CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
930 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 2 of 19
- CVE-2019-7321CRITICALCVSS 9.8EG 9.82019-06-13
Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code.
- CVE-2019-12730CRITICALCVSS 9.8EG 9.82019-06-04
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
- CVE-2019-9805CRITICALCVSS 9.8EG 9.82019-04-26
A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66.
- CVE-2019-9641CRITICALCVSS 9.8EG 9.82019-03-09
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.
- CVE-2019-0006CRITICALCVSS 9.8EG 9.82019-01-15
A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on all EX, QFX and MX Series devices in a Virtual Chassis configuration. This issue can resu…
- CVE-2018-14551CRITICALCVSS 9.8EG 9.82018-07-23
The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an uninitialized variable, leading to memory corruption.
- CVE-2018-5095CRITICALCVSS 9.8EG 9.82018-06-11
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This v…
- CVE-2020-36617CRITICALCVSS 4.6EG 9.82022-12-18
A vulnerability was found in ewxrjk sftpserver. It has been declared as problematic. Affected by this vulnerability is the function sftp_parse_path of the file parse.c. The manipulation leads to uninitialized pointer. The real existence of…
- CVE-2011-1998HIGHCVSS v2 9.3EG 9.32011-10-12
Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "Jscript9.dll Remote Code Execution Vulnerabili…
- CVE-2011-1995HIGHCVSS v2 9.3EG 9.32011-10-12
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "OLEAuto32.dll Remote Code Execution …
- CVE-2011-1964HIGHCVSS v2 9.3EG 9.32011-08-10
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Style Object M…
- CVE-2011-1963HIGHCVSS v2 9.3EG 9.32011-08-10
Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "XSLT Memory Co…
- CVE-2011-1266HIGHCVSS v2 9.3EG 9.32011-06-16
The Vector Markup Language (VML) implementation in vgx.dll in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was n…
- CVE-2011-1262HIGHCVSS v2 9.3EG 9.32011-06-16
Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "HTTP Redirect …
- CVE-2011-1261HIGHCVSS v2 9.3EG 9.32011-06-16
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Selection Obje…
- CVE-2011-1256HIGHCVSS v2 9.3EG 9.32011-06-16
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "DOM Modificati…
- CVE-2011-1255HIGHCVSS v2 9.3EG 9.32011-06-16
The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an objec…
- CVE-2011-1254HIGHCVSS v2 9.3EG 9.32011-06-16
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Drag and Drop …
- CVE-2011-1251HIGHCVSS v2 9.3EG 9.32011-06-16
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "DOM Manipulation Memory …
- CVE-2011-1250HIGHCVSS v2 9.3EG 9.32011-06-16
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Link Propertie…
- CVE-2010-3346HIGHCVSS v2 9.3EG 9.32010-12-16
Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory c…
- CVE-2010-3345HIGHCVSS v2 9.3EG 9.32010-12-16
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption,…
- CVE-2010-3343HIGHCVSS v2 9.3EG 9.32010-12-16
Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption,…
- CVE-2010-2559HIGHCVSS v2 9.3EG 9.32010-08-11
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption,…
- CVE-2010-2557HIGHCVSS v2 9.3EG 9.32010-08-11
Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption,…
- CVE-2010-2556HIGHCVSS v2 9.3EG 9.32010-08-11
Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory c…
- CVE-2007-1751HIGHCVSS v2 9.3EG 9.32007-06-12
Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memo…
- CVE-2026-53225CRITICALCVSS 9.1EG 9.12026-06-25
In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a par…
- CVE-2026-4716CRITICALCVSS 9.1EG 9.12026-03-24
Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
- CVE-2026-4715CRITICALCVSS 9.1EG 9.12026-03-24
Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
- CVE-2026-2806CRITICALCVSS 9.1EG 9.12026-02-24
Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
- CVE-2024-47685CRITICALCVSS 9.1EG 9.12024-10-21
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put() syzbot reported that nf_reject_ip6_tcphdr_put() was possibly sending garbage on the four reserved tcp bits (th-…
- CVE-2021-25905CRITICALCVSS 9.1EG 9.12021-01-26
An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized memory.
- CVE-2026-78519HIGHCVSS 8.8EG 8.82026-09-08
Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- CVE-2026-69485HIGHCVSS 8.8EG 8.82026-09-08
Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.
- CVE-2026-84326HIGHCVSS 8.8EG 8.82026-09-01
Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-53170HIGHCVSS 8.8EG 8.82026-06-25
In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uninitialized length cmd_state_init() initializes the command state with memset(0xff), leaving dma->len at U64_MAX to signal missi…
- CVE-2026-2044HIGHCVSS 8.8EG 8.82026-02-21
GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerabil…
- CVE-2024-38260HIGHCVSS 8.8EG 8.82024-09-10
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- CVE-2024-8178HIGHCVSS 8.8EG 8.82024-09-05
The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code ex…
- CVE-2024-6990HIGHCVSS 8.8EG 8.82024-08-01
Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2023-31275HIGHCVSS 8.8EG 8.82023-11-27
An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel file. A specially crafted malformed file can lead to remote code execution. An attacker can provide a …
- CVE-2023-38151HIGHCVSS 8.8EG 8.82023-11-14
Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability
- CVE-2023-21127HIGHCVSS 8.8EG 8.82023-06-15
In readSampleData of NuMediaExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitat…
- CVE-2023-32213HIGHCVSS 8.8EG 8.82023-06-02
When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
- CVE-2023-24886HIGHCVSS 8.8EG 8.82023-04-11
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-23413HIGHCVSS 8.8EG 8.82023-03-14
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2022-31741HIGHCVSS 8.8EG 8.82022-12-22
A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
- CVE-2022-35414HIGHCVSS 8.8EG 8.82022-07-11
softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference appl…
- CVE-2022-0115HIGHCVSS 8.8EG 8.82022-02-12
Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →