CWE-909— Missing Initialization of Resource
The product does not initialize a critical resource.— MITRE CWE catalog
109 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-909page 1 of 3
- CVE-2022-22704CRITICALCVSS 9.8EG 9.82022-01-06
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.
- CVE-2024-8178HIGHCVSS 8.8EG 8.82024-09-05
The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code ex…
- CVE-2021-29980HIGHCVSS 8.8EG 8.82021-08-17
Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Fire…
- CVE-2021-23994HIGHCVSS 8.8EG 8.82021-06-24
A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
- CVE-2019-25016HIGHCVSS 8.8EG 8.82021-01-28
In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user to execute specific…
- CVE-2020-0321HIGHCVSS 8.8EG 8.82020-09-17
In the mp3 extractor, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidV…
- CVE-2020-11741HIGHCVSS 8.8EG 8.82020-04-14
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information about other guests, cause a denial of service, or possibly gain privileges. For guests for which "ac…
- CVE-2024-9780HIGHCVSS 7.8EG 7.82024-10-10
ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
- CVE-2024-43873HIGHCVSS 7.8EG 7.82024-08-21
In the Linux kernel, the following vulnerability has been resolved: vhost/vsock: always initialize seqpacket_allow There are two issues around seqpacket_allow: 1. seqpacket_allow is not initialized when socket is created. Thus if feat…
- CVE-2022-29925HIGHCVSS 7.8EG 7.82022-06-14
Access of uninitialized pointer vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a us…
- CVE-2022-29968HIGHCVSS 7.8EG 7.82022-05-02
An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.
- CVE-2020-0438HIGHCVSS 7.8EG 7.82020-11-10
In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data. This could lead to local escalation of privilege if a process were using libbinder_ndk in a vulnerable way with no ad…
- CVE-2020-16932HIGHCVSS 7.8EG 7.82020-10-16
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of t…
- CVE-2021-23386HIGHCVSS 7.7EG 7.72021-05-20
This affects the package dns-packet before 5.2.2. It creates buffers with allocUnsafe and does not always fill them before forming network packets. This can expose internal application memory over unencrypted network when querying crafted …
- CVE-2025-8117HIGHCVSS 7.5EG 7.52025-09-30
PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects all 3 templates: www, bip and www+bip. This product is End…
- CVE-2021-0947HIGHCVSS 7.5EG 7.52022-08-24
The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM, and then copies the buffer to userspace. The method TLServerDiscoverStreamsKM may fail for severa…
- CVE-2021-0946HIGHCVSS 7.5EG 7.52022-08-24
The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolicAddr, and then copies the buffer to userspace. The method PMR_PDumpSymbolicAddr may fail, and if it…
- CVE-2021-39966HIGHCVSS 7.5EG 7.52022-01-03
There is an Uninitialized AOD driver structure in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2019-25054HIGHCVSS 7.5EG 7.52021-12-27
An issue was discovered in the pnet crate before 0.27.2 for Rust. There is a segmentation fault (upon attempted dereference of an uninitialized descriptor) because of an erroneous IcmpTransportChannelIterator compiler optimization.
- CVE-2021-36513HIGHCVSS 7.5EG 7.52021-10-18
An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view sensitive information due to an uninitialized value.
- CVE-2021-36386HIGHCVSS 7.5EG 7.52021-07-30
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error mes…
- CVE-2021-31919HIGHCVSS 7.5EG 7.52021-04-30
An issue was discovered in the rkyv crate before 0.6.0 for Rust. When an archive is created via serialization, the archive content may contain uninitialized values of certain parts of a struct.
- CVE-2021-1405HIGHCVSS 7.5EG 7.52021-04-08
A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulner…
- CVE-2018-21247HIGHCVSS 7.5EG 7.52020-06-17
An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.
- CVE-2020-13899HIGHCVSS 7.5EG 7.52020-06-10
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in janus.c discloses information from uninitialized stack memory.
- CVE-2019-19553HIGHCVSS 7.5EG 7.52019-12-05
In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInfo dissection.
- CVE-2019-12410HIGHCVSS 7.5EG 7.52019-11-08
While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Py…
- CVE-2019-12408HIGHCVSS 7.5EG 7.52019-11-08
It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had a uninitialized memory bug when building arrays with null values in some cases. This can lead to un…
- CVE-2019-16714HIGHCVSS 7.5EG 7.52019-09-23
In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized.
- CVE-2019-3804HIGHCVSS 7.5EG 7.52019-03-26
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid base64-encoded coo…
- CVE-2019-9639HIGHCVSS 7.5EG 7.52019-03-09
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.
- CVE-2018-14647HIGHCVSS 7.5EG 7.52018-09-25
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash …
- CVE-2018-1000224HIGHCVSS 7.5EG 7.52018-08-20
Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)Serialization functi…
- CVE-2018-10811HIGHCVSS 7.5EG 7.52018-06-19
strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.
- CVE-2026-43040HIGHCVSS 7.1EG 7.12026-05-01
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak When processing Router Advertisements with user options the ke…
- CVE-2022-50169HIGHCVSS 7.1EG 7.12025-06-18
In the Linux kernel, the following vulnerability has been resolved: wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi() The simple_write_to_buffer() function will succeed if even a single byte is initialized. However, we need …
- CVE-2022-49865HIGHCVSS 7.1EG 7.12025-05-01
In the Linux kernel, the following vulnerability has been resolved: ipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network When copying a `struct ifaddrlblmsg` to the network, __ifal_reserved remained uninitialized, re…
- CVE-2024-52870HIGHCVSS 7.1EG 7.12025-01-17
Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) that can result in a client user accessing arbitrary remote w…
- CVE-2023-5138MEDIUMCVSS 6.8EG 6.82024-01-03
Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.
- CVE-2020-24455MEDIUMCVSS 6.7EG 6.72021-02-26
Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.
- CVE-2024-53845MEDIUMCVSS 6.6EG 6.62024-12-12
ESPTouch is a connection protocol for internet of things devices. In the ESPTouchV2 protocol, while there is an option to use a custom AES key, there is no option to set the IV (Initialization Vector) prior to versions 5.3.2, 5.2.4, 5.1.6,…
- CVE-2024-50076MEDIUMCVSS 6.5EG 6.52024-10-29
In the Linux kernel, the following vulnerability has been resolved: vt: prevent kernel-infoleak in con_font_get() font.data may not initialize all memory spaces depending on the implementation of vc->vc_sw->con_font_get. This may cause i…
- CVE-2024-27913MEDIUMCVSS 6.5EG 6.52024-02-28
ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.
- CVE-2021-28167MEDIUMCVSS 6.5EG 6.52021-04-21
In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entries. This allows a user to call static methods or access static members without r…
- CVE-2020-0488MEDIUMCVSS 6.5EG 6.52020-12-15
In ihevc_inter_pred_chroma_copy_ssse3 of ihevc_inter_pred_filters_ssse3_intr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges …
- CVE-2020-12352MEDIUMCVSS 6.5EG 6.52020-11-23
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
- CVE-2020-0340MEDIUMCVSS 6.5EG 6.52020-09-17
In libcodec2_soft_mp3dec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Pr…
- CVE-2020-0195MEDIUMCVSS 6.5EG 6.52020-06-11
In ihevcd_iquant_itrans_recon_ctb of ihevcd_iquant_itrans_recon_ctb.c and related functions, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional executio…
- CVE-2019-9321MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Androi…
- CVE-2019-9320MEDIUMCVSS 6.5EG 6.52019-09-27
In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Androi…
Map vulnerabilities like CWE-909 to your infrastructure
EchelonGraph correlates every CVE — across CWE-909 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →