VYPR

CWE-665

Improper Initialization

ClassDraftLikelihood: Medium

Description

The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.

This can have security implications when the associated resource is expected to have certain properties or values, such as a variable that determines whether a user has been authenticated or not.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (358)

page 6 of 18
  • CVE-2026-21913HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    An Incorrect Initialization of Resource vulnerability in the Internal Device Manager (IDM) of Juniper Networks Junos OS on EX4000 models allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On EX4000 models with 48 ports (EX4000-48T, EX4000-48P,…

  • CVE-2025-21906HigApr 1, 2025
    risk 0.49cvss 7.6epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: clean up ROC on failure If the firmware fails to start the session protection, then we do call iwl_mvm_roc_finished() here, but that won't do anything at all because…

  • CVE-2024-45289HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.00

    The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option. Fetch would still connect…

  • CVE-2023-1719HigNov 1, 2023
    risk 0.49cvss 7.5epss 0.05

    Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the…

  • CVE-2020-35342HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.01

    GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.

  • CVE-2022-48352HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Some smartphones have data initialization issues. Successful exploitation of this vulnerability may cause a system panic.

  • CVE-2022-32231HigFeb 16, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-23555HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a virtual server, undisclosed traffic can cause the Traffic…

  • CVE-2022-46505HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero MasterSecret that can decrypt secret data.

  • CVE-2022-43468HigDec 7, 2022
    risk 0.49cvss 7.5epss 0.01

    External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article…

  • CVE-2022-2472HigSep 15, 2022
    risk 0.49cvss 7.6epss 0.00

    Improper Initialization vulnerability in the local server component of EZVIZ CS-C6N-A0-1C2WFR allows a local attacker to read the contents of the memory space containing the encrypted admin password. This issue affects: EZVIZ CS-C6N-A0-1C2WFR versions prior to 5.3.0 build 220428.

  • CVE-2022-24316HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-665: Improper Initialization vulnerability exists that could cause information exposure when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)

  • CVE-2021-20613HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.04

    Improper initialization vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.16 and prior, FX3U-ENET-L Firmware version 1.16 and prior and FX3U-ENET-P502 Firmware version 1.16 and prior allows a remote unauthenticated attacker to cause a denial-of-service (DoS)…

  • CVE-2021-40025HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The eID module has a vulnerability that causes the memory to be used without being initialized,Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-0280HigJul 15, 2021
    risk 0.49cvss 7.5epss 0.01

    Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on PTX platforms and QFX10K Series with Paradise (PE) chipset-based line cards, ddos-protection configuration changes made from the CLI will not take effect as expected beyond the default DDoS…

  • CVE-2021-0435HigApr 13, 2021
    risk 0.49cvss 7.5epss 0.02

    In avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-27950MedKEVDec 8, 2020
    risk 0.49cvss 5.5epss 0.17

    A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental…

  • CVE-2020-3811HigMay 26, 2020
    risk 0.49cvss 7.5epss 0.02

    qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.

  • CVE-2020-11655HigApr 9, 2020
    risk 0.49cvss 7.5epss 0.04

    SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.

  • CVE-2020-1617HigApr 8, 2020
    risk 0.49cvss 7.5epss 0.02

    This issue occurs on Juniper Networks Junos OS devices which do not support Advanced Forwarding Interface (AFI) / Advanced Forwarding Toolkit (AFT). Devices using AFI and AFT are not exploitable to this issue. An improper initialization of memory in the packet forwarding…