VYPR

CWE-908

Use of Uninitialized Resource

BaseIncompleteLikelihood: Medium

Description

The product uses or accesses a resource that has not been initialized.

When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (901)

page 18 of 46
  • CVE-2022-25345HigJun 17, 2022
    risk 0.42cvss 7.5epss 0.01

    All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.

  • CVE-2021-39671MedFeb 11, 2022
    risk 0.42cvss 6.5epss 0.00

    In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-23573HigFeb 4, 2022
    risk 0.42cvss 7.6epss 0.01

    Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitialized data to a new tensor. This later results in undefined behavior. The implementation has a check that the left hand side of the assignment is initialized…

  • CVE-2018-25023HigDec 27, 2021
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type.

  • CVE-2021-34855MedOct 25, 2021
    risk 0.42cvss 6.5epss 0.00

    This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability.…

  • CVE-2021-3545MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.00

    An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_get_capset_info() in contrib/vhost-user-gpu/virgl.c and could occur due to the read of uninitialized…

  • CVE-2021-31919HigApr 30, 2021
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the rkyv crate before 0.6.0 for Rust. When an archive is created via serialization, the archive content may contain uninitialized values of certain parts of a struct.

  • CVE-2021-31419MedApr 29, 2021
    risk 0.42cvss 6.5epss 0.00

    This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability.…

  • CVE-2021-31418MedApr 29, 2021
    risk 0.42cvss 6.5epss 0.00

    This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability.…

  • CVE-2021-31417MedApr 29, 2021
    risk 0.42cvss 6.5epss 0.00

    This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability.…

  • CVE-2021-26953HigFeb 9, 2021
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the postscript crate before 0.14.0 for Rust. It might allow attackers to obtain sensitive information from uninitialized memory locations via a user-provided Read implementation.

  • CVE-2021-26952HigFeb 9, 2021
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in the ms3d crate before 0.1.3 for Rust. It might allow attackers to obtain sensitive information from uninitialized memory locations via IoReader::read.

  • CVE-2021-26308HigJan 29, 2021
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the marc crate before 2.0.0 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated memory, violating soundness.

  • CVE-2020-16042MedJan 8, 2021
    risk 0.42cvss 6.5epss 0.01

    Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2020-35893HigDec 31, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the simple-slab crate before 0.3.3 for Rust. remove() has an off-by-one error, causing memory leakage and a drop of uninitialized memory.

  • CVE-2020-0411MedOct 14, 2020
    risk 0.42cvss 6.5epss 0.01

    In ~AACExtractor() of AACExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-0361MedSep 17, 2020
    risk 0.42cvss 6.5epss 0.01

    In libDRCdec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID:…

  • CVE-2020-0340MedSep 17, 2020
    risk 0.42cvss 6.5epss 0.01

    In libcodec2_soft_mp3dec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-0195MedJun 11, 2020
    risk 0.42cvss 6.5epss 0.01

    In ihevcd_iquant_itrans_recon_ctb of ihevcd_iquant_itrans_recon_ctb.c and related functions, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is…

  • CVE-2020-0049MedMar 10, 2020
    risk 0.42cvss 6.5epss 0.01

    In onReadBuffer() of StreamingSource.cpp, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions:…