CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
930 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 4 of 19
- CVE-2024-9717HIGHCVSS 7.8EG 7.82024-11-22
Trimble SketchUp Viewer SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interactio…
- CVE-2024-8842HIGHCVSS 7.8EG 7.82024-11-22
PDF-XChange Editor RTF File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is requi…
- CVE-2024-49029HIGHCVSS 7.8EG 7.82024-11-12
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2024-50143HIGHCVSS 7.8EG 7.82024-11-07
In the Linux kernel, the following vulnerability has been resolved: udf: fix uninit-value use in udf_get_fileshortad Check for overflow when computing alen in udf_current_aext to mitigate later uninit-value use in udf_get_fileshortad KMS…
- CVE-2024-8896HIGHCVSS 7.8EG 7.82024-10-29
A maliciously crafted DXF file when parsed in acdb25.dll through Autodesk AutoCAD can force to access a variable prior to initialization. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute…
- CVE-2024-47966HIGHCVSS 7.8EG 7.82024-10-10
Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to leverage this vulnerability to execute code in the context of the current proce…
- CVE-2024-37002HIGHCVSS 7.8EG 7.82024-06-25
A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, could lead to code execution in the current proces…
- CVE-2024-32906HIGHCVSS 7.8EG 7.82024-06-13
In AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-36898HIGHCVSS 7.8EG 7.82024-05-30
In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: fix uninitialised kfifo If a line is requested with debounce, and that results in debouncing in software, and the line is subsequently reconfigured to ena…
- CVE-2021-47553HIGHCVSS 7.8EG 7.82024-05-24
In the Linux kernel, the following vulnerability has been resolved: sched/scs: Reset task stack state in bringup_cpu() To hot unplug a CPU, the idle task on that CPU calls a few layers of C code before finally leaving the kernel. When KA…
- CVE-2023-42062HIGHCVSS 7.8EG 7.82024-05-03
PDF-XChange Editor U3D File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is requi…
- CVE-2024-27022HIGHCVSS 7.8EG 7.82024-05-01
In the Linux kernel, the following vulnerability has been resolved: fork: defer linking file vma until vma is fully initialized Thorvald reported a WARNING [1]. And the root cause is below race: CPU 1 CPU 2 fork hugetlbfs_fall…
- CVE-2024-3299HIGHCVSS 7.8EG 7.82024-04-04
Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attac…
- CVE-2024-1848HIGHCVSS 7.8EG 7.82024-03-22
Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnerabilities exist in the file reading procedure in SOLIDWORKS D…
- CVE-2024-1847HIGHCVSS 7.8EG 7.82024-02-28
Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings fr…
- CVE-2024-23137HIGHCVSS 7.8EG 7.82024-02-22
A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current p…
- CVE-2023-36704HIGHCVSS 7.8EG 7.82023-10-10
Windows Setup Files Cleanup Remote Code Execution Vulnerability
- CVE-2023-29367HIGHCVSS 7.8EG 7.82023-06-14
iSCSI Target WMI Provider Remote Code Execution Vulnerability
- CVE-2022-2950HIGHCVSS 7.8EG 7.82022-12-13
Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used a…
- CVE-2022-2949HIGHCVSS 7.8EG 7.82022-12-13
Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used a…
- CVE-2021-3928HIGHCVSS 7.8EG 7.82021-11-05
vim is vulnerable to Use of Uninitialized Variable
- CVE-2021-29631HIGHCVSS 7.8EG 7.82021-08-30
In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, certain VirtIO-based device models in bhyve failed to…
- CVE-2021-0530HIGHCVSS 7.8EG 7.82021-06-21
In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2021-0526HIGHCVSS 7.8EG 7.82021-06-21
In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2021-0495HIGHCVSS 7.8EG 7.82021-06-11
In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2020-36210HIGHCVSS 7.8EG 7.82021-01-26
An issue was discovered in the autorand crate before 0.2.3 for Rust. Because of impl Random on arrays, uninitialized memory can be dropped when a panic occurs, leading to memory corruption.
- CVE-2020-16932HIGHCVSS 7.8EG 7.82020-10-16
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of t…
- CVE-2020-16931HIGHCVSS 7.8EG 7.82020-10-16
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of t…
- CVE-2020-15523HIGHCVSS 7.8EG 7.82020-07-04
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dl…
- CVE-2019-14079HIGHCVSS 7.8EG 7.82020-03-05
Access to the uninitialized variable when the driver tries to unmap the dma buffer of a request which was never mapped in the first place leading to kernel failure in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon…
- CVE-2019-14044HIGHCVSS 7.8EG 7.82020-02-07
Out of bound access due to access of uninitialized memory segment in an array of pointers while normal camera open close in Snapdragon Consumer IOT, Snapdragon Mobile in QCS605, SDM439, SDM630, SDM636, SDM660, SDX24
- CVE-2019-1462HIGHCVSS 7.8EG 7.82019-12-10
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.
- CVE-2018-9557HIGHCVSS 7.8EG 7.82018-12-06
In really_install_package of install.cpp, there is a possible free of arbitrary memory due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…
- CVE-2018-15911HIGHCVSS 7.8EG 7.82018-08-28
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
- CVE-2018-10115HIGHCVSS 7.8EG 7.82018-05-02
Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted …
- CVE-2009-2692HIGHCVSS 7.8EG 7.82009-08-14
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privilege…
- CVE-2021-32846HIGHCVSS 7.7EG 7.82023-02-17
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vtsock_proc_tx` in `virtio-sock` can lead to to uninitialized memory use. In this situation, there is a check for the retu…
- CVE-2021-32845HIGHCVSS 7.7EG 7.82023-02-17
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, the implementation of `qnotify` at `pci_vtrnd_notify` fails to check the return value of `vq_getchain`. This leads…
- CVE-2022-34390HIGHCVSS 7.5EG 7.82022-10-12
Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
- CVE-2018-3975HIGHCVSS 7.5EG 7.82018-10-01
An exploitable uninitialized variable vulnerability exists in the RTF-parsing functionality of Atlantis Word Processor 3.2.6 version. A specially crafted RTF file can leverage an uninitialized stack address, resulting in an out-of-bounds w…
- CVE-2022-2308HIGHCVSS 6.5EG 7.82022-09-01
A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of the device config space is in line with the features advertised by the VDUSE userspace application. In case of a mismat…
- CVE-2024-42161HIGHCVSS 6.3EG 7.82024-07-30
In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid uninitialized value in BPF_CORE_READ_BITFIELD [Changes from V1: - Use a default branch in the switch statement to initialize `val'.] GCC warns that `val' ma…
- CVE-2024-43458HIGHCVSS 7.7EG 7.72024-09-10
Windows Networking Information Disclosure Vulnerability
- CVE-2022-23573HIGHCVSS 7.6EG 7.62022-02-04
Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitialized data to a new tensor. This later results in undefined behavior. The implementation has a check that the left hand…
- CVE-2026-94056HIGHCVSS 7.5EG 7.52026-09-19
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
- CVE-2026-72989HIGHCVSS 7.5EG 7.52026-09-08
Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.
- CVE-2026-19448HIGHCVSS 7.5EG 7.52026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial o…
- CVE-2026-0301HIGHCVSS 7.5EG 7.52026-08-13
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerabili…
- CVE-2026-66034HIGHCVSS 7.5EG 7.52026-07-24
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publick…
- CVE-2026-47247HIGHCVSS 7.5EG 7.52026-07-21
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to …
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →