CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
930 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 17 of 19
- CVE-2020-7042MEDIUMCVSS 5.3EG 5.32020-02-27
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never …
- CVE-2019-19240MEDIUMCVSS 5.3EG 5.32019-11-22
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can cause a copy of the Host header to fail, l…
- CVE-2019-1010299MEDIUMCVSS 5.3EG 5.32019-07-15
The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of uninitialized memory could be printed to string or to log file. The component is: Debug trait impleme…
- CVE-2019-13117MEDIUMCVSS 5.3EG 5.32019-07-01
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a…
- CVE-2019-11038MEDIUMCVSS 5.3EG 5.32019-06-19
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that w…
- CVE-2019-6976MEDIUMCVSS 5.3EG 5.32019-01-26
libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents…
- CVE-2024-8654MEDIUMCVSS 5.0EG 5.02024-09-10
MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 version 6.0.3.
- CVE-2024-26220MEDIUMCVSS 5.0EG 5.02024-04-09
Windows Mobile Hotspot Information Disclosure Vulnerability
- CVE-2026-106275MEDIUMCVSS 4.7EG 4.72026-10-06
Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-106395MEDIUMCVSS 4.7EG 4.72026-10-06
Uninitialized resource in Dawn in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106370MEDIUMCVSS 4.7EG 4.72026-10-06
Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity:…
- CVE-2026-106290MEDIUMCVSS 4.7EG 4.72026-10-06
Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity:…
- CVE-2026-106223MEDIUMCVSS 4.7EG 4.72026-10-06
Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106273MEDIUMCVSS 4.7EG 4.72026-10-06
Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-106202MEDIUMCVSS 4.7EG 4.72026-10-06
Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-106231MEDIUMCVSS 4.7EG 4.72026-10-06
Uninitialized resource in Dawn in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-106215MEDIUMCVSS 4.7EG 4.72026-10-06
Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-106376MEDIUMCVSS 4.7EG 4.72026-10-06
Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-106258MEDIUMCVSS 4.7EG 4.72026-10-06
Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-102307MEDIUMCVSS 4.7EG 4.72026-09-29
Uninitialized resource in Dawn in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-102313MEDIUMCVSS 4.7EG 4.72026-09-29
Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-95293MEDIUMCVSS 4.7EG 4.72026-09-29
Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-91720MEDIUMCVSS 4.7EG 4.72026-09-15
Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-87555MEDIUMCVSS 4.7EG 4.72026-09-09
Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-69853MEDIUMCVSS 4.7EG 4.72026-09-08
Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally.
- CVE-2026-23101MEDIUMCVSS 4.7EG 4.72026-02-04
In the Linux kernel, the following vulnerability has been resolved: leds: led-class: Only Add LED to leds_list when it is fully ready Before this change the LED was added to leds_list before led_init_core() gets called adding it the list…
- CVE-2024-36927MEDIUMCVSS 4.7EG 4.72024-05-30
In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix uninit-value access in __ip_make_skb() KMSAN reported uninit-value access in __ip_make_skb() [1]. __ip_make_skb() tests HDRINCL to know if the skb has icmphdr…
- CVE-2023-25588MEDIUMCVSS 4.7EG 4.72023-09-14
A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and local denial of service.
- CVE-2023-25586MEDIUMCVSS 4.7EG 4.72023-09-14
A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.
- CVE-2023-25585MEDIUMCVSS 4.7EG 4.72023-09-14
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.
- CVE-2023-36836MEDIUMCVSS 4.7EG 4.72023-07-14
A Use of an Uninitialized Resource vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial of Service (DoS). On all …
- CVE-2020-3964MEDIUMCVSS 4.7EG 4.72020-06-25
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain an information leak in the EHCI USB controlle…
- CVE-2026-6686MEDIUMCVSS 4.6EG 4.62026-07-01
FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-filling newly allocated clusters. This maps to CWE-908 (Use of Uninitialized Resource). Estimated CVSS v3.1 vector: CVS…
- CVE-2026-26175MEDIUMCVSS 4.6EG 4.62026-04-14
Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2022-20008MEDIUMCVSS 4.6EG 4.62022-05-10
In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This could lead to local information disclosure if reading from an SD card that triggers errors, with no additional execution …
- CVE-2019-19947MEDIUMCVSS 4.6EG 4.62019-12-24
In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c.
- CVE-2019-19535MEDIUMCVSS 4.6EG 4.62019-12-03
In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_fd.c driver, aka CID-30a8beeb3042.
- CVE-2025-20638MEDIUMCVSS 4.3EG 4.62025-02-03
In DA, there is a possible read of uninitialized heap data due to uninitialized data. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User i…
- CVE-2025-27796MEDIUMCVSS 4.5EG 4.52025-03-07
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.
- CVE-2025-12474MEDIUMCVSS 4.4EG 4.42026-02-11
A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optim…
- CVE-2026-20962MEDIUMCVSS 4.4EG 4.42026-01-13
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.
- CVE-2024-26638MEDIUMCVSS 4.4EG 4.42024-03-18
In the Linux kernel, the following vulnerability has been resolved: nbd: always initialize struct msghdr completely syzbot complains that msg->msg_get_inq value can be uninitialized [1] struct msghdr got many new fields recently, we sho…
- CVE-2022-20176MEDIUMCVSS 4.4EG 4.42022-06-15
In auth_store of sjtag-driver.c, there is a possible read of uninitialized memory due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for ex…
- CVE-2022-20096MEDIUMCVSS 4.4EG 4.42022-05-03
In camera, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS0641900…
- CVE-2022-20079MEDIUMCVSS 4.4EG 4.42022-04-11
In vow, there is a possible read of uninitialized data due to a improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: A…
- CVE-2022-0494MEDIUMCVSS 4.4EG 4.42022-03-25
A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kernel. This flaw allows a local attacker with a special user privilege (CAP_SYS_ADMIN or CAP_SYS_RAWIO) to create issues wi…
- CVE-2021-39680MEDIUMCVSS 4.4EG 4.42022-01-14
In sec_SHA256_Transform of sha256_core.c, there is a possible way to read heap data due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for expl…
- CVE-2022-20018MEDIUMCVSS 4.4EG 4.42022-01-04
In seninf driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP…
- CVE-2022-20015MEDIUMCVSS 4.4EG 4.42022-01-04
In kd_camera_hw driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch I…
- CVE-2021-37682MEDIUMCVSS 4.4EG 4.42021-08-12
TensorFlow is an end-to-end open source platform for machine learning. In affected versions all TFLite operations that use quantization can be made to use unitialized values. [For example](https://github.com/tensorflow/tensorflow/blob/460e…
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →