VYPR

CWE-908

Use of Uninitialized Resource

BaseIncompleteLikelihood: Medium

Description

The product uses or accesses a resource that has not been initialized.

When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (829)

page 29 of 42
  • CVE-2023-36713MedOct 10, 2023
    risk 0.36cvss 5.5epss 0.08

    Windows Common Log File System Driver Information Disclosure Vulnerability

  • CVE-2023-38140MedSep 12, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows Kernel Information Disclosure Vulnerability

  • CVE-2023-21276MedAug 14, 2023
    risk 0.36cvss 5.5epss 0.00

    In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2021-0948MedJul 13, 2023
    risk 0.36cvss 5.5epss 0.00

    The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel memory to user space. The contents of this memory could contain sensitive information.

  • CVE-2023-35326MedJul 11, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows CDP User Components Information Disclosure Vulnerability

  • CVE-2023-32041MedJul 11, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows Update Orchestrator Service Information Disclosure Vulnerability

  • CVE-2023-32016MedJun 14, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows Installer Information Disclosure Vulnerability

  • CVE-2023-21753MedJan 10, 2023
    risk 0.36cvss 5.5epss 0.01

    Event Tracing for Windows Information Disclosure Vulnerability

  • CVE-2021-0887MedAug 24, 2022
    risk 0.36cvss 5.5epss 0.00

    In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0698MedAug 24, 2022
    risk 0.36cvss 5.5epss 0.00

    In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20357MedAug 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-34266MedJul 19, 2022
    risk 0.36cvss 5.5epss 0.00

    The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (application crash), a different vulnerability than CVE-2022-0562. When processing a malicious TIFF file, an invalid range may be passed as an argument to the…

  • CVE-2021-40608MedJun 28, 2022
    risk 0.36cvss 5.5epss 0.01

    The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.

  • CVE-2022-20119MedMay 10, 2022
    risk 0.36cvss 5.5epss 0.00

    In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-44003MedDec 14, 2021
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll is vulnerable to use of uninitialized memory while parsing user supplied TIFF files. This could allow an attacker to cause a…

  • CVE-2021-0938MedOct 25, 2021
    risk 0.36cvss 5.5epss 0.00

    In memzero_explicit of compiler-clang.h, there is a possible bypass of defense in depth due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-21218MedApr 26, 2021
    risk 0.36cvss 5.5epss 0.01

    Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.

  • CVE-2021-0463MedMar 10, 2021
    risk 0.36cvss 5.5epss 0.00

    In convertToHidl of convert.cpp, there is a possible out of bounds read due to uninitialized data from ReturnFrameworkMessage. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-15989MedNov 3, 2020
    risk 0.36cvss 5.5epss 0.01

    Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.

  • CVE-2020-16855MedSep 11, 2020
    risk 0.36cvss 5.5epss 0.04

    An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view out of bound memory.…