CWE-909— Missing Initialization of Resource
The product does not initialize a critical resource.— MITRE CWE catalog
109 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-909page 2 of 3
- CVE-2020-16932HIGHCVSS 7.8EG 7.82020-10-16
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of t…
- CVE-2020-20739MEDIUMCVSS 5.3EG 5.32020-11-20
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
- CVE-2020-24455MEDIUMCVSS 6.7EG 6.72021-02-26
Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.
- CVE-2020-25579MEDIUMCVSS 5.3EG 5.32021-03-26
In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 11.4-RELEASE before p7 msdosfs(5) was failing to zero-fill a pair of padding fields in the dirent structure, resulting i…
- CVE-2020-6792MEDIUMCVSS 4.3EG 4.32020-03-02
When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 68.5.
- CVE-2020-9227MEDIUMCVSS 5.5EG 5.52020-07-17
Huawei Smart Phones Moana-AL00B with versions earlier than 10.1.0.166 have a missing initialization of resource vulnerability. An attacker tricks the user into installing then running a crafted application. Due to improper initialization o…
- CVE-2021-0423MEDIUMCVSS 5.5EG 5.52021-09-27
In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat…
- CVE-2021-0484MEDIUMCVSS 5.5EG 5.52021-06-11
In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not n…
- CVE-2021-0946HIGHCVSS 7.5EG 7.52022-08-24
The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolicAddr, and then copies the buffer to userspace. The method PMR_PDumpSymbolicAddr may fail, and if it…
- CVE-2021-0947HIGHCVSS 7.5EG 7.52022-08-24
The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM, and then copies the buffer to userspace. The method TLServerDiscoverStreamsKM may fail for severa…
- CVE-2021-0961MEDIUMCVSS 4.4EG 4.42021-12-15
In quota_proc_write of xt_quota2.c, there is a possible way to read kernel memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploi…
- CVE-2021-0966MEDIUMCVSS 5.5EG 5.52021-12-15
In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted parcelable to reveal uninitialized memory of a target process due to uninitialized data. This could lead to local information disclosure acro…
- CVE-2021-1405HIGHCVSS 7.5EG 7.52021-04-08
A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulner…
- CVE-2021-22482MEDIUMCVSS 5.3EG 5.32021-10-28
There is an Uninitialized variable vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause transmission of invalid data.
- CVE-2021-22898LOWCVSS 3.1EG 3.12021-06-11
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for…
- CVE-2021-23386HIGHCVSS 7.7EG 7.72021-05-20
This affects the package dns-packet before 5.2.2. It creates buffers with allocUnsafe and does not always fill them before forming network packets. This can expose internal application memory over unencrypted network when querying crafted …
- CVE-2021-23994HIGHCVSS 8.8EG 8.82021-06-24
A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
- CVE-2021-26333MEDIUMEG 5.52021-09-21
An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionary access control list (DACL) may allow low privileged users to open a handle and send requests to the driver resulting …
- CVE-2021-28167MEDIUMCVSS 6.5EG 6.52021-04-21
In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entries. This allows a user to call static methods or access static members without r…
- CVE-2021-28687MEDIUMCVSS 5.5EG 5.52021-06-11
HVM soft-reset crashes toolstack libxl requires all data structures passed across its public interface to be initialized before use and disposed of afterwards by calling a specific set of functions. Many internal data structures also requi…
- CVE-2021-29647MEDIUMCVSS 5.5EG 5.52021-03-30
An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624.
- CVE-2021-29980HIGHCVSS 8.8EG 8.82021-08-17
Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Fire…
- CVE-2021-31919HIGHCVSS 7.5EG 7.52021-04-30
An issue was discovered in the rkyv crate before 0.6.0 for Rust. When an archive is created via serialization, the archive content may contain uninitialized values of certain parts of a struct.
- CVE-2021-34693MEDIUMCVSS 5.5EG 5.52021-06-14
net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.
- CVE-2021-36386HIGHCVSS 7.5EG 7.52021-07-30
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error mes…
- CVE-2021-36513HIGHCVSS 7.5EG 7.52021-10-18
An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view sensitive information due to an uninitialized value.
