CWE-908
802 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
CVEs (802)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service. |
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service. |
1Microsoft 8Windows 10 1607 Windows 10 1809Windows 10 21h2+5 moreJun 17, 2026 Sep 12, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Kernel Information Disclosure Vulnerability |
In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction...Show more |
In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not nee...Show more |
1Intel 88Nuc 11 Compute Element Cm11ebc4w Firmware Nuc 11 Compute Element Cm11ebi38w FirmwareNuc 11 Compute Element Cm11ebi58w Firmware+85 moreJun 17, 2026 Aug 11, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Use of uninitialized resource in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access. |
1Microsoft 12Windows 10 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Aug 8, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Microsoft Message Queuing Information Disclosure Vulnerability |
1Silabs 1Gecko Software Development Kit Jun 17, 2026 Jul 28, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stack via malformed GBL file.
|
A Use of an Uninitialized Resource vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial of Serv...Show more |
The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel memory to user space. The contents of this memory could contain sensitive information.
|
1Microsoft 7Windows 10 1809 Windows 10 21h2Windows 10 22h2+4 moreJun 17, 2026 Jul 11, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows CDP User Components Information Disclosure Vulnerability |
1Microsoft 11Windows 10 1507 Windows 10 1607Windows 10 1809+8 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Print Spooler Information Disclosure Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 OLE Automation Information Disclosure Vulnerability |
1Microsoft 9Windows 10 1607 Windows 10 1809Windows 10 21h2+6 moreJun 17, 2026 Jul 11, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Update Orchestrator Service Information Disclosure Vulnerability |
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not have an MSS lower bound (e.g., it could be zero). |
1Silabs 1Gecko Software Development Kit Jun 17, 2026 Jun 15, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is uninitialized. |
In readSampleData of NuMediaExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is n...Show more |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreJun 17, 2026 Jun 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Installer Information Disclosure Vulnerability |
1Microsoft 4Windows Server 2012 Windows Server 2016Windows Server 2019+1 moreJun 17, 2026 Jun 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 iSCSI Target WMI Provider Remote Code Execution Vulnerability |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Jun 2, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11. |