CWE-1188

Initialization of a Resource with an Insecure Default

Parent: CWE-1419 - Incorrect Initialization of Resource

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

288 vulnerabilities with CWE-1188
CVE-2022-2196 MEDIUM
Linux Kernel <6.2 - Speculative Execution
CVSS 5.8
CVE-2022-20466 MEDIUM
Android - Local Information Disclosure via Insecure Default in NotificationShadeWindowControllerImpl
CVSS 5.5
CVE-2022-46831 MEDIUM
JetBrains TeamCity <2022.10.1 - Privilege Escalation
CVSS 6.6
CVE-2022-3262 HIGH
OpenShift - Insecure Default Variable Initialization in DNS Resolution
CVSS 8.1
CVE-2022-36349 MEDIUM
Intel NUC Board NUC5i3MYBE & Kit NUC5i3MYHE < MYi30060 - DoS via Insecure Default Variable
CVSS 5.2
CVE-2022-41648 CRITICAL
HEIDENHAIN Controller TNC 640 NC <34059007 SP5 - Privilege Escalation
CVSS 9.8
CVE-2022-42467 MEDIUM
Apache Isis < 2.0.0 - Insecure Default Configuration in Prototype Mode
CVSS 5.3
CVE-2022-40468 HIGH
Tinyproxy <84f203f - Info Disclosure
CVSS 7.5
CVE-2022-1278 HIGH
WildFly < 27.0.0 - Information Exposure via Trace Payload
CVSS 7.5
CVE-2022-32480 MEDIUM
Dell PowerScale OneFS 9.0.0-9.1.0.19, 9.2.1.12, 9.3.0.6, 9.4.0.2 - Authenticated Information Disclosure
CVSS 4.3
CVE-2022-20342 LOW
Android 13 - Unauthenticated WiFi Password Disclosure via Insecure Default Value
CVSS 3.3
CVE-2022-31806 CRITICAL
CODESYS V2 <V2.4.7.57 - Info Disclosure
CVSS 9.8
CVE-2022-24287 HIGH
SIMATIC PCS 7 & WinCC - Info Disclosure
CVSS 7.8
CVE-2022-24706 CRITICAL KEV
Apache Couchdb Erlang RCE
CVSS 9.8
CVE-2022-25568 HIGH
MotionEye Config Info Disclosure
CVSS 7.5
CVE-2021-47343 MEDIUM
Linux Kernel < 4.4.276 - Uninitialized Memory Access in dm_btree_remove
CVSS 5.5
CVE-2021-3586 CRITICAL
servicemesh-operator - Info Disclosure
CVSS 9.8
CVE-2021-33130 MEDIUM
Intel(R) RealSense(TM) ID Solution F450 <2.6.0.74 - Info Disclosure
CVSS 4.6
CVE-2021-39767 HIGH
Android 12L - Local Privilege Escalation via Insecure Default Recovery System Properties
CVSS 7.8
CVE-2021-38759 CRITICAL
Raspberry Pi OS <5.10 - Privilege Escalation
CVSS 9.8
CVE-2021-44480 HIGH
Wokka Lokka Q50 Firmware - Unauthenticated Sensitive Information Exposure via SMS Callback
CVSS 8.1
CVE-2021-41192 HIGH
Redash < 10.0.0 - Insecure Default Secret Key
CVSS 8.1
CVE-2021-35535 HIGH
Hitachi Energy Relion 670/650/SAM600-IO - Denial of Service via Insecure Boot Image
CVSS 8.1
CVE-2021-34795 CRITICAL
Cisco Catalyst PON Series Switches ONT Firmware - Unauthenticated Improper Access Control
CVSS 10.0
CVE-2021-42109 CRITICAL
VITEC Exterity IPTV Products < 2021-04-30 - Privilege Escalation to Root
CVSS 9.8
Details
Vulnerabilities 288