← Back
CWE-908

881 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.

JSON object

Loading...

CVEs (881)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
DebianF5+1 more
5Big Ip Application Acceleration Manager
Big Ip WebacceleratorDebian Linux+2 more
Jun 17, 2026
Jul 1, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLeap+3 more
Jun 17, 2026
Jul 1, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains...Show more
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.Show less
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Jun 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.
1Google
1Chrome
Jun 17, 2026
Jun 27, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Uninitialized data in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.
1Google
1Android
Jun 17, 2026
Jun 19, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized data leading to local information disclosure with no additional execution privileges needed. User inte...Show more
In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized data leading to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-115739809Show less
8Canonical
DebianFedoraproject+5 more
13Debian Linux
Enterprise LinuxFedora+10 more
Jun 17, 2026
Jun 19, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to...Show more
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead to disclosing contents of the stack that has been left there by previous code.Show less
1Artifex
1Mupdf
Jun 17, 2026
Jun 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code.
1Ffmpeg
1Ffmpeg
Jun 17, 2026
Jun 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.
1Qemu
1Qemu
Jun 17, 2026
Jun 3, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.
5Canonical
DebianFedoraproject+2 more
15Debian Linux
Enterprise LinuxEnterprise Linux Desktop+12 more
Jun 17, 2026
May 15, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the...Show more
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.Show less
1Haproxy
1Haproxy
Jun 17, 2026
May 9, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error.
1Mozilla
1Firefox
Jun 17, 2026
Apr 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66.
1Symantec
4Endpoint Protection
Endpoint Protection CloudEndpoint Protection Cloud Agent+1 more
Nov 21, 2024
Apr 25, 2019
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prio...Show more
Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22, SEP-12.1.7484.7002 and SEP Cloud prior to 22.16.3 may be susceptible to a kernel memory disclosure, which is a type of issue where a specially crafted IRP request can cause the driver to return uninitialized memory.Show less
6Canonical
DebianFedoraproject+3 more
9Debian Linux
Enterprise LinuxEnterprise Linux Eus+6 more
Jun 17, 2026
Apr 22, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory u...Show more
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.Show less
5Canonical
DebianNetapp+2 more
5Debian Linux
LeapPhp+2 more
Jun 17, 2026
Mar 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_TIFF.
6Canonical
DebianNetapp+3 more
6Debian Linux
LeapPhp+3 more
Jun 17, 2026
Mar 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variabl...Show more
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.Show less
1Yubico
1Libu2f Host
Jun 17, 2026
Mar 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.
1Google
1Android
Nov 21, 2024
Feb 11, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized data for socket address leads to information exposure.
1Wibu
1Wibukey
Nov 21, 2024
Feb 5, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An exploitable kernel memory disclosure vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400).A specially crafted IRP request can cause the driver to ret...Show more
An exploitable kernel memory disclosure vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400).A specially crafted IRP request can cause the driver to return uninitialized memory, resulting in kernel memory disclosure. An attacker can send an IRP request to trigger this vulnerability.Show less
1Libvips
1Libvips
Jun 17, 2026
Jan 26, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw proc...Show more
libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated memory. This can result in leaking raw process memory contents through the output image.Show less