CWE-908
803 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
CVEs (803)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 20Apq8009 Firmware Apq8053 FirmwareMdm9607 Firmware+17 moreJun 17, 2026 Mar 5, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Access to the uninitialized variable when the driver tries to unmap the dma buffer of a request which was never mapped in the first place leading to kernel failure in Snapdragon Auto, Snapdragon Compute, Snapdragon Consu...Show more |
When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability affects Thunderbird < 68.5. |
2Canonical Mozilla2Thunderbird Ubuntu LinuxJun 17, 2026 Mar 2, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 68.5. |
3Fedoraproject Openfortivpn ProjectOpensuse4Backports Sle FedoraLeap+1 moreJun 17, 2026 Feb 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid ce...Show more |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreJun 17, 2026 Feb 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. |
1Qualcomm 6Qcs605 Firmware Sdm439 FirmwareSdm630 Firmware+3 moreJun 17, 2026 Feb 7, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Out of bound access due to access of uninitialized memory segment in an array of pointers while normal camera open close in Snapdragon Consumer IOT, Snapdragon Mobile in QCS605, SDM439, SDM630, SDM636, SDM660, SDX24 |
In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User i...Show more |
In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to remote information disclosure in the NFC server with no addition...Show more |
4Canonical DebianLinux+1 more13Active Iq Unified Manager Aff Baseboard Management ControllerCloud Backup+10 moreJun 17, 2026 Dec 24, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c. |
1Microsoft 3Office Office 365 ProplusPowerpointJun 17, 2026 Dec 10, 2019 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'. |
5Canonical DebianFedoraproject+2 more8Chrome Debian LinuxEnterprise Linux Desktop+5 moreJun 17, 2026 Dec 10, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more7Chrome Debian LinuxEnterprise Linux Desktop+4 moreJun 17, 2026 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
4Debian LinuxOpensuse+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Dec 3, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_fd.c driver, aka CID-30a8beeb3042. |
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can cause a copy of the Hos...Show more |
1Qualcomm 36Mdm9206 Firmware Mdm9607 FirmwareMsm8909w Firmware+33 moreJun 17, 2026 Nov 6, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapd...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Nov 6, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could cause a memory disclosure problem. |
2Debian Openafs2Debian Linux OpenafsJun 17, 2026 Oct 29, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer. |
2Debian Openafs2Debian Linux OpenafsJun 17, 2026 Oct 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer. |
3Canonical DebianXmlsoft3Debian Linux LibxsltUbuntu LinuxJun 17, 2026 Oct 18, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and me...Show more |
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. Instead, the uninitialized variable errstr...Show more |