CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
930 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 3 of 19
- CVE-2021-30578HIGHCVSS 8.8EG 8.82021-08-03
Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
- CVE-2021-0473HIGHCVSS 8.8EG 8.82021-06-11
In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitat…
- CVE-2021-21190HIGHCVSS 8.8EG 8.82021-03-09
Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
- CVE-2020-0321HIGHCVSS 8.8EG 8.82020-09-17
In the mp3 extractor, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidV…
- CVE-2020-6398HIGHCVSS 8.8EG 8.82020-02-11
Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
- CVE-2019-13747HIGHCVSS 8.8EG 8.82019-12-10
Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2019-2105HIGHCVSS 8.8EG 8.82019-07-08
In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User int…
- CVE-2019-13135HIGHCVSS 8.8EG 8.82019-07-01
ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.
- CVE-2018-6981HIGHCVSS 8.8EG 8.82018-12-04
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware Workstation 15, VMware Workstation 14.1.3 or below, VMware Fusion 11, VMware Fusion 10.1.3 …
- CVE-2008-3475HIGHCVSS 8.8EG 8.82008-10-15
Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code …
- CVE-2008-4197HIGHCVSS 8.8EG 8.82008-09-27
Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbit…
- CVE-2008-2934HIGHCVSS 8.8EG 8.82008-07-18
Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.
- CVE-2024-23159HIGHCVSS 7.8EG 8.82024-06-25
A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current pro…
- CVE-2024-7022HIGHCVSS 4.3EG 8.82024-09-23
Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2025-31649HIGHCVSS 8.7EG 8.72025-11-17
A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to execut…
- CVE-2025-31361HIGHCVSS 8.7EG 8.72025-11-17
A privilege escalation vulnerability exists in the ControlVault WBDI Driver WBIO_USH_ADD_RECORD functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit c…
- CVE-2026-43139HIGHCVSS 8.6EG 8.62026-05-06
In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() xfrm6_get_saddr() does not check the return value of ipv6_dev_get_saddr(). When ipv6_dev_get_saddr() fails to find a …
- CVE-2026-40364HIGHCVSS 8.4EG 8.42026-05-12
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2017-18306HIGHCVSS 8.4EG 8.42024-11-26
Information disclosure due to uninitialized variable.
- CVE-2024-33021HIGHCVSS 8.4EG 8.42024-08-05
Memory corruption while processing IOCTL call to set metainfo.
- CVE-2020-11260HIGHCVSS 8.4EG 8.42021-06-09
An improper free of uninitialized memory can occur in DIAG services in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2026-43291HIGHCVSS 8.3EG 8.32026-05-08
In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Fix parameter validation for packet data Since commit 9c328f54741b ("net: nfc: nci: Add parameter validation for packet data") communication with nci nfc …
- CVE-2026-60005HIGHCVSS 8.2EG 8.22026-07-15
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send re…
- CVE-2024-7868HIGHCVSS 8.2EG 8.22024-08-15
In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.
- CVE-2020-13113HIGHCVSS 8.2EG 8.22020-05-21
An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.
- CVE-2019-17533HIGHCVSS 8.2EG 8.22019-10-13
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.
- CVE-2025-33070HIGHCVSS 8.1EG 8.12025-06-10
Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
- CVE-2023-6324HIGHCVSS 8.1EG 8.12024-05-15
ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity
- CVE-2022-29240HIGHCVSS 8.1EG 8.12022-09-15
Scylla is a real-time big data database that is API-compatible with Apache Cassandra and Amazon DynamoDB. When decompressing CQL frame received from user, Scylla assumes that user-provided uncompressed length is correct. If user provides f…
- CVE-2022-32745HIGHCVSS 8.1EG 8.12022-08-25
A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting in a segmentation fault.
- CVE-2009-1529HIGHCVSS 8.1EG 8.12009-06-10
Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code …
- CVE-2026-16868HIGHCVSS 7.5EG 8.12026-08-13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length processing.
- CVE-2026-47600HIGHCVSS 7.8EG 7.82026-09-30
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an error-handling path could operate on an improperly initialized resource. A successful exploit of this vulnerability might lead to co…
- CVE-2026-64082HIGHCVSS 7.8EG 7.82026-07-19
In the Linux kernel, the following vulnerability has been resolved: riscv: Fix register corruption from uninitialized cregs on error compat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when user_regset_copyin() fails. Sinc…
- CVE-2026-55949HIGHCVSS 7.8EG 7.82026-07-14
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-43456HIGHCVSS 7.8EG 7.82026-05-08
In the Linux kernel, the following vulnerability has been resolved: bonding: fix type confusion in bond_setup_by_slave() kernel BUG at net/core/skbuff.c:2306! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI RIP: 0010:pskb_expand_head+0xa…
- CVE-2026-31693HIGHCVSS 7.8EG 7.82026-04-30
In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we have a label to signify the start of the code where a request can be replayed if necessary…
- CVE-2026-23317HIGHCVSS 7.8EG 7.82026-03-25
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Return the correct value in vmw_translate_ptr functions Before the referenced fixes these functions used a lookup function that returned a pointer. This was …
- CVE-2025-40829HIGHCVSS 7.8EG 7.82025-12-12
A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uninitialized memory vulnerability while parsing specially crafted SLDPRT files. This could allow an attacker to execute c…
- CVE-2025-62472HIGHCVSS 7.8EG 7.82025-12-09
Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
- CVE-2022-50546HIGHCVSS 7.8EG 7.82025-10-07
In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninititialized value in 'ext4_evict_inode' Syzbot found the following issue: ===================================================== BUG: KMSAN: uninit-value in…
- CVE-2023-53578HIGHCVSS 7.8EG 7.82025-10-04
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: Fix an uninit variable access bug in qrtr_tx_resume() Syzbot reported a bug as following: ===================================================== BUG: KMSAN: u…
- CVE-2025-38718HIGHCVSS 7.8EG 7.82025-09-04
In the Linux kernel, the following vulnerability has been resolved: sctp: linearize cloned gso packets in sctp_rcv A cloned head skb still shares these frag skbs in fraglist with the original head skb. It's not safe to access these frag …
- CVE-2025-38579HIGHCVSS 7.8EG 7.82025-08-19
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix KMSAN uninit-value in extent_info usage KMSAN reported a use of uninitialized value in `__is_extent_mergeable()` and `__is_back_mergeable()` via the read exte…
- CVE-2025-38574HIGHCVSS 7.8EG 7.82025-08-19
In the Linux kernel, the following vulnerability has been resolved: pptp: ensure minimal skb length in pptp_xmit() Commit aabc6596ffb3 ("net: ppp: Add bound checking for skb data on ppp_sync_txmung") fixed ppp_sync_txmunge() We need a s…
- CVE-2025-53759HIGHCVSS 7.8EG 7.82025-08-12
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-1650HIGHCVSS 7.8EG 7.82025-03-13
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary c…
- CVE-2025-1649HIGHCVSS 7.8EG 7.82025-03-13
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary c…
- CVE-2025-1427HIGHCVSS 7.8EG 7.82025-03-13
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary c…
- CVE-2024-13164HIGHCVSS 7.8EG 7.82025-01-14
An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →