CWE-909
102 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Missing Initialization of Resource
The product does not initialize a critical resource.
CVEs (102)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Jun 14, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized. |
In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User i...Show more |
6Debian FedoraprojectHaxx+3 more12Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+9 moreJun 17, 2026 Jun 11, 2021 N/A· v4 3.1 LOW· v3 2.6 LOW· v2 curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in th...Show more |
HVM soft-reset crashes toolstack libxl requires all data structures passed across its public interface to be initialized before use and disposed of afterwards by calling a specific set of functions. Many internal data st...Show more |
1Dns Packet Project 1Dns Packet Jun 17, 2026 May 20, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 This affects the package dns-packet before 5.2.2. It creates buffers with allocUnsafe and does not always fill them before forming network packets. This can expose internal application memory over unencrypted network whe...Show more |
An issue was discovered in the rkyv crate before 0.6.0 for Rust. When an archive is created via serialization, the archive content may contain uninitialized values of certain parts of a struct. |
In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entries. This allows a user to call static methods or access stati...Show more |
2Clamav Debian2Clamav Debian LinuxJun 17, 2026 Apr 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Mar 30, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID...Show more |
In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 11.4-RELEASE before p7 msdosfs(5) was failing to zero-fill a pair of padding fields in the dirent str...Show more |
2Fedoraproject Tpm2 Software Stack Project2Fedora Tpm2 Software StackJun 17, 2026 Feb 26, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3. |
In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authenticating rule allowed the user to execute any command. Rules that only allowed to authenticated user...Show more |
1Phoenixcontact 9Fl Mguard Rs4004 Tx/dtx Firmware Fl Mguard Rs4004 Tx/dtx Vpn FirmwareInnominate Mguard Rs4000 4tx/3g/tx Vpn Firmware+6 moreJun 17, 2026 Dec 17, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switc...Show more |
In ihevc_inter_pred_chroma_copy_ssse3 of ihevc_inter_pred_filters_ssse3_intr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional ex...Show more |
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access. |
3Debian FedoraprojectLibvips3Debian Linux FedoraLibvipsJun 17, 2026 Nov 20, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address. |
In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data. This could lead to local escalation of privilege if a process were using libbinder_ndk in a vulner...Show more |
1Microsoft 5365 Apps ExcelOffice+2 moreJun 17, 2026 Oct 16, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code...Show more |
1Huawei 1Moana Al00b Firmware Jun 17, 2026 Jul 17, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Huawei Smart Phones Moana-AL00B with versions earlier than 10.1.0.166 have a missing initialization of resource vulnerability. An attacker tricks the user into installing then running a crafted application. Due to improp...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreJun 17, 2026 Jul 14, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, C...Show more |