VYPR

CWE-908

Use of Uninitialized Resource

BaseIncompleteLikelihood: Medium

Description

The product uses or accesses a resource that has not been initialized.

When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (901)

page 23 of 46
  • CVE-2026-69672MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.

  • CVE-2026-69288MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

  • CVE-2026-68873MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.

  • CVE-2026-68852MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally.

  • CVE-2026-58084MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. For a timer using CLOCK_TAI this can fail when no TAI offset has been configured, but the error return was not checked, so the uninitialized output…

  • CVE-2026-49425MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero the stack struct. An unprivileged user may observe a small amount of uninitialized kernel stack data, which may contain sensitive information.

  • CVE-2026-49424MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct. An unprivileged user may observe 104 bytes of uninitialized kernel stack data, which may contain sensitive information.

  • CVE-2026-70317MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

  • CVE-2026-68799MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-62740MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.

  • CVE-2026-62709MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

  • CVE-2026-59137MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.

  • CVE-2026-59136MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.

  • CVE-2026-70631MedAug 6, 2026
    risk 0.36cvss 5.5epss 0.00

    FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that…

  • CVE-2026-70630MedAug 6, 2026
    risk 0.36cvss 5.5epss 0.00

    FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a…

  • CVE-2026-70629MedAug 6, 2026
    risk 0.36cvss 5.5epss 0.00

    FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that…

  • CVE-2026-42969MedJun 9, 2026
    risk 0.36cvss 5.5epss 0.00

    Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

  • CVE-2026-23123MedFeb 14, 2026
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: interconnect: debugfs: initialize src_node and dst_node to empty strings The debugfs_create_str() API assumes that the string pointer is either NULL or points to valid kmalloc() memory. Leaving the pointer…

  • CVE-2026-23007MedJan 25, 2026
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: block: zero non-PI portion of auto integrity buffer The auto-generated integrity buffer for writes needs to be fully initialized before being passed to the underlying block device, otherwise the uninitialized…

  • CVE-2025-71115MedJan 14, 2026
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: um: init cpu_tasks[] earlier This is currently done in uml_finishsetup(), but e.g. with KCOV enabled we'll crash because some init code can call into e.g. memparse(), which has coverage annotations, and then…