Vulnerabilities > Insecure Default Initialization of Resource

DATE CVE VULNERABILITY TITLE RISK
2023-04-24 CVE-2023-27524 Insecure Default Initialization of Resource vulnerability in Apache Superset
Session Validation attacks in Apache Superset versions up to and including 2.0.1.
network
low complexity
apache CWE-1188
critical
9.8
2023-03-29 CVE-2022-48432 Insecure Default Initialization of Resource vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.
local
low complexity
jetbrains CWE-1188
8.8
2023-02-23 CVE-2022-48342 Insecure Default Initialization of Resource vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
network
low complexity
jetbrains CWE-1188
critical
9.8
2023-01-19 CVE-2022-47194 Insecure Default Initialization of Resource vulnerability in Ghost 5.9.4
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
network
low complexity
ghost CWE-1188
5.4
2023-01-19 CVE-2022-47196 Insecure Default Initialization of Resource vulnerability in Ghost 5.9.4
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4.
network
low complexity
ghost CWE-1188
5.4
2023-01-09 CVE-2022-2196 Insecure Default Initialization of Resource vulnerability in multiple products
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) advertising eIBRS support to L1.
local
low complexity
linux debian CWE-1188
8.8
2022-12-13 CVE-2022-20466 Insecure Default Initialization of Resource vulnerability in Google Android
In applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to observe the user's password on a secondary display due to an insecure default value.
local
low complexity
google CWE-1188
5.5
2022-12-08 CVE-2022-46831 Insecure Default Initialization of Resource vulnerability in Jetbrains Teamcity 2022.10/2022.10.1
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
network
low complexity
jetbrains CWE-1188
4.9
2022-12-08 CVE-2022-3262 Insecure Default Initialization of Resource vulnerability in Redhat Openshift 4.9
A flaw was found in Openshift.
network
low complexity
redhat CWE-1188
8.1
2022-11-11 CVE-2022-36349 Insecure Default Initialization of Resource vulnerability in Intel products
Insecure default variable initialization in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow an authenticated user to potentially enable denial of service via local access.
local
low complexity
intel CWE-1188
5.5