CWE-909
102 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Missing Initialization of Resource
The product does not initialize a critical resource.
CVEs (102)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Silabs 1Gecko Software Development Kit Jun 17, 2026 Jan 3, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B. |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Aug 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information...Show more |
2Redhat Virglrenderer Project2Enterprise Linux VirglrendererJun 17, 2026 Aug 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the gu...Show more |
The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM, and then copies the buffer to userspace. The method TLServerDiscoverStreamsKM...Show more |
The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolicAddr, and then copies the buffer to userspace. The method PMR_PDumpSymbolicAddr...Show more |
3Fedoraproject LinuxNetapp8Fedora H300s FirmwareH410c Firmware+5 moreJun 17, 2026 May 2, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private. |
An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way a user sends a TIPC datagram to one or more destinations. This flaw allows a local user to read som...Show more |
3Debian FedoraprojectGerbv Project3Debian Linux FedoraGerbvJun 17, 2026 Feb 4, 2022 N/A· v4 6.3 MEDIUM· v3 4.3 MEDIUM· v2 An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit th...Show more |
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration. |
There is an Uninitialized AOD driver structure in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality. |
An issue was discovered in the pnet crate before 0.27.2 for Rust. There is a segmentation fault (upon attempted dereference of an uninitialized descriptor) because of an erroneous IcmpTransportChannelIterator compiler op...Show more |
In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted parcelable to reveal uninitialized memory of a target process due to uninitialized data. This could lead to local informat...Show more |
In quota_proc_write of xt_quota2.c, there is a possible way to read kernel memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is no...Show more |
There is an Uninitialized variable vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause transmission of invalid data. |
An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view sensitive information due to an uninitialized value. |
1Amd 2Chipset Driver Psp DriverJun 17, 2026 Sep 21, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionary access control list (DACL) may allow low privileged users to open a handle and send requests to th...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Aug 17, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ES...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 Aug 5, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory. |
2Fedoraproject Fetchmail2Fedora FetchmailJun 17, 2026 Jul 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Jun 24, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88. |