CWE-908
Use of Uninitialized Resource
Description
The product uses or accesses a resource that has not been initialized.
Hierarchy (View 1000)
CVEs mapped to this weakness (829)
page 11 of 42| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-29838 | Hig | 0.49 | 7.5 | 0.01 | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller software | ||
| CVE-2024-23314 | Hig | 0.49 | 7.5 | 0.01 | Feb 14, 2024 | When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | ||
| CVE-2023-36567 | Hig | 0.49 | 7.5 | 0.02 | Oct 10, 2023 | Windows Deployment Services Information Disclosure Vulnerability | ||
| CVE-2023-21233 | Hig | 0.49 | 7.5 | 0.00 | Aug 14, 2023 | In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-35325 | Hig | 0.49 | 7.5 | 0.02 | Jul 11, 2023 | Windows Print Spooler Information Disclosure Vulnerability | ||
| CVE-2023-28967 | Hig | 0.49 | 7.5 | 0.01 | Apr 17, 2023 | A Use of Uninitialized Resource vulnerability in the Border Gateway Protocol (BGP) software of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to send specific genuine BGP packets to a device configured with BGP to cause a Denial… | ||
| CVE-2022-25737 | Hig | 0.49 | 7.5 | 0.00 | Apr 13, 2023 | Information disclosure in modem due to missing NULL check while reading packets received from local network | ||
| CVE-2023-22281 | Hig | 0.49 | 7.5 | 0.01 | Feb 1, 2023 | On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP AFM NAT policy with a destination NAT rule is configured on a FastL4 virtual server, undisclosed traffic can cause the Traffic… | ||
| CVE-2022-47012 | Hig | 0.49 | 7.5 | 0.01 | Jan 20, 2023 | Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21. | ||
| CVE-2022-34390 | Hig | 0.49 | 7.5 | 0.00 | Oct 12, 2022 | Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM. | ||
| CVE-2022-34655 | Hig | 0.49 | 7.5 | 0.01 | Aug 4, 2022 | In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing the HTTP::payload command is configured on a virtual server, undisclosed traffic can cause Traffic Management Microkernel (TMM) to terminate. Note: Software… | ||
| CVE-2022-28488 | Hig | 0.49 | 7.5 | 0.01 | May 4, 2022 | The function wav_format_write in libwav.c in libwav through 2017-04-20 has an Use of Uninitialized Variable vulnerability. | ||
| CVE-2021-45694 | Hig | 0.49 | 7.5 | 0.01 | Dec 27, 2021 | An issue was discovered in the rdiff crate through 2021-02-03 for Rust. Window may read from uninitialized memory locations. | ||
| CVE-2020-36511 | Hig | 0.49 | 7.5 | 0.01 | Dec 27, 2021 | An issue was discovered in the bite crate through 2020-12-31 for Rust. read::BiteReadExpandedExt::read_framed_max may read from uninitialized memory locations. | ||
| CVE-2021-36512 | Hig | 0.49 | 7.5 | 0.01 | Oct 19, 2021 | An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers to view sensitive information due to an uninitialized value. | ||
| CVE-2021-28030 | Hig | 0.49 | 7.5 | 0.01 | Mar 5, 2021 | An issue was discovered in the truetype crate before 0.30.1 for Rust. Attackers can read the contents of uninitialized memory locations via a user-provided Read operation within Tape::take_bytes. | ||
| CVE-2021-28029 | Hig | 0.49 | 7.5 | 0.01 | Mar 5, 2021 | An issue was discovered in the toodee crate before 0.3.0 for Rust. The row-insertion feature allows attackers to read the contents of uninitialized memory locations. | ||
| CVE-2020-26148 | Hig | 0.49 | 7.5 | 0.01 | Sep 30, 2020 | md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial of service (e.g., assertion failure) via a malformed Markdown document. | ||
| CVE-2020-0300 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2020 | In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148736216 | ||
| CVE-2020-2575 | Hig | 0.49 | 7.5 | 0.01 | Apr 29, 2020 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the… |
- risk 0.49cvss 7.5epss 0.01
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller software
- risk 0.49cvss 7.5epss 0.01
When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- risk 0.49cvss 7.5epss 0.02
Windows Deployment Services Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.00
In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.49cvss 7.5epss 0.02
Windows Print Spooler Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.01
A Use of Uninitialized Resource vulnerability in the Border Gateway Protocol (BGP) software of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker to send specific genuine BGP packets to a device configured with BGP to cause a Denial…
- risk 0.49cvss 7.5epss 0.00
Information disclosure in modem due to missing NULL check while reading packets received from local network
- risk 0.49cvss 7.5epss 0.01
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP AFM NAT policy with a destination NAT rule is configured on a FastL4 virtual server, undisclosed traffic can cause the Traffic…
- risk 0.49cvss 7.5epss 0.01
Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.
- risk 0.49cvss 7.5epss 0.00
Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
- risk 0.49cvss 7.5epss 0.01
In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing the HTTP::payload command is configured on a virtual server, undisclosed traffic can cause Traffic Management Microkernel (TMM) to terminate. Note: Software…
- risk 0.49cvss 7.5epss 0.01
The function wav_format_write in libwav.c in libwav through 2017-04-20 has an Use of Uninitialized Variable vulnerability.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in the rdiff crate through 2021-02-03 for Rust. Window may read from uninitialized memory locations.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in the bite crate through 2020-12-31 for Rust. read::BiteReadExpandedExt::read_framed_max may read from uninitialized memory locations.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers to view sensitive information due to an uninitialized value.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in the truetype crate before 0.30.1 for Rust. Attackers can read the contents of uninitialized memory locations via a user-provided Read operation within Tape::take_bytes.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in the toodee crate before 0.3.0 for Rust. The row-insertion feature allows attackers to read the contents of uninitialized memory locations.
- risk 0.49cvss 7.5epss 0.01
md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial of service (e.g., assertion failure) via a malformed Markdown document.
- risk 0.49cvss 7.5epss 0.01
In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148736216
- risk 0.49cvss 7.5epss 0.01
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.40, prior to 6.0.20 and prior to 6.1.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the…