CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
930 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 6 of 19
- CVE-2021-26953HIGHCVSS 7.5EG 7.52021-02-09
An issue was discovered in the postscript crate before 0.14.0 for Rust. It might allow attackers to obtain sensitive information from uninitialized memory locations via a user-provided Read implementation.
- CVE-2021-26952HIGHCVSS 7.5EG 7.52021-02-09
An issue was discovered in the ms3d crate before 0.1.3 for Rust. It might allow attackers to obtain sensitive information from uninitialized memory locations via IoReader::read.
- CVE-2020-35893HIGHCVSS 7.5EG 7.52020-12-31
An issue was discovered in the simple-slab crate before 0.3.3 for Rust. remove() has an off-by-one error, causing memory leakage and a drop of uninitialized memory.
- CVE-2020-26148HIGHCVSS 7.5EG 7.52020-09-30
md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial of service (e.g., assertion failure) via a malformed Markdown document.
- CVE-2020-0300HIGHCVSS 7.5EG 7.52020-09-18
In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers…
- CVE-2020-13899HIGHCVSS 7.5EG 7.52020-06-10
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in janus.c discloses information from uninitialized stack memory.
- CVE-2020-1206HIGHCVSS 7.5EG 7.52020-06-09
An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Information Disclosure Vulnerability'.
- CVE-2020-2575HIGHCVSS 7.5EG 7.52020-04-29
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Difficult to exploit vulnerability allows high priv…
- CVE-2020-6821HIGHCVSS 7.5EG 7.52020-04-24
When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentia…
- CVE-2020-11828HIGHCVSS 7.5EG 7.52020-04-21
In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the screenShot function to RGB value assignme…
- CVE-2019-18602HIGHCVSS 7.5EG 7.52019-10-29
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer.
- CVE-2019-18197HIGHCVSS 7.5EG 7.52019-10-18
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buff…
- CVE-2019-16866HIGHCVSS 7.5EG 7.52019-10-03
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
- CVE-2019-9329HIGHCVSS 7.5EG 7.52019-09-27
In Bluetooth, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure, with no additional privileges required. User interaction is not needed for exploitation. Product: AndroidVers…
- CVE-2019-16144HIGHCVSS 7.5EG 7.52019-09-09
An issue was discovered in the generator crate before 0.6.18 for Rust. Uninitialized memory is used by Scope, done, and yield_ during API calls.
- CVE-2019-15553HIGHCVSS 7.5EG 7.52019-08-26
An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninitialized memory.
- CVE-2019-11694HIGHCVSS 7.5EG 7.52019-07-23
A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an otherwise unavailable file. This results in the potential leaking of information…
- CVE-2019-9639HIGHCVSS 7.5EG 7.52019-03-09
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.
- CVE-2019-9578HIGHCVSS 7.5EG 7.52019-03-05
In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.
- CVE-2018-7166HIGHCVSS 7.5EG 7.52018-08-21
In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory. This method is intended to be safe and only return initialized, or cleared, memory. The third argument sp…
- CVE-2018-1000224HIGHCVSS 7.5EG 7.52018-08-20
Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)Serialization functi…
- CVE-2018-5160HIGHCVSS 7.5EG 7.52018-06-11
WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnera…
- CVE-2017-9098HIGHCVSS 7.5EG 7.52017-05-19
ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick co…
- CVE-2009-0949HIGHCVSS 7.5EG 7.52009-06-09
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a s…
- CVE-2008-3688HIGHCVSS 7.5EG 7.52008-08-14
sockethandler.cpp in HTTP Antivirus Proxy (HAVP) 0.88 allows remote attackers to cause a denial of service (hang) by connecting to a non-responsive server, which triggers an infinite loop due to an uninitialized variable.
- CVE-2008-0063HIGHCVSS 7.5EG 7.52008-03-19
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack…
- CVE-2024-7526HIGHCVSS 6.5EG 7.52024-08-06
ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunder…
- CVE-2022-26370HIGHCVSS 5.9EG 7.52022-05-05
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is con…
- CVE-2021-43848HIGHCVSS 7.4EG 7.42022-02-01
h2o is an open source http server. In code prior to the `8c0eca3` commit h2o may attempt to access uninitialized memory. When receiving QUIC frames in certain order, HTTP/3 server-side implementation of h2o can be misguided to treat uninit…
- CVE-2026-54634HIGHCVSS 7.3EG 7.32026-09-17
Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld send_raw command on TCP port 4532 reaches rigctl_send_raw() in tests/rigctl_parse.c, which writes a NUL byte at buf[buf…
- CVE-2024-11364HIGHCVSS 7.3EG 7.32024-12-19
Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If …
- CVE-2024-36503HIGHCVSS 7.3EG 7.32024-06-14
Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2021-29934HIGHCVSS 7.3EG 7.32021-04-01
An issue was discovered in PartialReader in the uu_od crate before 0.0.4 for Rust. Attackers can read the contents of uninitialized memory locations via a user-provided Read operation.
- CVE-2023-42797HIGHCVSS 7.2EG 7.22024-01-09
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.20), CP-8050 MASTER MODULE (All versions < CPCI85 V05.20). The network configuration service of affected devices contains a flaw in the conversion of i…
- CVE-2026-69358HIGHCVSS 7.1EG 7.12026-09-08
Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.
- CVE-2026-49165HIGHCVSS 7.1EG 7.12026-07-14
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
- CVE-2026-47272HIGHCVSS 7.1EG 7.12026-05-27
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare() function in src/pad.c only verified that the user-side pad (~/.pamusb/device.pad) could be read, but did not enforce …
- CVE-2026-31626HIGHCVSS 7.1EG 7.12026-04-24
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify() Initialize le_tmp64 to zero in rtw_BIP_verify() to prevent using uninitialized data. Smatch warns that only …
- CVE-2025-41239HIGHCVSS 7.1EG 7.12025-07-15
VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may b…
- CVE-2024-57912HIGHCVSS 7.1EG 7.12025-01-19
In the Linux kernel, the following vulnerability has been resolved: iio: pressure: zpa2326: fix information leak in triggered buffer The 'sample' local struct is used to push data to user space from a triggered buffer, but it has a hole …
- CVE-2024-57911HIGHCVSS 7.1EG 7.12025-01-19
In the Linux kernel, the following vulnerability has been resolved: iio: dummy: iio_simply_dummy_buffer: fix information leak in triggered buffer The 'data' array is allocated via kmalloc() and it is used to push data to user space from …
- CVE-2024-57910HIGHCVSS 7.1EG 7.12025-01-19
In the Linux kernel, the following vulnerability has been resolved: iio: light: vcnl4035: fix information leak in triggered buffer The 'buffer' local array is used to push data to userspace from a triggered buffer, but it does not set an…
- CVE-2024-57909HIGHCVSS 7.1EG 7.12025-01-19
In the Linux kernel, the following vulnerability has been resolved: iio: light: bh1745: fix information leak in triggered buffer The 'scan' local struct is used to push data to user space from a triggered buffer, but it does not set valu…
- CVE-2024-57908HIGHCVSS 7.1EG 7.12025-01-19
In the Linux kernel, the following vulnerability has been resolved: iio: imu: kmx61: fix information leak in triggered buffer The 'buffer' local array is used to push data to user space from a triggered buffer, but it does not set values…
- CVE-2024-57907HIGHCVSS 7.1EG 7.12025-01-19
In the Linux kernel, the following vulnerability has been resolved: iio: adc: rockchip_saradc: fix information leak in triggered buffer The 'data' local struct is used to push data to user space from a triggered buffer, but it does not s…
- CVE-2024-57906HIGHCVSS 7.1EG 7.12025-01-19
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads8688: fix information leak in triggered buffer The 'buffer' local array is used to push data to user space from a triggered buffer, but it does not set v…
- CVE-2024-57905HIGHCVSS 7.1EG 7.12025-01-19
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1119: fix information leak in triggered buffer The 'scan' local struct is used to push data to user space from a triggered buffer, but it has a hole betw…
- CVE-2024-53155HIGHCVSS 7.1EG 7.12024-12-24
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix uninitialized value in ocfs2_file_read_iter() Syzbot has reported the following KMSAN splat: BUG: KMSAN: uninit-value in ocfs2_file_read_iter+0x9a4/0xf80 oc…
- CVE-2024-50035HIGHCVSS 7.1EG 7.12024-10-21
In the Linux kernel, the following vulnerability has been resolved: ppp: fix ppp_async_encode() illegal access syzbot reported an issue in ppp_async_encode() [1] In this case, pppoe_sendmsg() is called with a zero size. Then ppp_async_e…
- CVE-2024-50033HIGHCVSS 7.1EG 7.12024-10-21
In the Linux kernel, the following vulnerability has been resolved: slip: make slhc_remember() more robust against malicious packets syzbot found that slhc_remember() was missing checks against malicious packets [1]. slhc_remember() onl…
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →