CWE-908
Use of Uninitialized Resource
Description
The product uses or accesses a resource that has not been initialized.
Hierarchy (View 1000)
CVEs mapped to this weakness (829)
page 29 of 42| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36713 | Med | 0.36 | 5.5 | 0.08 | Oct 10, 2023 | Windows Common Log File System Driver Information Disclosure Vulnerability | ||
| CVE-2023-38140 | Med | 0.36 | 5.5 | 0.01 | Sep 12, 2023 | Windows Kernel Information Disclosure Vulnerability | ||
| CVE-2023-21276 | Med | 0.36 | 5.5 | 0.00 | Aug 14, 2023 | In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2021-0948 | Med | 0.36 | 5.5 | 0.00 | Jul 13, 2023 | The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel memory to user space. The contents of this memory could contain sensitive information. | ||
| CVE-2023-35326 | Med | 0.36 | 5.5 | 0.01 | Jul 11, 2023 | Windows CDP User Components Information Disclosure Vulnerability | ||
| CVE-2023-32041 | Med | 0.36 | 5.5 | 0.01 | Jul 11, 2023 | Windows Update Orchestrator Service Information Disclosure Vulnerability | ||
| CVE-2023-32016 | Med | 0.36 | 5.5 | 0.01 | Jun 14, 2023 | Windows Installer Information Disclosure Vulnerability | ||
| CVE-2023-21753 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2023 | Event Tracing for Windows Information Disclosure Vulnerability | ||
| CVE-2021-0887 | Med | 0.36 | 5.5 | 0.00 | Aug 24, 2022 | In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2021-0698 | Med | 0.36 | 5.5 | 0.00 | Aug 24, 2022 | In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-20357 | Med | 0.36 | 5.5 | 0.00 | Aug 10, 2022 | In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-34266 | Med | 0.36 | 5.5 | 0.00 | Jul 19, 2022 | The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (application crash), a different vulnerability than CVE-2022-0562. When processing a malicious TIFF file, an invalid range may be passed as an argument to the… | ||
| CVE-2021-40608 | Med | 0.36 | 5.5 | 0.01 | Jun 28, 2022 | The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command. | ||
| CVE-2022-20119 | Med | 0.36 | 5.5 | 0.00 | May 10, 2022 | In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2021-44003 | Med | 0.36 | 5.5 | 0.01 | Dec 14, 2021 | A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll is vulnerable to use of uninitialized memory while parsing user supplied TIFF files. This could allow an attacker to cause a… | ||
| CVE-2021-0938 | Med | 0.36 | 5.5 | 0.00 | Oct 25, 2021 | In memzero_explicit of compiler-clang.h, there is a possible bypass of defense in depth due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2021-21218 | Med | 0.36 | 5.5 | 0.01 | Apr 26, 2021 | Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file. | ||
| CVE-2021-0463 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2021 | In convertToHidl of convert.cpp, there is a possible out of bounds read due to uninitialized data from ReturnFrameworkMessage. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:… | ||
| CVE-2020-15989 | Med | 0.36 | 5.5 | 0.01 | Nov 3, 2020 | Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file. | ||
| CVE-2020-16855 | Med | 0.36 | 5.5 | 0.04 | Sep 11, 2020 | An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view out of bound memory.… |
- risk 0.36cvss 5.5epss 0.08
Windows Common Log File System Driver Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Kernel Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel memory to user space. The contents of this memory could contain sensitive information.
- risk 0.36cvss 5.5epss 0.01
Windows CDP User Components Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Update Orchestrator Service Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Installer Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Event Tracing for Windows Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.36cvss 5.5epss 0.00
The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (application crash), a different vulnerability than CVE-2022-0562. When processing a malicious TIFF file, an invalid range may be passed as an argument to the…
- risk 0.36cvss 5.5epss 0.01
The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
- risk 0.36cvss 5.5epss 0.00
In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.01
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll is vulnerable to use of uninitialized memory while parsing user supplied TIFF files. This could allow an attacker to cause a…
- risk 0.36cvss 5.5epss 0.00
In memzero_explicit of compiler-clang.h, there is a possible bypass of defense in depth due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.01
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
- risk 0.36cvss 5.5epss 0.00
In convertToHidl of convert.cpp, there is a possible out of bounds read due to uninitialized data from ReturnFrameworkMessage. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.01
Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
- risk 0.36cvss 5.5epss 0.04
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view out of bound memory.…