VYPR

CWE-665

Improper Initialization

ClassDraftLikelihood: Medium

Description

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

This can have security implications when the associated resource is expected to have certain properties or values, such as a variable that determines whether a user has been authenticated or not.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (358)

page 4 of 18
  • CVE-2022-26722HigMay 26, 2022
    risk 0.51cvss 7.8epss 0.01

    A memory initialization issue was addressed. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to gain root privileges.

  • CVE-2022-26721HigMay 26, 2022
    risk 0.51cvss 7.8epss 0.01

    A memory initialization issue was addressed. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to gain root privileges.

  • CVE-2021-26353HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.00

    Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity.

  • CVE-2022-22657HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

  • CVE-2021-26326HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.00

    Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity.

  • CVE-2021-0061HigAug 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper initialization in some Intel(R) Graphics Driver before version 27.20.100.9030 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-26886HigMar 18, 2021
    risk 0.51cvss 7.8epss 0.01

    Softaculous before 5.5.7 is affected by a code execution vulnerability because of External Initialization of Trusted Variables or Data Stores. This leads to privilege escalation on the local host.

  • CVE-2021-1661HigJan 12, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2020-10143HigDec 9, 2020
    risk 0.51cvss 7.8epss 0.01

    Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged service that uses this OpenSSL component. Because unprivileged Windows users can create subdirectories off of the system root, a user can…

  • CVE-2020-8744HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via…

  • CVE-2020-3573HigNov 6, 2020
    risk 0.51cvss 7.8epss 0.03

    Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex…

  • CVE-2020-9863HigOct 22, 2020
    risk 0.51cvss 7.8epss 0.01

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. An application may be able to execute arbitrary code with kernel privileges.

  • CVE-2020-10139HigOct 21, 2020
    risk 0.51cvss 7.8epss 0.00

    Acronis True Image 2021 includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis True Image contains a privileged service that uses this OpenSSL component. Because unprivileged Windows users can create subdirectories…

  • CVE-2020-10138HigOct 21, 2020
    risk 0.51cvss 7.8epss 0.01

    Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis Cyber Backup and Cyber Protect contain a privileged service that uses this OpenSSL component. Because…

  • CVE-2020-24996HigSep 3, 2020
    risk 0.51cvss 7.8epss 0.01

    There is an invalid memory access in the function TextString::~TextString() located in Catalog.cc in Xpdf 4.0.2. It can be triggered by (for example) sending a crafted pdf file to the pdftohtml binary, which allows a remote attacker to cause a Denial of Service (Segmentation…

  • CVE-2020-0586HigJun 15, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper initialization in subsystem for Intel(R) SPS versions before SPS_E3_04.01.04.109.0 and SPS_E3_04.08.04.070.0 may allow an authenticated user to potentially enable escalation of privilege and/or denial of service via local access.

  • CVE-2020-0529HigJun 15, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper initialization in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processor families may allow an unauthenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-3919HigApr 1, 2020
    risk 0.51cvss 7.8epss 0.01

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A malicious application may be able to execute arbitrary code with kernel privileges.

  • CVE-2020-0561HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-8629HigDec 18, 2019
    risk 0.51cvss 7.8epss 0.01

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with system privileges.