CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
930 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 15 of 19
- CVE-2022-48654MEDIUMCVSS 5.5EG 5.52024-04-28
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix possible bogus match in nf_osf_find() nf_osf_find() incorrectly returns true on mismatch, this leads to copying uninitialized memory area i…
- CVE-2024-26901MEDIUMCVSS 5.5EG 5.52024-04-17
In the Linux kernel, the following vulnerability has been resolved: do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak syzbot identified a kernel information leak vulnerability in do_sys_name_to_handle() and issued the followi…
- CVE-2024-26876MEDIUMCVSS 5.5EG 5.52024-04-17
In the Linux kernel, the following vulnerability has been resolved: drm/bridge: adv7511: fix crash on irq during probe Moved IRQ registration down to end of adv7511_probe(). If an IRQ already is pending during adv7511_probe (before adv7…
- CVE-2024-26863MEDIUMCVSS 5.5EG 5.52024-04-17
In the Linux kernel, the following vulnerability has been resolved: hsr: Fix uninit-value access in hsr_get_node() KMSAN reported the following uninit-value access issue [1]: ===================================================== BUG: KM…
- CVE-2024-26857MEDIUMCVSS 5.5EG 5.52024-04-17
In the Linux kernel, the following vulnerability has been resolved: geneve: make sure to pull inner header in geneve_rx() syzbot triggered a bug in geneve_rx() [1] Issue is similar to the one I fixed in commit 8d975c15c0cd ("ip6_tunnel:…
- CVE-2024-26849MEDIUMCVSS 5.5EG 5.52024-04-17
In the Linux kernel, the following vulnerability has been resolved: netlink: add nla be16/32 types to minlen array BUG: KMSAN: uninit-value in nla_validate_range_unsigned lib/nlattr.c:222 [inline] BUG: KMSAN: uninit-value in nla_validate…
- CVE-2024-26209MEDIUMCVSS 5.5EG 5.52024-04-09
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
- CVE-2024-26805MEDIUMCVSS 5.5EG 5.52024-04-04
In the Linux kernel, the following vulnerability has been resolved: netlink: Fix kernel-infoleak-after-free in __skb_datagram_iter syzbot reported the following uninit-value access issue [1]: netlink_to_full_skb() creates a new `skb` an…
- CVE-2024-26788MEDIUMCVSS 5.5EG 5.52024-04-04
In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-qdma: init irq after reg initialization Initialize the qDMA irqs after the registers are configured so that interrupts that may have been pending from a p…
- CVE-2024-26711MEDIUMCVSS 5.5EG 5.52024-04-03
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad4130: zero-initialize clock init data The clk_init_data struct does not have all its members initialized, causing issues when trying to expose the internal c…
- CVE-2024-26644MEDIUMCVSS 5.5EG 5.52024-03-26
In the Linux kernel, the following vulnerability has been resolved: btrfs: don't abort filesystem when attempting to snapshot deleted subvolume If the source file descriptor to the snapshot ioctl refers to a deleted subvolume, we get the…
- CVE-2021-47139MEDIUMCVSS 5.5EG 5.52024-03-25
In the Linux kernel, the following vulnerability has been resolved: net: hns3: put off calling register_netdev() until client initialize complete Currently, the netdevice is registered before client initializing complete. So there is a t…
- CVE-2021-47136MEDIUMCVSS 5.5EG 5.52024-03-25
In the Linux kernel, the following vulnerability has been resolved: net: zero-initialize tc skb extension on allocation Function skb_ext_add() doesn't initialize created skb extension with any value and leaves it up to the user. However,…
- CVE-2024-26641MEDIUMCVSS 5.5EG 5.52024-03-18
In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, and…
- CVE-2023-52577MEDIUMCVSS 5.5EG 5.52024-03-02
In the Linux kernel, the following vulnerability has been resolved: dccp: fix dccp_v4_err()/dccp_v6_err() again dh->dccph_x is the 9th byte (offset 8) in "struct dccp_hdr", not in the "byte 7" as Jann claimed. We need to make sure the I…
- CVE-2023-52528MEDIUMCVSS 5.5EG 5.52024-03-02
In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg syzbot reported the following uninit-value access issue: ============================================…
- CVE-2021-47056MEDIUMCVSS 5.5EG 5.52024-02-29
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - ADF_STATUS_PF_RUNNING should be set after adf_dev_init ADF_STATUS_PF_RUNNING is (only) used and checked by adf_vf2pf_shutdown() before calling adf_iov_putm…
- CVE-2024-20694MEDIUMCVSS 5.5EG 5.52024-01-09
Windows CoreMessaging Information Disclosure Vulnerability
- CVE-2023-45663MEDIUMCVSS 5.5EG 5.52023-10-21
stb_image is a single file MIT licensed library for processing images. The stbi__getn function reads a specified number of bytes from context (typically a file) into the specified buffer. In case the file stream points to the end, it retur…
- CVE-2023-36713MEDIUMCVSS 5.5EG 5.52023-10-10
Windows Common Log File System Driver Information Disclosure Vulnerability
- CVE-2023-38140MEDIUMCVSS 5.5EG 5.52023-09-12
Windows Kernel Information Disclosure Vulnerability
- CVE-2023-21276MEDIUMCVSS 5.5EG 5.52023-08-14
In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for …
- CVE-2021-0948MEDIUMCVSS 5.5EG 5.52023-07-13
The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel memory to user space. The contents of this memory could contain sensitive information.
