CWE-908
881 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
CVEs (881)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 8Windows 10 1607 Windows 10 1809Windows 10 21h2+5 moreSep 8, 2026 Sep 8, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. |
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network. |
Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network. |
Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally. |
Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally. |
Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally. |
Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally. |
Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally. |
Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network. |
Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network. |
Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network. |
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. |
Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally. |
Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally. |
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. |
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. |
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. |