VYPR

CWE-908

Use of Uninitialized Resource

BaseIncompleteLikelihood: Medium

Description

The product uses or accesses a resource that has not been initialized.

When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (829)

page 40 of 42
  • CVE-2026-50455MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

  • CVE-2026-50376MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-55003MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-54997MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

  • CVE-2026-49801MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

  • CVE-2026-49165HigJul 14, 2026
    risk 0.00cvss 7.1epss 0.00

    Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

  • CVE-2026-40422MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-56085LowJul 3, 2026
    risk 0.00cvss 3.3epss 0.00

    Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of uninitialized resource vulnerability. A low…

  • CVE-2026-6686MedJul 1, 2026
    risk 0.00cvss 4.6epss 0.00

    FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-filling newly allocated clusters. This maps to CWE-908 (Use of Uninitialized Resource). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N…

  • CVE-2025-2173MedMar 11, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in libzvbi up to 0.2.43. It has been classified as problematic. Affected is the function vbi_strndup_iconv_ucs2 of the file src/conv.c. The manipulation of the argument src_length leads to uninitialized pointer. It is possible to launch the attack…

  • CVE-2024-11991MedDec 9, 2024
    risk 0.00cvss 5.6epss 0.00

    Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of write barriers in a few locations. This vulnerability could potentially allow unauthorized read or write access to a Canister's memory. However, exploiting this…

  • CVE-2023-35847HigJun 19, 2023
    risk 0.00cvss 7.5epss 0.01

    VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not have an MSS lower bound (e.g., it could be zero).

  • CVE-2023-27598HigMar 15, 2023
    risk 0.00cvss 7.5epss 0.01

    OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, sending a malformed `Via` header to OpenSIPS triggers a segmentation fault when the function `calc_tag_suffix` is called. A specially crafted `Via` header, which is deemed…

  • CVE-2021-32846HigFeb 17, 2023
    risk 0.00cvss 7.7epss 0.00

    HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vtsock_proc_tx` in `virtio-sock` can lead to to uninitialized memory use. In this situation, there is a check for the return value to be less or equal to…

  • CVE-2021-32845HigFeb 17, 2023
    risk 0.00cvss 7.7epss 0.00

    HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, the implementation of `qnotify` at `pci_vtrnd_notify` fails to check the return value of `vq_getchain`. This leads to `struct iovec iov;` being…

  • CVE-2022-40768MedSep 18, 2022
    risk 0.00cvss 5.5epss 0.00

    drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.

  • CVE-2022-29240HigSep 15, 2022
    risk 0.00cvss 8.1epss 0.01

    Scylla is a real-time big data database that is API-compatible with Apache Cassandra and Amazon DynamoDB. When decompressing CQL frame received from user, Scylla assumes that user-provided uncompressed length is correct. If user provides fake length, that is greater than the…

  • CVE-2022-38668HigAug 22, 2022
    risk 0.00cvss 7.5epss 0.01

    HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfilling a request for a static file smaller than 16 KB.

  • CVE-2020-27795HigAug 19, 2022
    risk 0.00cvss 7.5epss 0.01

    A segmentation fault was discovered in radare2 with adf command. In libr/core/cmd_anal.c, when command "adf" has no or wrong argument, anal_fcn_data (core, input + 1) --> RAnalFunction *fcn = r_anal_get_fcn_in (core->anal, core->offset, -1); returns null pointer for fcn causing…

  • CVE-2022-35414HigJul 11, 2022
    risk 0.00cvss 8.8epss 0.01

    softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference applies here, i.e., "Bugs affecting the…