VYPR

CWE-908

Use of Uninitialized Resource

BaseIncompleteLikelihood: Medium

Description

The product uses or accesses a resource that has not been initialized.

When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (829)

page 2 of 42
  • CVE-2021-45691CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string may read from uninitialized memory locations.

  • CVE-2021-45690CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_binary may read from uninitialized memory locations.

  • CVE-2021-45689CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the gfx-auxil crate through 2021-01-07 for Rust. gfx_auxil::read_spirv may read from uninitialized memory locations.

  • CVE-2021-45685CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the columnar crate through 2021-01-07 for Rust. ColumnarReadExt::read_typed_vec may read from uninitialized memory locations.

  • CVE-2021-45683CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the binjs_io crate through 2021-01-03 for Rust. The Read method may read from uninitialized memory locations.

  • CVE-2021-45682CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the bronzedb-protocol crate through 2021-01-03 for Rust. ReadKVExt may read from uninitialized memory locations.

  • CVE-2020-36514CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. fill_buf may read from uninitialized memory locations.

  • CVE-2020-36513CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. read_up_to may read from uninitialized memory locations.

  • CVE-2020-36512CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the buffoon crate through 2020-12-31 for Rust. InputStream::read_exact may read from uninitialized memory locations.

  • CVE-2021-1619CriSep 23, 2021
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the…

  • CVE-2021-1104CriAug 13, 2021
    risk 0.64cvss 9.8epss 0.02

    The RISC-V Instruction Set Manual contains a documented ambiguity for the Machine Trap Vector Base Address (MTVEC) register that may lead to a vulnerability due to the initial state of the register not being defined, potentially leading to information disclosure, data tampering…

  • CVE-2020-36452CriAug 8, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the array-tools crate before 0.3.2 for Rust. FixedCapacityDequeLike::clone() has a drop of uninitialized memory.

  • CVE-2020-36443CriAug 8, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust. An uninitialized buffer is passed to AsyncRead::poll_read(), which is a user-provided trait function.

  • CVE-2020-36432CriAug 8, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matrix::new().

  • CVE-2018-25014CriMay 21, 2021
    risk 0.64cvss 9.8epss 0.02

    A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().

  • CVE-2021-29936CriApr 1, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the adtensor crate through 2021-01-11 for Rust. There is a drop of uninitialized memory via the FromIterator implementation for Vector and Matrix.

  • CVE-2021-26951CriFeb 9, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the calamine crate before 0.17.0 for Rust. It allows attackers to overwrite heap-memory locations because Vec::set_len is used without proper memory claiming, and this uninitialized memory is used for a user-provided Read operation, as demonstrated by…

  • CVE-2020-35888CriDec 31, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the arr crate through 2020-08-25 for Rust. Uninitialized memory is dropped by Array::new_from_template.

  • CVE-2020-35878CriDec 31, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the ozone crate through 2020-07-04 for Rust. Memory safety is violated because of the dropping of uninitialized memory.

  • CVE-2019-14052CriSep 8, 2020
    risk 0.64cvss 9.8epss 0.01

    u'Accessing an uninitialized data structure could result in partially copying of contents and thus incorrect processing' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables…