CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
930 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 1 of 19
- CVE-2026-85880CRITICALCVSS 7.8EG 9.0⚠ KEV2026-09-08
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
- CVE-2025-5777CRITICALCVSS 7.5EG 9.0⚠ KEV2025-06-17
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
- CVE-2024-50302CRITICALCVSS 5.5EG 9.0⚠ KEV2024-11-19
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make …
- CVE-2024-29745CRITICALCVSS 5.5EG 9.0⚠ KEV2024-04-05
there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-24826CRITICALCVSS 10.0EG 10.02026-01-27
Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reachable Assertion vulnerability in cadaver turso3d.This issue affects .
- CVE-2026-56190CRITICALCVSS 9.8EG 9.82026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
- CVE-2026-52989CRITICALCVSS 9.8EG 9.82026-06-24
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currently, when nvmet_tcp_build_pdu_iovec() detects an out-of-bounds PDU length or offset, it trig…
- CVE-2025-50165CRITICALCVSS 9.8EG 9.82025-08-12
Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- CVE-2025-1942CRITICALCVSS 9.8EG 9.82025-03-04
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.
- CVE-2024-47540CRITICALCVSS 9.8EG 9.82024-12-12
GStreamer is a library for constructing graphs of media-handling components. An uninitialized stack variable vulnerability has been identified in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. When size < 4, the p…
- CVE-2024-32611CRITICALCVSS 9.8EG 9.82024-05-14
HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.
- CVE-2023-4489CRITICALCVSS 9.8EG 9.82023-12-14
The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing netw…
- CVE-2023-24941CRITICALCVSS 9.8EG 9.82023-05-09
Windows Network File System Remote Code Execution Vulnerability
- CVE-2022-26437CRITICALCVSS 9.8EG 9.82022-08-01
In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: …
- CVE-2022-21217CRITICALCVSS 9.8EG 9.82022-01-28
An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to an out-of-bounds write. An attacker can send an HTTP request to trig…
- CVE-2021-45703CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the tectonic_xdv crate before 0.1.12 for Rust. XdvParser::<T>::process may read from uninitialized memory locations.
- CVE-2021-45693CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string_primitive may read from uninitialized memory locations.
- CVE-2021-45692CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_extension_others may read from uninitialized memory locations.
- CVE-2021-45691CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string may read from uninitialized memory locations.
- CVE-2021-45690CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_binary may read from uninitialized memory locations.
- CVE-2021-45689CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the gfx-auxil crate through 2021-01-07 for Rust. gfx_auxil::read_spirv may read from uninitialized memory locations.
- CVE-2021-45688CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the ash crate before 0.33.1 for Rust. util::read_spv may read from uninitialized memory locations.
- CVE-2021-45686CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the csv-sniffer crate through 2021-01-05 for Rust. preamble_skipcount may read from uninitialized memory locations.
- CVE-2021-45685CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the columnar crate through 2021-01-07 for Rust. ColumnarReadExt::read_typed_vec may read from uninitialized memory locations.
- CVE-2021-45684CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the flumedb crate through 2021-01-07 for Rust. read_entry may read from uninitialized memory locations.
- CVE-2021-45683CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the binjs_io crate through 2021-01-03 for Rust. The Read method may read from uninitialized memory locations.
- CVE-2021-45682CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the bronzedb-protocol crate through 2021-01-03 for Rust. ReadKVExt may read from uninitialized memory locations.
- CVE-2020-36514CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. fill_buf may read from uninitialized memory locations.
- CVE-2020-36513CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. read_up_to may read from uninitialized memory locations.
- CVE-2020-36512CRITICALCVSS 9.8EG 9.82021-12-27
An issue was discovered in the buffoon crate through 2020-12-31 for Rust. InputStream::read_exact may read from uninitialized memory locations.
- CVE-2021-40418CRITICALCVSS 9.8EG 9.82021-12-22
When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property containing an object referring to a UUID that was parsed from a frame within the video container. U…
- CVE-2021-1619CRITICALCVSS 9.8EG 9.82021-09-23
A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Insta…
- CVE-2021-1104CRITICALCVSS 9.8EG 9.82021-08-13
The RISC-V Instruction Set Manual contains a documented ambiguity for the Machine Trap Vector Base Address (MTVEC) register that may lead to a vulnerability due to the initial state of the register not being defined, potentially leading to…
- CVE-2020-36452CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the array-tools crate before 0.3.2 for Rust. FixedCapacityDequeLike::clone() has a drop of uninitialized memory.
- CVE-2020-36443CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust. An uninitialized buffer is passed to AsyncRead::poll_read(), which is a user-provided trait function.
- CVE-2020-36432CRITICALCVSS 9.8EG 9.82021-08-08
An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matrix::new().
- CVE-2018-25014CRITICALCVSS 9.8EG 9.82021-05-21
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
- CVE-2021-29937CRITICALCVSS 9.8EG 9.82021-04-01
An issue was discovered in the telemetry crate through 2021-02-17 for Rust. There is a drop of uninitialized memory if a value.clone() call panics within misc::vec_with_size().
- CVE-2021-29936CRITICALCVSS 9.8EG 9.82021-04-01
An issue was discovered in the adtensor crate through 2021-01-11 for Rust. There is a drop of uninitialized memory via the FromIterator implementation for Vector and Matrix.
- CVE-2021-28035CRITICALCVSS 9.8EG 9.82021-03-05
An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a drop of uninitialized memory can occur upon a val.clone() panic.
- CVE-2021-28033CRITICALCVSS 9.8EG 9.82021-03-05
An issue was discovered in the byte_struct crate before 0.6.1 for Rust. There can be a drop of uninitialized memory if a certain deserialization method panics.
- CVE-2021-26951CRITICALCVSS 9.8EG 9.82021-02-09
An issue was discovered in the calamine crate before 0.17.0 for Rust. It allows attackers to overwrite heap-memory locations because Vec::set_len is used without proper memory claiming, and this uninitialized memory is used for a user-prov…
- CVE-2021-26305CRITICALCVSS 9.8EG 9.82021-01-29
An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated heap memory, violating soundness.
- CVE-2020-35888CRITICALCVSS 9.8EG 9.82020-12-31
An issue was discovered in the arr crate through 2020-08-25 for Rust. Uninitialized memory is dropped by Array::new_from_template.
- CVE-2020-35878CRITICALCVSS 9.8EG 9.82020-12-31
An issue was discovered in the ozone crate through 2020-07-04 for Rust. Memory safety is violated because of the dropping of uninitialized memory.
- CVE-2020-24753CRITICALCVSS 9.8EG 9.82020-09-17
A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to execute code via crafted Concise Binary Object Representation (CBOR) input to the cbor2json decoder. An u…
- CVE-2019-14052CRITICALCVSS 9.8EG 9.82020-09-08
u'Accessing an uninitialized data structure could result in partially copying of contents and thus incorrect processing' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdra…
- CVE-2019-10541CRITICALCVSS 9.8EG 9.82019-11-06
Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music…
- CVE-2019-15900CRITICALCVSS 9.8EG 9.82019-10-18
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. Instead, the uninitialized variable errstr was checked and in …
- CVE-2019-5067CRITICALCVSS 9.8EG 9.82019-09-18
An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write from uninitialized memory, resulting in memory corruption and…
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →