VYPR

CWE-908

Use of Uninitialized Resource

BaseIncompleteLikelihood: Medium

Description

The product uses or accesses a resource that has not been initialized.

When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (829)

page 11 of 42
  • CVE-2024-29838HigApr 15, 2024
    risk 0.49cvss 7.5epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller software

  • CVE-2024-23314HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2023-36567HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Deployment Services Information Disclosure Vulnerability

  • CVE-2023-21233HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.00

    In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-35325HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Print Spooler Information Disclosure Vulnerability

  • CVE-2023-28967HigApr 17, 2023
    risk 0.49cvss 7.5epss 0.01

    A Use of Uninitialized Resource vulnerability in the Border Gateway Protocol (BGP) software of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to send specific genuine BGP packets to a device configured with BGP to cause a Denial…

  • CVE-2022-25737HigApr 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in modem due to missing NULL check while reading packets received from local network

  • CVE-2023-22281HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP AFM NAT policy with a destination NAT rule is configured on a FastL4 virtual server, undisclosed traffic can cause the Traffic…

  • CVE-2022-47012HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.

  • CVE-2022-34390HigOct 12, 2022
    risk 0.49cvss 7.5epss 0.00

    Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

  • CVE-2022-34655HigAug 4, 2022
    risk 0.49cvss 7.5epss 0.01

    In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing the HTTP::payload command is configured on a virtual server, undisclosed traffic can cause Traffic Management Microkernel (TMM) to terminate. Note: Software…

  • CVE-2022-28488HigMay 4, 2022
    risk 0.49cvss 7.5epss 0.01

    The function wav_format_write in libwav.c in libwav through 2017-04-20 has an Use of Uninitialized Variable vulnerability.

  • CVE-2021-45694HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the rdiff crate through 2021-02-03 for Rust. Window may read from uninitialized memory locations.

  • CVE-2020-36511HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the bite crate through 2020-12-31 for Rust. read::BiteReadExpandedExt::read_framed_max may read from uninitialized memory locations.

  • CVE-2021-36512HigOct 19, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers to view sensitive information due to an uninitialized value.

  • CVE-2021-28030HigMar 5, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the truetype crate before 0.30.1 for Rust. Attackers can read the contents of uninitialized memory locations via a user-provided Read operation within Tape::take_bytes.

  • CVE-2021-28029HigMar 5, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the toodee crate before 0.3.0 for Rust. The row-insertion feature allows attackers to read the contents of uninitialized memory locations.

  • CVE-2020-26148HigSep 30, 2020
    risk 0.49cvss 7.5epss 0.01

    md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial of service (e.g., assertion failure) via a malformed Markdown document.

  • CVE-2020-0300HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.01

    In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148736216

  • CVE-2020-2575HigApr 29, 2020
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the…