CWE-908
881 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
CVEs (881)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python binding...Show more |
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, re...Show more |
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_fr...Show more |
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use of an uninitialized stack pointer. |
To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. For a timer using CLOCK_TAI this can fail when no TAI offset has been configured, but the...Show more |
The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero the stack struct. An unprivileged user may observe a small amount of uninitialized kernel stac...Show more |
The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct. An unprivileged user may observe 104 bytes of uninitialized kernel...Show more |
When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index for every mbuf in the chain, including mbufs that were skipped because they contained only TLS heade...Show more |
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash wh...Show more |
Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium secur...Show more |
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized memory during ASN.1 length processing. |
rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as...Show more |
1Paloaltonetworks 3Cloud Ngfw Pan OsPrisma AccessAug 28, 2026 Aug 13, 2026 1.7 LOW· v4 7.5 HIGH· v3 N/A· v2 An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted b...Show more |
1Microsoft 6365 Apps Microsoft 365Office 2016+3 moreAug 14, 2026 Aug 11, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally. |
1Microsoft 6365 Apps ExcelMicrosoft 365+3 moreAug 13, 2026 Aug 11, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreAug 16, 2026 Aug 11, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreAug 16, 2026 Aug 11, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreAug 16, 2026 Aug 11, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreAug 16, 2026 Aug 11, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. |
SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading to a low on confidential...Show more |