CWE-909
102 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Missing Initialization of Resource
The product does not initialize a critical resource.
CVEs (102)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In libavc, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersion...Show more |
In libstagefright, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Androi...Show more |
In AAC Codec, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVers...Show more |
3Canonical F5Linux3Linux Kernel Traffix Signaling Delivery ControllerUbuntu LinuxJun 17, 2026 Sep 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized. |
3Cockpit Project FedoraprojectRedhat3Cockpit FedoraVirtualizationJun 17, 2026 Mar 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid...Show more |
6Canonical DebianNetapp+3 more6Debian Linux LeapPhp+3 moreJun 17, 2026 Mar 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variabl...Show more |
In tcpdump 4.9.2, a stack-based buffer over-read exists in the print_prefix function of print-hncp.c via crafted packet data because of missing initialization. |
In ipSecSetEncapSocketOwner of XfrmController.cpp, there is a possible failure to initialize a security feature due to uninitialized data. This could lead to local denial of service of IPsec on sockets with no additional...Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Sep 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause...Show more |
Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)S...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraStrongswan+1 moreNov 21, 2024 Jun 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable. |
A denial of service vulnerability in the Android media framework (h264 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36279112. |
2Linux Redhat6Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+3 moreApr 29, 2026 Feb 18, 2011 N/A· v4 N/A· v3 2.1 LOW· v2 The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information...Show more |
The get_name function in net/tipc/socket.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by r...Show more |
4Debian LinuxOpensuse+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Jan 3, 2011 N/A· v4 N/A· v3 1.9 LOW· v2 net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by levera...Show more |
4Debian LinuxOpensuse+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Nov 30, 2010 N/A· v4 N/A· v3 1.9 LOW· v2 The copy_semid_to_user function in ipc/sem.c in the Linux kernel before 2.6.36 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via a...Show more |
3Linux OpensuseSuse5Linux Enterprise Desktop Linux Enterprise Real Time ExtensionLinux Enterprise Server+2 moreApr 29, 2026 Nov 30, 2010 N/A· v4 N/A· v3 1.9 LOW· v2 The viafb_ioctl_get_viafb_info function in drivers/video/via/ioctl.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive...Show more |
4Debian LinuxOpensuse+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Nov 30, 2010 N/A· v4 N/A· v3 1.9 LOW· v2 The snd_hdspm_hwdep_ioctl function in sound/pci/rme9652/hdspm.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from ker...Show more |
4Debian LinuxOpensuse+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Nov 29, 2010 N/A· v4 N/A· v3 1.9 LOW· v2 The sisfb_ioctl function in drivers/video/sis/sis_main.c in the Linux kernel before 2.6.36-rc6 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information...Show more |
5Canonical DebianLinux+2 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Sep 30, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from...Show more |