CWE-908
760 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
CVEs (760)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 7Office Office Online ServerOffice Web Apps+4 moreNov 21, 2024 Mar 14, 2018 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Ser...Show more |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreMay 13, 2026 Oct 27, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreMay 13, 2026 Oct 27, 2017 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HT...Show more |
1Vmware 5Esxi FusionFusion Pro+2 moreMay 13, 2026 Jun 7, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG;...Show more |
3Debian GraphicsmagickImagemagick3Debian Linux GraphicsmagickImagemagickMay 13, 2026 May 19, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks aga...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Sep 2, 2016 N/A· v4 4.4 MEDIUM· v3 1.9 LOW· v2 The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read ho...Show more |
2Google Linux2Android Linux KernelMay 6, 2026 Mar 12, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consider the relationship to the mmap_min_addr value, which makes it easier...Show more |
3Fedoraproject PcrePhp3Fedora Perl Compatible Regular Expression LibraryPhpMay 6, 2026 Dec 2, 2015 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted re...Show more |
7Arista DebianFedoraproject+4 more24Debian Linux Enterprise Linux Compute Node EusEnterprise Linux Desktop+21 moreMay 6, 2026 Aug 12, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors. |
5Apple CanonicalDebian+2 more6Debian Linux Mac Os XPhp+3 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or poss...Show more |
1Microsoft 2Data Access Components Windows Data Access ComponentsApr 29, 2026 Jul 10, 2012 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers acc...Show more |
Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "Jscript9.dll Remote Code Ex...Show more |
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that was not properly initialized, aka "OLEAuto32.dll Rem...Show more |
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted,...Show more |
Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted,...Show more |
The Vector Markup Language (VML) implementation in vgx.dll in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an ob...Show more |
Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted,...Show more |
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted,...Show more |
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted,...Show more |
The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by...Show more |