The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.
Volume of CVEs assigned to CWE-665 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
352 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0847HIGH A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux ker | Mar 10, 2022 | 7.8 | 98 | YES | YES |
CVE-2022-22719HIGH A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. | Mar 14, 2022 | 7.5 | 65 | NO | NO |
CVE-2020-27950MEDIUM A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Upd | Dec 8, 2020 | 5.5 | 65 | YES | NO |
CVE-2013-1675MEDIUM Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the ns | May 16, 2013 | 6.5 | 61 | YES | NO |
CVE-2020-28019HIGH Exim 4 before 4.94.2 has Improper Initialization that can lead to recursion-based stack consumption or other consequences. This occurs because use of certain getc functions is mish | May 6, 2021 | 7.5 | 56 | NO | NO |
CVE-2022-46164CRITICAL NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to im | Dec 5, 2022 | 9.8 | 50 | NO | NO |
CVE-2023-1719CRITICAL Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute | Nov 1, 2023 | 9.8 | 41 | NO | YES |
CVE-2019-14271CRITICAL In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that | Jul 29, 2019 | 9.8 | 41 | NO | NO |
CVE-2001-1471HIGH prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock i | Jul 31, 2001 | 8.8 | 41 | NO | YES |
CVE-2018-6947HIGH An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged us | Feb 28, 2018 | 7.8 | 37 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.