VYPR

CWE-665

Improper Initialization

ClassDraftLikelihood: Medium

Description

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

This can have security implications when the associated resource is expected to have certain properties or values, such as a variable that determines whether a user has been authenticated or not.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (358)

page 11 of 18
  • CVE-2025-5702MedJun 5, 2025
    risk 0.36cvss 5.6epss 0.00

    The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in…

  • CVE-2025-25947MedFeb 19, 2025
    risk 0.36cvss 5.5epss 0.00

    An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file.

  • CVE-2024-44947MedSep 2, 2024
    risk 0.36cvss 5.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store(), unlike fuse_do_readpage(), does not enable page zeroing (because it can be used to change partial page contents). So…

  • CVE-2024-42078MedJul 29, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: nfsd: initialise nfsd_info.mutex early. nfsd_info.mutex can be dereferenced by svc_pool_stats_start() immediately after the new netns is created. Currently this can trigger an oops. Move the initialisation…

  • CVE-2024-32930MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    In plugin_ipc_handler of slc_plugin.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure of 4 bytes of stack memory with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-45315MedMay 16, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper initialization in some Intel(R) Power Gadget software for Windwos all versions may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2021-46932MedFeb 27, 2024
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Input: appletouch - initialize work before device registration Syzbot has reported warning in __flush_work(). This warning is caused by work->func == NULL, which means missing work initialization. This may…

  • CVE-2023-5370MedOct 4, 2023
    risk 0.36cvss 5.5epss 0.00

    On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no speculative execution workarounds being installed on CPU 0.

  • CVE-2023-20597MedSep 20, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

  • CVE-2022-48518MedJul 6, 2023
    risk 0.36cvss 5.5epss 0.00

    Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the…

  • CVE-2023-27115MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size.

  • CVE-2022-32823MedSep 23, 2022
    risk 0.36cvss 5.5epss 0.00

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. An app may be able to leak sensitive user information.

  • CVE-2021-4218MedAug 24, 2022
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the Linux kernel’s implementation of reading the SVC RDMA counters. Reading the counter sysctl panics the system. This flaw allows a local attacker with local access to cause a denial of service while the system reboots. The issue is specific to CentOS/RHEL.

  • CVE-2022-24378MedAug 18, 2022
    risk 0.36cvss 5.5epss 0.00

    Improper initialization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2022-1122MedMar 29, 2022
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a…

  • CVE-2021-0145MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2021-0120MedNov 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Improper initialization in the installer for some Intel(R) Graphics DCH Drivers for Windows 10 before version 27.20.100.9316 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2021-26312MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.

  • CVE-2021-0423MedSep 27, 2021
    risk 0.36cvss 5.5epss 0.00

    In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID:…

  • CVE-2021-30962MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.01

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Big Sur 11.6.2. Parsing a maliciously crafted audio file may lead to disclosure of user information.