CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
930 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 18 of 19
- CVE-2020-26266MEDIUMCVSS 4.4EG 4.42020-12-10
In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code execution. This is caused by having tensor buffers be filled with the default value of the type but forgetting to defa…
- CVE-2020-26271MEDIUMCVSS 4.4EG 4.42020-12-10
In affected versions of TensorFlow under certain cases, loading a saved model can result in accessing uninitialized memory while building the computation graph. The MakeEdge function creates an edge between one output tensor of the src nod…
- CVE-2020-0272MEDIUMCVSS 4.4EG 4.42020-09-18
In libhwbinder, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product: Andro…
- CVE-2020-11494MEDIUMCVSS 4.4EG 4.42020-04-02
An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the …
- CVE-2016-5105MEDIUMCVSS 4.4EG 4.42016-09-02
The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vecto…
- CVE-2020-10732MEDIUMCVSS 3.3EG 4.42020-06-12
A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.
- CVE-2022-33716MEDIUMCVSS 2.3EG 4.42022-08-05
An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local attacker to read uninitialized memory.
- CVE-2026-106184MEDIUMCVSS 4.3EG 4.32026-10-06
Uninitialized resource in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-106379MEDIUMCVSS 4.3EG 4.32026-10-06
Uninitialized resource in Skia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-106245MEDIUMCVSS 4.3EG 4.32026-10-06
Uninitialized resource in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-102325MEDIUMCVSS 4.3EG 4.32026-09-29
Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-102300MEDIUMCVSS 4.3EG 4.32026-09-29
Uninitialized resource in WebGPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-102303MEDIUMCVSS 4.3EG 4.32026-09-29
Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-91740MEDIUMCVSS 4.3EG 4.32026-09-15
Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-87497MEDIUMCVSS 4.3EG 4.32026-09-09
Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-87642MEDIUMCVSS 4.3EG 4.32026-09-09
Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-84267MEDIUMCVSS 4.3EG 4.32026-09-01
A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving …
- CVE-2026-79040MEDIUMCVSS 4.3EG 4.32026-08-25
Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-78962MEDIUMCVSS 4.3EG 4.32026-08-25
Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79269MEDIUMCVSS 4.3EG 4.32026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79118MEDIUMCVSS 4.3EG 4.32026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-78965MEDIUMCVSS 4.3EG 4.32026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-62986MEDIUMCVSS 4.3EG 4.32026-08-25
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale heap…
- CVE-2026-62377MEDIUMCVSS 4.3EG 4.32026-08-18
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash when heif_context_get…
- CVE-2025-9640MEDIUMCVSS 4.3EG 4.32025-10-15
A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, re…
- CVE-2020-17482MEDIUMCVSS 4.3EG 4.32020-10-02
An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory.
- CVE-2020-12864MEDIUMCVSS 4.3EG 4.32020-06-24
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.
- CVE-2020-6792MEDIUMCVSS 4.3EG 4.32020-03-02
When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 68.5.
- CVE-2018-6132MEDIUMCVSS 4.3EG 4.32019-06-27
Uninitialized data in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.
- CVE-2018-1037MEDIUMCVSS 4.3EG 4.32018-04-12
An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory while compiling program database (PDB) files, aka "Microsoft Visual Studio Information Disclosure Vulnerability…
- CVE-2017-5103MEDIUMCVSS 4.3EG 4.32017-10-27
Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2017-5102MEDIUMCVSS 4.3EG 4.32017-10-27
Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2026-48104MEDIUMCVSS 4.2EG 4.22026-06-05
7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain an uninitialized heap read in the SquashFS archive handler caused by a sparsely populated index array. In the SquashFS handler, _blockToNode is all…
- CVE-2024-56446MEDIUMCVSS 4.0EG 4.02025-01-08
Vulnerability of variables not being initialized in the notification module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2021-47096MEDIUMCVSS 4.0EG 4.02024-03-04
In the Linux kernel, the following vulnerability has been resolved: ALSA: rawmidi - fix the uninitalized user_pversion The user_pversion was uninitialized for the user space file structure in the open function, because the file private s…
- CVE-2021-3435MEDIUMCVSS 4.0EG 4.02022-06-28
Information leakage in le_ecred_conn_req(). Zephyr versions >= v2.4.0 Use of Uninitialized Resource (CWE-908). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-xhg3-gvj6-4rqh
- CVE-2024-45618LOWCVSS 3.9EG 3.92024-09-03
A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of…
- CVE-2024-45617LOWCVSS 3.9EG 3.92024-09-03
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or …
- CVE-2024-45616LOWCVSS 3.9EG 3.92024-09-03
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following pr…
- CVE-2024-45615LOWCVSS 3.9EG 3.92024-09-03
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).
- CVE-2023-3488LOWCVSS 3.8EG 3.82023-07-28
Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stack via malformed GBL file.
- CVE-2026-102635LOWCVSS 3.7EG 3.72026-09-29
ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to rea…
- CVE-2026-11809LOWCVSS 3.7EG 3.72026-08-10
The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z_impl_updatehub_probe(). The probe response from the UpdateHub server is copied into a heap buffer (metadata) that is c…
- CVE-2021-29623LOWCVSS 3.6EG 3.62021-05-13
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and…
- CVE-2022-39282LOWCVSS 3.5EG 3.52022-10-12
FreeRDP is a free remote desktop protocol library and clients. FreeRDP based clients on unix systems using `/parallel` command line switch might read uninitialized data and send it to the server the client is currently connected to. FreeRD…
- CVE-2026-102315LOWCVSS 3.4EG 3.42026-09-29
Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severit…
- CVE-2026-102319LOWCVSS 3.4EG 3.42026-09-29
Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-102311LOWCVSS 3.4EG 3.42026-09-29
Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity:…
- CVE-2026-95359LOWCVSS 3.4EG 3.42026-09-29
Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity:…
- CVE-2026-95324LOWCVSS 3.4EG 3.42026-09-29
Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →