CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
854 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 3 of 18
- CVE-2019-18786MEDIUMCVSS 5.5EG 5.52019-11-06
In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could cause a memory disclosure problem.
- CVE-2019-19240MEDIUMCVSS 5.3EG 5.32019-11-22
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can cause a copy of the Host header to fail, l…
- CVE-2019-19535MEDIUMCVSS 4.6EG 4.62019-12-03
In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_fd.c driver, aka CID-30a8beeb3042.
- CVE-2019-19947MEDIUMCVSS 4.6EG 4.62019-12-24
In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c.
- CVE-2019-2004MEDIUMCVSS 5.5EG 5.52019-06-19
In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized data leading to local information disclosure with no additional execution privileges needed. User interaction is not need…
- CVE-2019-20623LOWCVSS 3.3EG 3.32020-03-24
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. Gallery has uninitialized memory disclosure. The Samsung ID is SVE-2018-13060 (February 2019).
- CVE-2019-20785MEDIUMCVSS 6.8EG 6.82020-04-17
An issue was discovered on LG mobile devices with Android OS 8.0 and 8.1 software for the DTAG carrier. RILD in the radio layer uses an uninitialized variable. The LG ID is LVE-SMP-180013 (January 2019).
- CVE-2019-2104MEDIUMCVSS 5.5EG 5.52019-07-08
In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not …
- CVE-2019-2105HIGHCVSS 8.8EG 8.82019-07-08
In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User int…
- CVE-2019-2118MEDIUMCVSS 5.5EG 5.52019-07-08
In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables. These could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo…
- CVE-2019-2140MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac, there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersio…
- CVE-2019-2166MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
- CVE-2019-2167MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
- CVE-2019-2168MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
- CVE-2019-2169MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
- CVE-2019-2170MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
- CVE-2019-2171MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
- CVE-2019-2172MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
- CVE-2019-5067CRITICALCVSS 9.8EG 9.82019-09-18
An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write from uninitialized memory, resulting in memory corruption and…
- CVE-2019-5818MEDIUMCVSS 6.5EG 6.52019-06-27
Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.
- CVE-2019-6976MEDIUMCVSS 5.3EG 5.32019-01-26
libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents…
- CVE-2019-7321CRITICALCVSS 9.8EG 9.82019-06-13
Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code.
- CVE-2019-9322MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9329HIGHCVSS 7.5EG 7.52019-09-27
In Bluetooth, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure, with no additional privileges required. User interaction is not needed for exploitation. Product: AndroidVers…
- CVE-2019-9334MEDIUMCVSS 6.5EG 6.52019-09-27
In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android…
- CVE-2019-9335MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9336MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9337MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9338MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9359MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9361MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9369MEDIUMCVSS 5.5EG 5.52019-09-27
In Bluetooth, there is a use of uninitialized variable. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10An…
- CVE-2019-9391MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: …
- CVE-2019-9406MEDIUMCVSS 6.5EG 6.52019-09-27
In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android…
- CVE-2019-9408MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9409MEDIUMCVSS 6.5EG 6.52019-09-27
In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android…
- CVE-2019-9410MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9411MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9415MEDIUMCVSS 6.5EG 6.52019-09-27
In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: …
- CVE-2019-9416MEDIUMCVSS 6.5EG 6.52019-09-27
In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: …
- CVE-2019-9578HIGHCVSS 7.5EG 7.52019-03-05
In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.
- CVE-2019-9639HIGHCVSS 7.5EG 7.52019-03-09
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.
- CVE-2019-9641CRITICALCVSS 9.8EG 9.82019-03-09
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.
- CVE-2019-9805CRITICALCVSS 9.8EG 9.82019-04-26
A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66.
- CVE-2019-9824MEDIUMCVSS 5.5EG 5.52019-06-03
tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.
- CVE-2020-0006MEDIUMCVSS 6.5EG 6.52020-01-08
In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to remote information disclosure in the NFC server with no additional execution privil…
- CVE-2020-0007MEDIUMCVSS 5.5EG 5.52020-01-08
In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not n…
- CVE-2020-0048MEDIUMCVSS 5.5EG 5.52020-03-10
In onTransact of IAudioFlinger.cpp, there is a possible stack information leak due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex…
- CVE-2020-0049MEDIUMCVSS 6.5EG 6.52020-03-10
In onReadBuffer() of StreamingSource.cpp, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for…
- CVE-2020-0101MEDIUMCVSS 5.5EG 5.52020-05-14
In BnCrypto::onTransact of ICrypto.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for explo…
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →