CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
930 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 7 of 19
- CVE-2024-49900HIGHCVSS 7.1EG 7.12024-10-21
In the Linux kernel, the following vulnerability has been resolved: jfs: Fix uninit-value access of new_ea in ea_buffer syzbot reports that lzo1x_1_do_compress is using uninit-value: =====================================================…
- CVE-2024-43502HIGHCVSS 7.1EG 7.12024-10-08
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2024-46865HIGHCVSS 7.1EG 7.12024-09-27
In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a condition where if fou is NULL, goto out will be executed and grc would be used uninitial…
- CVE-2024-44999HIGHCVSS 7.1EG 7.12024-09-04
In the Linux kernel, the following vulnerability has been resolved: gtp: pull network headers in gtp_dev_xmit() syzbot/KMSAN reported use of uninit-value in get_dev_xmit() [1] We must make sure the IPv4 or Ipv6 header is pulled in skb->…
- CVE-2024-44983HIGHCVSS 7.1EG 7.12024-09-04
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: validate vlan header Ensure there is sufficient room to access the protocol field of the VLAN header, validate it once before the flowtable lookup.…
- CVE-2024-43815HIGHCVSS 7.1EG 7.12024-08-17
In the Linux kernel, the following vulnerability has been resolved: crypto: mxs-dcp - Ensure payload is zero when using key slot We could leak stack memory through the payload field when running AES with a key from one of the hardware's …
- CVE-2024-41059HIGHCVSS 7.1EG 7.12024-07-29
In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix uninit-value in copy_name [syzbot reported] BUG: KMSAN: uninit-value in sized_strscpy+0xc4/0x160 sized_strscpy+0xc4/0x160 copy_name+0x2af/0x320 fs/hfsplus…
- CVE-2024-38381HIGHCVSS 7.1EG 7.12024-06-21
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_rx_work syzbot reported the following uninit-value access issue [1] nci_rx_work() parses received packet from ndev->rx_q. It should be…
- CVE-2024-38538HIGHCVSS 7.1EG 7.12024-06-19
In the Linux kernel, the following vulnerability has been resolved: net: bridge: xmit: make sure we have at least eth header len bytes syzbot triggered an uninit value[1] error in bridge device's xmit path by sending a short (less than E…
- CVE-2023-52842HIGHCVSS 7.1EG 7.12024-05-21
In the Linux kernel, the following vulnerability has been resolved: virtio/vsock: Fix uninit-value in virtio_transport_recv_pkt() KMSAN reported the following uninit-value access issue: ==================================================…
- CVE-2024-35849HIGHCVSS 7.1EG 7.12024-05-17
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix information leak in btrfs_ioctl_logical_to_ino() Syzbot reported the following information leak for in btrfs_ioctl_logical_to_ino(): BUG: KMSAN: kernel-inf…
- CVE-2021-47101HIGHCVSS 7.1EG 7.12024-03-04
In the Linux kernel, the following vulnerability has been resolved: asix: fix uninit-value in asix_mdio_read() asix_read_cmd() may read less than sizeof(smsr) bytes and in this case smsr will be uninitialized. Fail log: BUG: KMSAN: unin…
- CVE-2020-15193HIGHCVSS 7.1EG 7.12020-09-25
In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_dlpack` can be made to use uninitialized memory resulting in further memory corruption. This is because the pybind11 glue code assumes that the argument is a t…
- CVE-2019-13220HIGHCVSS 7.1EG 7.12019-08-15
Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file.
- CVE-2026-64413HIGHCVSS 7.0EG 7.02026-07-25
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko reports: looking at ebtables table translation, could a sparse cpu_possible_mask lead to an uninitialized pointer f…
- CVE-2025-59194HIGHCVSS 7.0EG 7.02025-10-14
Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2024-42228HIGHCVSS 7.0EG 7.02024-07-30
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc Initialize the size before calling amdgpu_vce_cs_reloc, such as case 0x03000001. V2: To real…
- CVE-2025-48513MEDIUMCVSS 6.9EG 6.92026-05-15
Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory resulting in loss of confidentiality or availability.
- CVE-2026-15710MEDIUMCVSS 6.8EG 6.82026-09-11
An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the k…
- CVE-2019-20785MEDIUMCVSS 6.8EG 6.82020-04-17
An issue was discovered on LG mobile devices with Android OS 8.0 and 8.1 software for the DTAG carrier. RILD in the radio layer uses an uninitialized variable. The LG ID is LVE-SMP-180013 (January 2019).
- CVE-2020-1934MEDIUMCVSS 5.3EG 6.82020-04-01
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
- CVE-2025-21357MEDIUMCVSS 6.7EG 6.72025-01-14
Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2022-32616MEDIUMCVSS 6.7EG 6.72022-11-08
In isp, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341258; I…
- CVE-2022-32615MEDIUMCVSS 6.7EG 6.72022-11-08
In ccd, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326559; I…
- CVE-2021-0634MEDIUMCVSS 6.7EG 6.72021-10-25
In display driver, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05…
- CVE-2020-0326MEDIUMCVSS 6.7EG 6.72020-09-18
In NFC, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: …
- CVE-2026-106386MEDIUMCVSS 6.5EG 6.52026-10-06
Uninitialized resource in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-106261MEDIUMCVSS 6.5EG 6.52026-10-06
Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-91946MEDIUMCVSS 6.5EG 6.52026-09-15
FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialize…
- CVE-2026-80091MEDIUMCVSS 6.5EG 6.52026-09-08
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.
- CVE-2026-68776MEDIUMCVSS 6.5EG 6.52026-09-08
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-67648MEDIUMCVSS 6.5EG 6.52026-09-08
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-67386MEDIUMCVSS 6.5EG 6.52026-09-08
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-85089MEDIUMCVSS 6.5EG 6.52026-09-03
FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, an…
- CVE-2026-78914MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-78977MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-79221MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79229MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79285MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79270MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79120MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-78969MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in Video in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-66038MEDIUMCVSS 6.5EG 6.52026-07-24
FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer…
- CVE-2026-58546MEDIUMCVSS 6.5EG 6.52026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-57982MEDIUMCVSS 6.5EG 6.52026-07-14
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
- CVE-2026-50376MEDIUMCVSS 6.5EG 6.52026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-55003MEDIUMCVSS 6.5EG 6.52026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-58051MEDIUMCVSS 6.5EG 6.52026-06-28
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an unini…
- CVE-2026-48101MEDIUMCVSS 6.5EG 6.52026-06-05
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCapsule function allocates a heap buffer o…
- CVE-2026-11089MEDIUMCVSS 6.5EG 6.52026-06-04
Uninitialized Use in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium securi…
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →