CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
930 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 8 of 19
- CVE-2026-32814MEDIUMCVSS 6.5EG 6.52026-05-19
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns heif_erro…
- CVE-2026-27496MEDIUMCVSS 6.5EG 6.52026-03-25
n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, an authenticated user with permission to create or modify workflows could use the JavaScript Task Runner to allocate uninitialized memory bu…
- CVE-2025-12736MEDIUMCVSS 6.5EG 6.52026-03-16
in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitialized resource.
- CVE-2025-55198MEDIUMCVSS 6.5EG 6.52025-08-14
Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml files, an improper validation of type error can lead to a panic. This issue has been resolved in Helm 3.18.5. A workaround…
- CVE-2025-29959MEDIUMCVSS 6.5EG 6.52025-05-13
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-29958MEDIUMCVSS 6.5EG 6.52025-05-13
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-29830MEDIUMCVSS 6.5EG 6.52025-05-13
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-27474MEDIUMCVSS 6.5EG 6.52025-04-08
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-21288MEDIUMCVSS 6.5EG 6.52025-01-14
Windows COM Server Information Disclosure Vulnerability
- CVE-2025-21272MEDIUMCVSS 6.5EG 6.52025-01-14
Windows COM Server Information Disclosure Vulnerability
- CVE-2018-9429MEDIUMCVSS 6.5EG 6.52024-12-02
In buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploit…
- CVE-2024-43537MEDIUMCVSS 6.5EG 6.52024-10-08
Windows Mobile Broadband Driver Denial of Service Vulnerability
- CVE-2023-36398MEDIUMCVSS 6.5EG 6.52023-11-14
Windows NTFS Information Disclosure Vulnerability
- CVE-2023-32042MEDIUMCVSS 6.5EG 6.52023-07-11
OLE Automation Information Disclosure Vulnerability
- CVE-2023-22897MEDIUMCVSS 6.5EG 6.52023-04-12
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. Essentially, uninitialized data can be retrieved vi…
- CVE-2021-39671MEDIUMCVSS 6.5EG 6.52022-02-11
In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for…
- CVE-2021-34855MEDIUMCVSS 6.5EG 6.52021-10-25
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest system …
- CVE-2021-3545MEDIUMCVSS 6.5EG 6.52021-06-02
An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c and could …
- CVE-2021-31419MEDIUMCVSS 6.5EG 6.52021-04-29
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker must first obtain the ability to execute low-privileged code on the target guest system in…
- CVE-2021-31418MEDIUMCVSS 6.5EG 6.52021-04-29
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker must first obtain the ability to execute low-privileged code on the target guest system in…
- CVE-2021-31417MEDIUMCVSS 6.5EG 6.52021-04-29
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker must first obtain the ability to execute low-privileged code on the target guest system in…
- CVE-2020-16042MEDIUMCVSS 6.5EG 6.52021-01-08
Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2020-0411MEDIUMCVSS 6.5EG 6.52020-10-14
In ~AACExtractor() of AACExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for expl…
- CVE-2020-0361MEDIUMCVSS 6.5EG 6.52020-09-17
In libDRCdec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: Andro…
- CVE-2020-0340MEDIUMCVSS 6.5EG 6.52020-09-17
In libcodec2_soft_mp3dec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Pr…
- CVE-2020-0195MEDIUMCVSS 6.5EG 6.52020-06-11
In ihevcd_iquant_itrans_recon_ctb of ihevcd_iquant_itrans_recon_ctb.c and related functions, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional executio…
- CVE-2020-1322MEDIUMCVSS 6.5EG 6.52020-06-09
An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due to an uninitialized variable, aka 'Microsoft Project Information Disclosure Vulnerability'.
- CVE-2020-0049MEDIUMCVSS 6.5EG 6.52020-03-10
In onReadBuffer() of StreamingSource.cpp, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for…
- CVE-2020-6793MEDIUMCVSS 6.5EG 6.52020-03-02
When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability affects Thunderbird < 68.5.
- CVE-2020-0006MEDIUMCVSS 6.5EG 6.52020-01-08
In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to remote information disclosure in the NFC server with no additional execution privil…
- CVE-2019-13751MEDIUMCVSS 6.5EG 6.52019-12-10
Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- CVE-2019-9416MEDIUMCVSS 6.5EG 6.52019-09-27
In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: …
- CVE-2019-9415MEDIUMCVSS 6.5EG 6.52019-09-27
In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: …
- CVE-2019-9411MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9410MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9409MEDIUMCVSS 6.5EG 6.52019-09-27
In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android…
- CVE-2019-9408MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9406MEDIUMCVSS 6.5EG 6.52019-09-27
In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android…
- CVE-2019-9391MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: …
- CVE-2019-9361MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9359MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9338MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9337MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9336MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9335MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-9334MEDIUMCVSS 6.5EG 6.52019-09-27
In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android…
- CVE-2019-9322MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidV…
- CVE-2019-2172MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
- CVE-2019-2171MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
- CVE-2019-2170MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →