVSS 4.4EG 4.42021-03-10
In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2021-0451MEDIUMCVSS 4.4EG 4.42021-03-10
In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2021-0450MEDIUMCVSS 4.4EG 4.42021-03-10
In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2021-0449MEDIUMCVSS 4.4EG 4.42021-03-10
In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2020-0522MEDIUMCVSS 4.4EG 4.42021-02-17
Improper initialization in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may allow a privileged user to potentially enable denial of service via local access.
- CVE-2019-14556MEDIUMCVSS 4.4EG 4.42020-10-05
Improper initialization in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow a privileged user to potentially enable denial of service via local access.
- CVE-2020-0272MEDIUMCVSS 4.4EG 4.42020-09-18
In libhwbinder, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product: Andro…
- CVE-2020-1592MEDIUMCVSS 4.4EG 4.42020-09-11
<p>An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.</p> <p>To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who …
- CVE-2026-78940MEDIUMCVSS 4.3EG 4.32026-08-25
Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2023-35061MEDIUMCVSS 4.3EG 4.32024-02-14
Improper initialization for the Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
- CVE-2019-1761MEDIUMCVSS 4.3EG 4.32019-03-28
A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to receive potentially sensitive information from an affected device. The vulnerability …
- CVE-2012-0012MEDIUMCVSS v2 4.3EG 4.32012-02-14
Microsoft Internet Explorer 9 does not properly handle the creation and initialization of string objects, which allows remote attackers to read data from arbitrary process-memory locations via a crafted web site, aka "Null Byte Information…
- CVE-2025-22834MEDIUMCVSS 4.2EG 4.22025-08-12
AMI APTIOV contains a vulnerability in BIOS where a user may cause “Improper Initialization” by local accessing. Successful exploitation of this vulnerability may leave the resource in an unexpected state and potentially impact confide…
- CVE-2025-21100MEDIUMCVSS 4.1EG 4.12025-05-13
Improper initialization in the UEFI firmware for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2026-34553MEDIUMCVSS 4.0EG 4.02026-03-31
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a defect in LUT dump/iteration logic affecting CIccCLUT::Iterate() and output produced by CIccMBB::Describe() (…
- CVE-2022-31477MEDIUMCVSS 4.0EG 4.02023-05-10
Improper initialization for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2025-14955LOWCVSS 3.7EG 3.72025-12-19
A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component PFCP. The manipulation results in improper initialization. It is…
- CVE-2023-26084LOWCVSS 3.7EG 3.72023-03-15
The armv8_dec_aes_gcm_full() API of Arm AArch64cryptolib before 86065c6 fails to the verify the authentication tag of AES-GCM protected data, leading to a man-in-the-middle attack. This occurs because of an improperly initialized variable.
- CVE-2019-19411LOWCVSS 3.7EG 3.72020-01-21
USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 have an information leakage vulnerability. Due to improper processing of the initialization vector us…
- CVE-2021-29611LOWCVSS 3.6EG 3.62021-05-14
TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `SparseReshape` results in a denial of service based on a `CHECK`-failure. The implementation(https://github.com/tensorflow/tensorflow/blob/e87…
- CVE-2021-29610LOWCVSS 3.6EG 3.62021-05-14
TensorFlow is an end-to-end open source platform for machine learning. The validation in `tf.raw_ops.QuantizeAndDequantizeV2` allows invalid values for `axis` argument:. The validation(https://github.com/tensorflow/tensorflow/blob/eccb7ec4…
- CVE-2014-0178LOWCVSS v2 3.5EG 3.52014-05-28
Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users t…
- CVE-2024-25563LOWCVSS 3.4EG 3.42024-11-13
Improper initialization in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi before version 23.40 may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2025-25058LOWCVSS 3.3EG 3.32026-02-10
Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) & 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an information disclosure. Unprivileged softwa…
- CVE-2025-24511LOWCVSS 3.3EG 3.32025-08-12
Improper initialization in the Linux kernel-mode driver for some Intel(R) I350 Series Ethernet before version 5.19.2 may allow an authenticated user to potentially enable Information disclosure via data exposure.
Map vulnerabilities like CWE-665 to your infrastructure
EchelonGraph correlates every CVE — across CWE-665 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →