VYPR

CWE-665

Improper Initialization

ClassDraftLikelihood: Medium

Description

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

This can have security implications when the associated resource is expected to have certain properties or values, such as a variable that determines whether a user has been authenticated or not.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (358)

page 12 of 18
  • CVE-2020-24475MedJun 9, 2021
    risk 0.36cvss 5.5epss 0.00

    Improper initialization in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2020-12326MedNov 12, 2020
    risk 0.36cvss 5.5epss 0.00

    Improper initialization in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-9964MedOct 16, 2020
    risk 0.36cvss 5.5epss 0.00

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 14.0 and iPadOS 14.0. A local user may be able to read kernel memory.

  • CVE-2020-14347MedAug 5, 2020
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.

  • CVE-2020-1389MedJul 14, 2020
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1419, CVE-2020-1426.

  • CVE-2020-9833MedJun 9, 2020
    risk 0.36cvss 5.5epss 0.00

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.5. A local user may be able to read kernel memory.

  • CVE-2020-3872MedFeb 27, 2020
    risk 0.36cvss 5.5epss 0.01

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to read restricted memory.

  • CVE-2019-8540MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.02

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.

  • CVE-2019-8504MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.00

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A local user may be able to read kernel memory.

  • CVE-2019-1409MedNov 12, 2019
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability exists when the Windows Remote Procedure Call (RPC) runtime improperly initializes objects in memory, aka 'Windows Remote Procedure Call Information Disclosure Vulnerability'.

  • CVE-2014-8181MedNov 6, 2019
    risk 0.36cvss 5.5epss 0.00

    The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.

  • CVE-2019-1274MedSep 11, 2019
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'.

  • CVE-2019-1039MedJun 12, 2019
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory. To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could…

  • CVE-2019-0782MedApr 9, 2019
    risk 0.36cvss 5.5epss 0.02

    An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0755, CVE-2019-0767, CVE-2019-0775.

  • CVE-2019-0767MedApr 9, 2019
    risk 0.36cvss 5.5epss 0.02

    An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerability, an authenticated attacker could run a specially crafted application, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE…

  • CVE-2018-4351MedApr 3, 2019
    risk 0.36cvss 5.5epss 0.01

    A memory initialization issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.

  • CVE-2019-0663MedMar 5, 2019
    risk 0.36cvss 5.5epss 0.02

    An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerability, an authenticated attacker could run a specially crafted application, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE…

  • CVE-2018-8514MedDec 12, 2018
    risk 0.36cvss 5.5epss 0.02

    An information disclosure vulnerability exists when Remote Procedure Call runtime improperly initializes objects in memory, aka "Remote Procedure Call runtime Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server…

  • CVE-2018-8408MedNov 14, 2018
    risk 0.36cvss 5.5epss 0.02

    An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012,…

  • CVE-2018-8407MedNov 14, 2018
    risk 0.36cvss 5.5epss 0.02

    An information disclosure vulnerability exists when "Kernel Remote Procedure Call Provider" driver improperly initializes objects in memory, aka "MSRPC Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008,…