CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
930 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 9 of 19
- CVE-2019-2169MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
- CVE-2019-2168MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
- CVE-2019-2167MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
- CVE-2019-2166MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion…
- CVE-2019-2140MEDIUMCVSS 6.5EG 6.52019-09-27
In libxaac, there is a possible information disclosure due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersio…
- CVE-2019-11750MEDIUMCVSS 6.5EG 6.52019-09-27
A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
- CVE-2018-20992MEDIUMCVSS 6.5EG 6.52019-08-26
An issue was discovered in the claxon crate before 0.4.1 for Rust. Uninitialized memory can be exposed because certain decode buffer sizes are mishandled.
- CVE-2019-5818MEDIUMCVSS 6.5EG 6.52019-06-27
Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.
- CVE-2018-18366MEDIUMCVSS 6.5EG 6.52019-04-25
Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be…
- CVE-2018-6982MEDIUMCVSS 6.5EG 6.52018-12-04
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may lead to an information leak from host to guest.
- CVE-2026-4147MEDIUMCVSS 4.3EG 6.52026-03-17
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command.
- CVE-2026-92834MEDIUMCVSS 6.3EG 6.32026-10-02
Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift C++ WebSocket server. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issu…
- CVE-2026-85483MEDIUMCVSS 6.3EG 6.32026-10-02
Use of uninitialized resource, Return of wrong status code vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.
- CVE-2020-6444MEDIUMCVSS 6.3EG 6.32020-04-13
Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2026-84622MEDIUMCVSS 6.2EG 6.22026-09-14
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27.…
- CVE-2018-9378MEDIUMCVSS 6.2EG 6.22025-01-28
In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User inte…
- CVE-2024-38254MEDIUMCVSS 6.2EG 6.22024-09-10
Windows Authentication Information Disclosure Vulnerability
- CVE-2024-31874MEDIUMCVSS 6.2EG 6.22024-04-10
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 uses uninitialized variables when deploying that could allow a local user to cause a denial of service. IBM X-Force ID: 287318.
- CVE-2020-16985MEDIUMCVSS 6.2EG 6.22020-11-11
Azure Sphere Information Disclosure Vulnerability
- CVE-2018-9377MEDIUMCVSS 5.5EG 6.22024-11-28
In getIntentForIntentSender of ActivityManagerService.java, there is a possible way to access user metadata due to a pending intent. This could lead to local escalation of privilege with no additional execution privileges needed. User inte…
- CVE-2023-46100MEDIUMCVSS 5.5EG 6.22023-11-20
in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitialized resource.
- CVE-2024-57878MEDIUMCVSS 6.1EG 6.12025-01-11
In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: fix partial SETREGSET for NT_ARM_FPMR Currently fpmr_set() doesn't initialize the temporary 'fpmr' variable, and a SETREGSET call with a length of zero wi…
- CVE-2024-57877MEDIUMCVSS 6.1EG 6.12025-01-11
In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: fix partial SETREGSET for NT_ARM_POE Currently poe_set() doesn't initialize the temporary 'ctrl' variable, and a SETREGSET call with a length of zero will…
- CVE-2024-57874MEDIUMCVSS 6.1EG 6.12025-01-11
In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: fix partial SETREGSET for NT_ARM_TAGGED_ADDR_CTRL Currently tagged_addr_ctrl_set() doesn't initialize the temporary 'ctrl' variable, and a SETREGSET call …
- CVE-2020-35494MEDIUMCVSS 6.1EG 6.12021-01-04
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower t…
- CVE-2023-22330MEDIUMCVSS 6.0EG 6.02023-08-11
Use of uninitialized resource in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2021-31423MEDIUMCVSS 6.0EG 6.02021-04-29
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability to execute high-privileged code on the target guest system i…
- CVE-2020-14704MEDIUMCVSS 6.0EG 6.02020-07-15
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privi…
- CVE-2020-14703MEDIUMCVSS 6.0EG 6.02020-07-15
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privi…
- CVE-2026-16827MEDIUMCVSS 5.9EG 5.92026-08-19
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use of an uninitialized stack pointer.
- CVE-2022-39283MEDIUMCVSS 5.9EG 5.92022-10-12
FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command line switch might read uninitialized data, decode it as audio/video and display the result. FreeRDP based server imple…
- CVE-2022-31026MEDIUMCVSS 5.9EG 5.92022-06-09
Trilogy is a client library for MySQL. When authenticating, a malicious server could return a specially crafted authentication packet, causing the client to read and return up to 12 bytes of data from an uninitialized variable in stack mem…
- CVE-2021-41253MEDIUMCVSS 5.9EG 5.92021-11-08
Zydis is an x86/x86-64 disassembler library. Users of Zydis versions v3.2.0 and older that use the string functions provided in `zycore` in order to append untrusted user data to the formatter buffer within their custom formatter hooks can…
- CVE-2019-18603MEDIUMCVSS 5.9EG 5.92019-10-29
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer.
- CVE-2019-11323MEDIUMCVSS 5.9EG 5.92019-05-09
HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error.
- CVE-2026-63381MEDIUMCVSS 5.8EG 5.82026-08-20
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees…
- CVE-2026-69349MEDIUMCVSS 5.7EG 5.72026-09-08
Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network.
- CVE-2025-53719MEDIUMCVSS 5.7EG 5.72025-08-12
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- CVE-2025-53153MEDIUMCVSS 5.7EG 5.72025-08-12
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- CVE-2025-53148MEDIUMCVSS 5.7EG 5.72025-08-12
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- CVE-2025-53138MEDIUMCVSS 5.7EG 5.72025-08-12
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- CVE-2025-50157MEDIUMCVSS 5.7EG 5.72025-08-12
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- CVE-2025-50156MEDIUMCVSS 5.7EG 5.72025-08-12
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- CVE-2024-32606MEDIUMCVSS 5.7EG 5.72024-05-14
HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).
- CVE-2026-7141MEDIUMCVSS 5.6EG 5.62026-04-27
A vulnerability was found in vLLM up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of the component KV Block Handler. Performing a manipulation results in uninitialized resource.…
- CVE-2024-11991MEDIUMCVSS 5.6EG 5.62024-12-09
Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of write barriers in a few locations. This vulnerability could potentially allow unauthorized read or write access to a Canis…
- CVE-2026-47555MEDIUMCVSS 5.5EG 5.52026-09-30
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause uninitialized kernel memory to be copied back to userspace. A successful exploit of this vulnerability might lead to…
- CVE-2026-93018MEDIUMCVSS 5.5EG 5.52026-09-18
Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader adds …
- CVE-2026-81958MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-81391MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →