Vulnerabilities > Insecure Default Initialization of Resource

DATE CVE VULNERABILITY TITLE RISK
2020-11-12 CVE-2020-12336 Insecure Default Initialization of Resource vulnerability in Intel products
Insecure default variable initialization in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-1188
7.8
2020-11-12 CVE-2020-12327 Insecure Default Initialization of Resource vulnerability in Intel Thunderbolt DCH Driver 1.41.1054.0
Insecure default variable initialization in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow a privileged user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-1188
4.4
2020-11-12 CVE-2020-8705 Insecure Default Initialization of Resource vulnerability in Intel products
Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E5_04.01.04.400, E3_04.01.04.200, SoC-X_04.00.04.200 and SoC-A_04.00.04.300 may allow an unauthenticated user to potentially enable escalation of privileges via physical access.
low complexity
intel CWE-1188
6.8
2020-11-10 CVE-2020-13927 Insecure Default Initialization of Resource vulnerability in Apache Airflow
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact.
network
low complexity
apache CWE-1188
critical
9.8
2020-10-29 CVE-2020-11489 Insecure Default Initialization of Resource vulnerability in Intel BMC Firmware 1.06.06/2.47
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contain a vulnerability in the AMI BMC firmware in which default SNMP community strings are used, which may lead to information disclosure.
network
low complexity
intel CWE-1188
7.5
2020-10-14 CVE-2020-0416 Insecure Default Initialization of Resource vulnerability in Google Android
In multiple settings screens, there are possible tapjacking attacks due to an insecure default value.
network
low complexity
google CWE-1188
8.8
2020-10-09 CVE-2020-26930 Insecure Default Initialization of Resource vulnerability in Netgear Ex7700 Firmware
NETGEAR EX7700 devices before 1.0.0.210 are affected by incorrect configuration of security settings.
network
low complexity
netgear CWE-1188
3.8
2020-09-24 CVE-2020-24365 Insecure Default Initialization of Resource vulnerability in Gemteks Wrtm-127Acn Firmware and Wrtm-127X9 Firmware
An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices.
network
low complexity
gemteks CWE-1188
8.8
2020-09-18 CVE-2020-0271 Insecure Default Initialization of Resource vulnerability in Google Android 11.0
In the Settings app, there is an insecure default value.
local
low complexity
google CWE-1188
7.3
2020-09-17 CVE-2020-0394 Insecure Default Initialization of Resource vulnerability in Google Android
In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value.
local
low complexity
google CWE-1188
7.8