Vulnerabilities > Insecure Default Initialization of Resource

DATE CVE VULNERABILITY TITLE RISK
2023-10-04 CVE-2023-5368 Insecure Default Initialization of Resource vulnerability in Freebsd
On an msdosfs filesystem, the 'truncate' or 'ftruncate' system calls under certain circumstances populate the additional space in the file with unallocated data from the underlying disk device, rather than zero bytes. This may permit a user with write access to files on a msdosfs filesystem to read unintended data (e.g.
network
low complexity
freebsd CWE-1188
6.5
2023-08-23 CVE-2023-3453 Insecure Default Initialization of Resource vulnerability in Etictelecom Remote Access Server Firmware 4.5.0/4.7.0
ETIC Telecom RAS versions 4.7.0 and prior the web management portal authentication disabled by default.
low complexity
etictelecom CWE-1188
8.1
2023-08-14 CVE-2023-35689 Insecure Default Initialization of Resource vulnerability in Google Android 11.0/13.0
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value.
local
low complexity
google CWE-1188
7.8
2023-06-30 CVE-2023-3485 Insecure Default Initialization of Resource vulnerability in Temporal
Insecure defaults in open-source Temporal Server before version 1.20 on all platforms allows an attacker to craft a task token with access to a namespace other than the one specified in the request.
local
high complexity
temporal CWE-1188
3.6
2023-05-24 CVE-2023-33949 Insecure Default Initialization of Resource vulnerability in Liferay Digital Experience Platform and Liferay Portal
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control.
network
low complexity
liferay CWE-1188
7.5
2023-05-22 CVE-2023-31101 Insecure Default Initialization of Resource vulnerability in Apache Inlong 1.5.0/1.6.0
Insecure Default Initialization of Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.6.0.
network
low complexity
apache CWE-1188
6.5
2023-05-19 CVE-2023-1618 Insecure Default Initialization of Resource vulnerability in Mitsubishielectric Melsec Ws0-Geth00200 Firmware
Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior allows a remote unauthenticated attacker to bypass authentication and illegally log into the affected module by connecting to it via telnet which is hidden function and is enabled by default when shipped from the factory.
network
low complexity
mitsubishielectric CWE-1188
8.6
2023-04-24 CVE-2023-27524 Insecure Default Initialization of Resource vulnerability in Apache Superset
Session Validation attacks in Apache Superset versions up to and including 2.0.1.
network
low complexity
apache CWE-1188
critical
9.8
2023-04-17 CVE-2023-28978 Insecure Default Initialization of Resource vulnerability in Juniper Junos OS Evolved
An Insecure Default Initialization of Resource vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to read certain confidential information.
network
low complexity
juniper CWE-1188
5.3
2023-03-24 CVE-2022-38745 Insecure Default Initialization of Resource vulnerability in Apache Openoffice
Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path.
local
low complexity
apache CWE-1188
7.8