- CVE-2023-35326MEDIUMCVSS 5.5EG 5.52023-07-11
Windows CDP User Components Information Disclosure Vulnerability
- CVE-2023-32041MEDIUMCVSS 5.5EG 5.52023-07-11
Windows Update Orchestrator Service Information Disclosure Vulnerability
- CVE-2023-32016MEDIUMCVSS 5.5EG 5.52023-06-14
Windows Installer Information Disclosure Vulnerability
- CVE-2023-21753MEDIUMCVSS 5.5EG 5.52023-01-10
Event Tracing for Windows Information Disclosure Vulnerability
- CVE-2022-40768MEDIUMCVSS 5.5EG 5.52022-09-18
drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.
- CVE-2021-0887MEDIUMCVSS 5.5EG 5.52022-08-24
In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed…
- CVE-2021-0698MEDIUMCVSS 5.5EG 5.52022-08-24
In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo…
- CVE-2022-20357MEDIUMCVSS 5.5EG 5.52022-08-10
In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo…
- CVE-2022-34266MEDIUMCVSS 5.5EG 5.52022-07-19
The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (application crash), a different vulnerability than CVE-2022-0562. When processing a malicious TIFF file, an invalid range m…
- CVE-2021-40608MEDIUMCVSS 5.5EG 5.52022-06-28
The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
- CVE-2022-29205MEDIUMCVSS 5.5EG 5.52022-05-20
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, there is a potential for segfault / denial of service in TensorFlow by calling `tf.compat.v1.*` ops which don't yet have support …
- CVE-2022-20119MEDIUMCVSS 5.5EG 5.52022-05-10
In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not nee…
- CVE-2022-0433MEDIUMCVSS 5.5EG 5.52022-03-10
A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_next_key function of the BPF bloom filter. This flaw allows a local user to crash the system. This flaw affects Linux kern…
- CVE-2021-44003MEDIUMCVSS 5.5EG 5.52021-12-14
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll is vulnerable to use of uninitialized memory while parsing user supplied TIFF files. This cou…
- CVE-2021-41225MEDIUMCVSS 5.5EG 5.52021-11-05
TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's Grappler optimizer has a use of unitialized variable. If the `train_nodes` vector (obtained from the saved model that gets optimized) does not co…
- CVE-2021-0938MEDIUMCVSS 5.5EG 5.52021-10-25
In memzero_explicit of compiler-clang.h, there is a possible bypass of defense in depth due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not need…
- CVE-2021-30027MEDIUMCVSS 5.5EG 5.52021-04-29
md_analyze_line in md4c.c in md4c 0.4.7 allows attackers to trigger use of uninitialized memory, and cause a denial of service via a malformed Markdown document.
- CVE-2021-21218MEDIUMCVSS 5.5EG 5.52021-04-26
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
- CVE-2021-0463MEDIUMCVSS 5.5EG 5.52021-03-10
In convertToHidl of convert.cpp, there is a possible out of bounds read due to uninitialized data from ReturnFrameworkMessage. This could lead to local information disclosure with no additional execution privileges needed. User interaction…
- CVE-2020-15989MEDIUMCVSS 5.5EG 5.52020-11-03
Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
- CVE-2020-16855MEDIUMCVSS 5.5EG 5.52020-09-11
<p>An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerabil…
- CVE-2020-1342MEDIUMCVSS 5.5EG 5.52020-07-14
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka 'Microsoft Office Information Disclosure Vulnerabili…
- CVE-2020-0101MEDIUMCVSS 5.5EG 5.52020-05-14
In BnCrypto::onTransact of ICrypto.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for explo…
- CVE-2020-0048MEDIUMCVSS 5.5EG 5.52020-03-10
In onTransact of IAudioFlinger.cpp, there is a possible stack information leak due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex…
- CVE-2020-0007MEDIUMCVSS 5.5EG 5.52020-01-08
In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not n…
- CVE-2019-18786MEDIUMCVSS 5.5EG 5.52019-11-06
In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could cause a memory disclosure problem.
- CVE-2019-9369MEDIUMCVSS 5.5EG 5.52019-09-27
In Bluetooth, there is a use of uninitialized variable. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10An…
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →