Vulnerabilities > Insecure Default Initialization of Resource

DATE CVE VULNERABILITY TITLE RISK
2020-10-14 CVE-2020-0416 Insecure Default Initialization of Resource vulnerability in Google Android
In multiple settings screens, there are possible tapjacking attacks due to an insecure default value.
network
google CWE-1188
critical
9.3
2020-10-09 CVE-2020-26930 Insecure Default Initialization of Resource vulnerability in Netgear Ex7700 Firmware
NETGEAR EX7700 devices before 1.0.0.210 are affected by incorrect configuration of security settings.
network
low complexity
netgear CWE-1188
5.5
2020-09-24 CVE-2020-24365 Insecure Default Initialization of Resource vulnerability in Gemteks Wrtm-127Acn Firmware and Wrtm-127X9 Firmware
An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices.
network
low complexity
gemteks CWE-1188
critical
9.0
2020-09-11 CVE-2020-16873 Insecure Default Initialization of Resource vulnerability in Microsoft Xamarin.Forms
<p>A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on Android WebView version prior to 83.0.4103.106.
network
low complexity
microsoft CWE-1188
4.7
2020-09-03 CVE-2020-7729 Insecure Default Initialization of Resource vulnerability in multiple products
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
network
high complexity
gruntjs debian canonical CWE-1188
7.1
2020-07-28 CVE-2020-7685 Insecure Default Initialization of Resource vulnerability in Umbraco Forms
This affects all versions of package UmbracoForms.
network
low complexity
umbraco CWE-1188
7.5
2020-06-24 CVE-2020-10279 Insecure Default Initialization of Resource vulnerability in multiple products
MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots.
7.5
2020-06-15 CVE-2020-14011 Insecure Default Initialization of Resource vulnerability in Lansweeper
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked.
network
low complexity
lansweeper CWE-1188
7.5
2020-03-13 CVE-2019-13393 Insecure Default Initialization of Resource vulnerability in Netgear Cg3700B Firmware 2.02.03
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses the same default 8 character passphrase for the administrative console and the WPA2 pre-shared key.
network
low complexity
netgear CWE-1188
5.0
2020-02-26 CVE-2019-17274 Insecure Default Initialization of Resource vulnerability in Netapp products
NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.
local
low complexity
netapp CWE-1188
7.2