CWE-908
Use of Uninitialized Resource
Description
The product uses or accesses a resource that has not been initialized.
Hierarchy (View 1000)
CVEs mapped to this weakness (901)
page 22 of 46| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-4905 | Med | 0.39 | 5.5 | 0.01 | Jun 7, 2017 | VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion… | ||
| CVE-2026-16827 | Med | 0.38 | 5.9 | 0.00 | Aug 19, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use of an uninitialized stack pointer. | ||
| CVE-2022-39283 | Med | 0.38 | 5.9 | 0.01 | Oct 12, 2022 | FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command line switch might read uninitialized data, decode it as audio/video and display the result. FreeRDP based server implementations are not affected. This issue… | ||
| CVE-2022-26370 | Med | 0.38 | 5.9 | 0.01 | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual… | ||
| CVE-2019-18603 | Med | 0.38 | 5.9 | 0.01 | Oct 29, 2019 | OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer. | ||
| CVE-2019-11323 | Med | 0.38 | 5.9 | 0.01 | May 9, 2019 | HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error. | ||
| CVE-2026-69349 | Med | 0.37 | 5.7 | 0.01 | Sep 8, 2026 | Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53719 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53153 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53148 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53138 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-50157 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-50156 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2024-32606 | Med | 0.37 | 5.7 | 0.00 | May 14, 2024 | HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c). | ||
| CVE-2024-26209 | Med | 0.37 | 5.5 | 0.15 | Apr 9, 2024 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | ||
| CVE-2026-81958 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-81391 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-72945 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally. | ||
| CVE-2026-70290 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally. | ||
| CVE-2026-69770 | Med | 0.36 | 5.5 | 0.00 | Sep 8, 2026 | Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally. |
- risk 0.39cvss 5.5epss 0.01
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion…
- risk 0.38cvss 5.9epss 0.00
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use of an uninitialized stack pointer.
- risk 0.38cvss 5.9epss 0.01
FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command line switch might read uninitialized data, decode it as audio/video and display the result. FreeRDP based server implementations are not affected. This issue…
- risk 0.38cvss 5.9epss 0.01
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual…
- risk 0.38cvss 5.9epss 0.01
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer.
- risk 0.38cvss 5.9epss 0.01
HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.00
HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).
- risk 0.37cvss 5.5epss 0.15
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.