CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
930 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 5 of 19
- CVE-2026-16386HIGHCVSS 7.5EG 7.52026-07-21
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-16385HIGHCVSS 7.5EG 7.52026-07-21
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-16384HIGHCVSS 7.5EG 7.52026-07-21
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-58535HIGHCVSS 7.5EG 7.52026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-58533HIGHCVSS 7.5EG 7.52026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-50497HIGHCVSS 7.5EG 7.52026-07-14
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
- CVE-2026-11576HIGHCVSS 7.5EG 7.52026-06-19
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file …
- CVE-2026-45736HIGHCVSS 7.5EG 7.52026-05-15
ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is …
- CVE-2026-43405HIGHCVSS 7.5EG 7.52026-05-08
In the Linux kernel, the following vulnerability has been resolved: libceph: Use u32 for non-negative values in ceph_monmap_decode() This patch fixes unnecessary implicit conversions that change signedness of blob_len and num_mon in ceph…
- CVE-2026-6749HIGHCVSS 7.5EG 7.52026-04-21
Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-34543HIGHCVSS 7.5EG 7.52026-04-01
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory may be leak…
- CVE-2026-3497HIGHCVSS 7.5EG 7.52026-03-12
Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of ssh…
- CVE-2026-2794HIGHCVSS 7.5EG 7.52026-02-24
Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 148.
- CVE-2025-15281HIGHCVSS 7.5EG 7.52026-01-20
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort…
- CVE-2026-0915HIGHCVSS 7.5EG 7.52026-01-15
Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to …
- CVE-2025-59964HIGHCVSS 7.5EG 7.52025-10-09
A Use of Uninitialized Resource vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX4700 devices allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When forwarding-opt…
- CVE-2025-49718HIGHCVSS 7.5EG 7.52025-07-08
Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.
- CVE-2023-37930HIGHCVSS 7.5EG 7.52025-04-08
Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via …
- CVE-2025-21220HIGHCVSS 7.5EG 7.52025-01-14
Microsoft Message Queuing Information Disclosure Vulnerability
- CVE-2024-12085HIGHCVSS 7.5EG 7.52025-01-14
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one…
- CVE-2018-9381HIGHCVSS 7.5EG 7.52024-12-02
In gatts_process_read_by_type_req of gatt_sr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is n…
- CVE-2024-38257HIGHCVSS 7.5EG 7.52024-09-10
Microsoft AllJoyn API Information Disclosure Vulnerability
- CVE-2024-42225HIGHCVSS 7.5EG 7.52024-07-30
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data
- CVE-2024-38064HIGHCVSS 7.5EG 7.52024-07-09
Windows TCP/IP Information Disclosure Vulnerability
- CVE-2022-48747HIGHCVSS 7.5EG 7.52024-06-20
In the Linux kernel, the following vulnerability has been resolved: block: Fix wrong offset in bio_truncate() bio_truncate() clears the buffer outside of last block of bdev, however current bio_truncate() is using the wrong offset of pag…
- CVE-2024-29838HIGHCVSS 7.5EG 7.52024-04-15
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller software
- CVE-2024-21502HIGHCVSS 7.5EG 7.52024-02-24
Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the curvemath_mul function in src/curveMath.c, due to being used and interpreted as user-defined type. Depending on the variab…
- CVE-2024-26147HIGHCVSS 7.5EG 7.52024-02-21
Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plug…
- CVE-2024-23314HIGHCVSS 7.5EG 7.52024-02-14
When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not eva…
- CVE-2023-36567HIGHCVSS 7.5EG 7.52023-10-10
Windows Deployment Services Information Disclosure Vulnerability
- CVE-2023-21233HIGHCVSS 7.5EG 7.52023-08-14
In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2023-36913HIGHCVSS 7.5EG 7.52023-08-08
Microsoft Message Queuing Information Disclosure Vulnerability
- CVE-2023-35325HIGHCVSS 7.5EG 7.52023-07-11
Windows Print Spooler Information Disclosure Vulnerability
- CVE-2023-35847HIGHCVSS 7.5EG 7.52023-06-19
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not have an MSS lower bound (e.g., it could be zero).
- CVE-2023-28967HIGHCVSS 7.5EG 7.52023-04-17
A Use of Uninitialized Resource vulnerability in the Border Gateway Protocol (BGP) software of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to send specific genuine BGP packets to a device…
- CVE-2022-25737HIGHCVSS 7.5EG 7.52023-04-13
Information disclosure in modem due to missing NULL check while reading packets received from local network
- CVE-2023-27598HIGHCVSS 7.5EG 7.52023-03-15
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, sending a malformed `Via` header to OpenSIPS triggers a segmentation fault when the function `calc_tag_suffix` is called. A specially…
- CVE-2023-22281HIGHCVSS 7.5EG 7.52023-02-01
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP AFM NAT policy with a destination NAT rule is configured on a FastL4 virtual server, undisc…
- CVE-2022-47012HIGHCVSS 7.5EG 7.52023-01-20
Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.
- CVE-2022-38668HIGHCVSS 7.5EG 7.52022-08-22
HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfilling a request for a static file smaller than 16 KB.
- CVE-2020-27795HIGHCVSS 7.5EG 7.52022-08-19
A segmentation fault was discovered in radare2 with adf command. In libr/core/cmd_anal.c, when command "adf" has no or wrong argument, anal_fcn_data (core, input + 1) --> RAnalFunction *fcn = r_anal_get_fcn_in (core->anal, core->offset, -1…
- CVE-2022-34655HIGHCVSS 7.5EG 7.52022-08-04
In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing the HTTP::payload command is configured on a virtual server, undisclosed traffic can cause Traffic Management Microkernel…
- CVE-2022-25345HIGHCVSS 7.5EG 7.52022-06-17
All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.
- CVE-2022-28488HIGHCVSS 7.5EG 7.52022-05-04
The function wav_format_write in libwav.c in libwav through 2017-04-20 has an Use of Uninitialized Variable vulnerability.
- CVE-2021-45694HIGHCVSS 7.5EG 7.52021-12-27
An issue was discovered in the rdiff crate through 2021-02-03 for Rust. Window may read from uninitialized memory locations.
- CVE-2020-36511HIGHCVSS 7.5EG 7.52021-12-27
An issue was discovered in the bite crate through 2020-12-31 for Rust. read::BiteReadExpandedExt::read_framed_max may read from uninitialized memory locations.
- CVE-2018-25023HIGHCVSS 7.5EG 7.52021-12-27
An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type.
- CVE-2021-36512HIGHCVSS 7.5EG 7.52021-10-19
An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers to view sensitive information due to an uninitialized value.
- CVE-2021-28030HIGHCVSS 7.5EG 7.52021-03-05
An issue was discovered in the truetype crate before 0.30.1 for Rust. Attackers can read the contents of uninitialized memory locations via a user-provided Read operation within Tape::take_bytes.
- CVE-2021-28029HIGHCVSS 7.5EG 7.52021-03-05
An issue was discovered in the toodee crate before 0.3.0 for Rust. The row-insertion feature allows attackers to read the contents of uninitialized memory locations.
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →