CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
854 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 17 of 18
- CVE-2026-55949HIGHCVSS 7.8EG 7.82026-07-14
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-56085LOWCVSS 3.3EG 3.32026-07-03
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of uninitia…
- CVE-2026-56190CRITICALCVSS 9.8EG 9.82026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
- CVE-2026-56968MEDIUMCVSS 5.3EG 5.32026-06-23
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
- CVE-2026-57083MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.
- CVE-2026-57084MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
- CVE-2026-57982MEDIUMCVSS 6.5EG 6.52026-07-14
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
- CVE-2026-58051MEDIUMCVSS 6.5EG 6.52026-06-28
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an unini…
- CVE-2026-58084MEDIUMCVSS 5.5EG 5.52026-08-19
To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. For a timer using CLOCK_TAI this can fail when no TAI offset has been configured, but the error return was n…
- CVE-2026-58247MEDIUMCVSS 5.3EG 5.32026-08-11
SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading to a low on confidentiality, with no impact…
- CVE-2026-58533HIGHCVSS 7.5EG 7.52026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-58535HIGHCVSS 7.5EG 7.52026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-58546MEDIUMCVSS 6.5EG 6.52026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-59136MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
- CVE-2026-59137MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
- CVE-2026-60005HIGHCVSS 8.2EG 8.22026-07-15
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send re…
- CVE-2026-62377MEDIUMCVSS 4.3EG 4.32026-08-18
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash when heif_context_get…
- CVE-2026-62709MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
- CVE-2026-62740MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.
- CVE-2026-62986MEDIUMCVSS 4.3EG 4.32026-08-25
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale heap…
- CVE-2026-63381MEDIUMCVSS 5.8EG 5.82026-08-20
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees…
- CVE-2026-6368LOWCVSS 2.1EG 2.12026-08-10
Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
- CVE-2026-64130MEDIUMCVSS 5.5EG 5.52026-07-19
In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free __GFP_ZEROTAGS semantics are currently a bit weird, but effectively this flag is only …
- CVE-2026-64220MEDIUMCVSS 5.5EG 5.52026-07-24
In the Linux kernel, the following vulnerability has been resolved: device property: set fwnode->secondary to NULL in fwnode_init() If a firmware node is allocated on the stack (for instance: temporary software node whose life-time we co…
- CVE-2026-66034HIGHCVSS 7.5EG 7.52026-07-24
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publick…
- CVE-2026-66038MEDIUMCVSS 6.5EG 6.52026-07-24
FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer…
- CVE-2026-6686MEDIUMCVSS 4.6EG 4.62026-07-01
FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-filling newly allocated clusters. This maps to CWE-908 (Use of Uninitialized Resource). Estimated CVSS v3.1 vector: CVS…
- CVE-2026-6749HIGHCVSS 7.5EG 7.52026-04-21
Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-68744LOWCVSS 3.3EG 3.32026-08-04
A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be trans…
- CVE-2026-68799MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-70317MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-70459MEDIUMCVSS 5.3EG 5.32026-08-13
rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The …
- CVE-2026-70629MEDIUMCVSS 5.5EG 5.52026-08-06
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted vid…
- CVE-2026-70630MEDIUMCVSS 5.5EG 5.52026-08-06
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by sup…
- CVE-2026-70631MEDIUMCVSS 5.5EG 5.52026-08-06
FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply…
- CVE-2026-7141MEDIUMCVSS 5.6EG 5.62026-04-27
A vulnerability was found in vLLM up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of the component KV Block Handler. Performing a manipulation results in uninitialized resource.…
- CVE-2026-76042LOWCVSS 3.1EG 3.12026-08-18
Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-78914MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-78958MEDIUMEG 6.52026-08-25
Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-78962MEDIUMCVSS 4.3EG 4.32026-08-25
Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-78965HIGHEG 8.82026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-78969MEDIUMEG 6.52026-08-25
Uninitialized resource in Video in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-78977MEDIUMEG 5.42026-08-25
Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-78984MEDIUMEG 6.52026-08-25
Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: M…
- CVE-2026-78986HIGHEG 8.82026-08-25
Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-79007MEDIUMEG 6.52026-08-25
Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: M…
- CVE-2026-79040MEDIUMEG 5.42026-08-25
Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-79118HIGHEG 8.82026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-79120MEDIUMEG 6.52026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79221MEDIUMEG 6.52026-08-25
Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →