CWE-908
Use of Uninitialized Resource
Description
The product uses or accesses a resource that has not been initialized.
Hierarchy (View 1000)
CVEs mapped to this weakness (829)
page 16 of 42| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-29958 | Med | 0.42 | 6.5 | 0.01 | May 13, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-29830 | Med | 0.42 | 6.5 | 0.01 | May 13, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-27474 | Med | 0.42 | 6.5 | 0.02 | Apr 8, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-21288 | Med | 0.42 | 6.5 | 0.01 | Jan 14, 2025 | Windows COM Server Information Disclosure Vulnerability | ||
| CVE-2025-21272 | Med | 0.42 | 6.5 | 0.01 | Jan 14, 2025 | Windows COM Server Information Disclosure Vulnerability | ||
| CVE-2024-12085 | Hig | 0.42 | 7.5 | 0.09 | Jan 14, 2025 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a… | ||
| CVE-2018-9429 | Med | 0.42 | 6.5 | 0.00 | Dec 2, 2024 | In buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. | ||
| CVE-2024-43537 | Med | 0.42 | 6.5 | 0.01 | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability | ||
| CVE-2024-7526 | Med | 0.42 | 6.5 | 0.01 | Aug 6, 2024 | ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14. | ||
| CVE-2024-21502 | Hig | 0.42 | 7.5 | 0.01 | Feb 24, 2024 | Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the curvemath_mul function in src/curveMath.c, due to being used and interpreted as user-defined type. Depending on the variable's actual value it could be arbitrary… | ||
| CVE-2024-26147 | Hig | 0.42 | 7.5 | 0.01 | Feb 21, 2024 | Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all… | ||
| CVE-2023-4489 | Med | 0.42 | 6.4 | 0.01 | Dec 14, 2023 | The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0… | ||
| CVE-2023-36398 | Med | 0.42 | 6.5 | 0.01 | Nov 14, 2023 | Windows NTFS Information Disclosure Vulnerability | ||
| CVE-2023-36913 | Med | 0.42 | 6.5 | 0.02 | Aug 8, 2023 | Microsoft Message Queuing Information Disclosure Vulnerability | ||
| CVE-2023-32042 | Med | 0.42 | 6.5 | 0.01 | Jul 11, 2023 | OLE Automation Information Disclosure Vulnerability | ||
| CVE-2022-2308 | Med | 0.42 | 6.5 | 0.00 | Sep 1, 2022 | A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of the device config space is in line with the features advertised by the VDUSE userspace application. In case of a mismatch, Virtio drivers config read helpers… | ||
| CVE-2022-25345 | Hig | 0.42 | 7.5 | 0.01 | Jun 17, 2022 | All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash. | ||
| CVE-2021-39671 | Med | 0.42 | 6.5 | 0.00 | Feb 11, 2022 | In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-23573 | Hig | 0.42 | 7.6 | 0.01 | Feb 4, 2022 | Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitialized data to a new tensor. This later results in undefined behavior. The implementation has a check that the left hand side of the assignment is initialized… | ||
| CVE-2018-25023 | Hig | 0.42 | 7.5 | 0.01 | Dec 27, 2021 | An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type. |
- risk 0.42cvss 6.5epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.02
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Windows COM Server Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows COM Server Information Disclosure Vulnerability
- risk 0.42cvss 7.5epss 0.09
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a…
- risk 0.42cvss 6.5epss 0.00
In buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
- risk 0.42cvss 6.5epss 0.01
Windows Mobile Broadband Driver Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
- risk 0.42cvss 7.5epss 0.01
Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the curvemath_mul function in src/curveMath.c, due to being used and interpreted as user-defined type. Depending on the variable's actual value it could be arbitrary…
- risk 0.42cvss 7.5epss 0.01
Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content. When either an `index.yaml` file or a plugins `plugin.yaml` file were missing all…
- risk 0.42cvss 6.4epss 0.01
The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key generated at startup predictable, potentially allowing network key prediction and unauthorized S0…
- risk 0.42cvss 6.5epss 0.01
Windows NTFS Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Message Queuing Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
OLE Automation Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.00
A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of the device config space is in line with the features advertised by the VDUSE userspace application. In case of a mismatch, Virtio drivers config read helpers…
- risk 0.42cvss 7.5epss 0.01
All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.
- risk 0.42cvss 6.5epss 0.00
In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.42cvss 7.6epss 0.01
Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitialized data to a new tensor. This later results in undefined behavior. The implementation has a check that the left hand side of the assignment is initialized…
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type.