- CVE-2021-3655LOWCVSS 3.3EG 3.32021-08-05
A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory.
- CVE-2021-39636MEDIUMCVSS 4.4EG 4.42021-12-15
In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is…
- CVE-2021-39966HIGHCVSS 7.5EG 7.52022-01-03
There is an Uninitialized AOD driver structure in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-40403MEDIUMCVSS 6.3EG 6.32022-02-04
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initializ…
- CVE-2022-0175MEDIUMCVSS 5.5EG 5.52022-08-26
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read…
- CVE-2022-0382MEDIUMCVSS 5.5EG 5.52022-02-11
An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way a user sends a TIPC datagram to one or more destinations. This flaw allows a local user to read some kernel memory. Th…
- CVE-2022-1016MEDIUMCVSS 5.5EG 5.52022-08-29
A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem cause…
- CVE-2022-20357MEDIUMCVSS 5.5EG 5.52022-08-10
In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo…
- CVE-2022-22704CRITICALCVSS 9.8EG 9.82022-01-06
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.
- CVE-2022-24448LOWCVSS 3.3EG 3.32022-02-04
An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR shou…
- CVE-2022-29925HIGHCVSS 7.8EG 7.82022-06-14
Access of uninitialized pointer vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a us…
- CVE-2022-29968HIGHCVSS 7.8EG 7.82022-05-02
An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.
- CVE-2022-49217MEDIUMCVSS 5.5EG 5.52025-02-26
In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix abort all task initialization In pm80xx_send_abort_all(), the n_elem field of the ccb used is not initialized to 0. This missing initialization sometim…
- CVE-2022-49865HIGHCVSS 7.1EG 7.12025-05-01
In the Linux kernel, the following vulnerability has been resolved: ipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network When copying a `struct ifaddrlblmsg` to the network, __ifal_reserved remained uninitialized, re…
- CVE-2022-50169HIGHCVSS 7.1EG 7.12025-06-18
In the Linux kernel, the following vulnerability has been resolved: wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi() The simple_write_to_buffer() function will succeed if even a single byte is initialized. However, we need …
- CVE-2023-5138MEDIUMCVSS 6.8EG 6.82024-01-03
Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.
- CVE-2024-26635MEDIUMCVSS 5.5EG 5.52024-03-18
In the Linux kernel, the following vulnerability has been resolved: llc: Drop support for ETH_P_TR_802_2. syzbot reported an uninit-value bug below. [0] llc supports ETH_P_802_2 (0x0004) and used to support ETH_P_TR_802_2 (0x0011), and …
- CVE-2024-27913MEDIUMCVSS 6.5EG 6.52024-02-28
ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.
- CVE-2024-32945LOWCVSS 2.6EG 2.62024-07-15
Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
- CVE-2024-43873HIGHCVSS 7.8EG 7.82024-08-21
In the Linux kernel, the following vulnerability has been resolved: vhost/vsock: always initialize seqpacket_allow There are two issues around seqpacket_allow: 1. seqpacket_allow is not initialized when socket is created. Thus if feat…
- CVE-2024-50076MEDIUMCVSS 6.5EG 6.52024-10-29
In the Linux kernel, the following vulnerability has been resolved: vt: prevent kernel-infoleak in con_font_get() font.data may not initialize all memory spaces depending on the implementation of vc->vc_sw->con_font_get. This may cause i…
- CVE-2024-52870HIGHCVSS 7.1EG 7.12025-01-17
Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) that can result in a client user accessing arbitrary remote w…
- CVE-2024-53845MEDIUMCVSS 6.6EG 6.62024-12-12
ESPTouch is a connection protocol for internet of things devices. In the ESPTouchV2 protocol, while there is an option to use a custom AES key, there is no option to set the IV (Initialization Vector) prior to versions 5.3.2, 5.2.4, 5.1.6,…
- CVE-2024-56676MEDIUMCVSS 5.5EG 5.52024-12-28
In the Linux kernel, the following vulnerability has been resolved: thermal: testing: Initialize some variables annoteded with _free() Variables annotated with __free() need to be initialized if the function can return before they get up…
Map vulnerabilities like CWE-909 to your infrastructure
EchelonGraph correlates every CVE — across CWE-909 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →