Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-908

MITRE ↗

CWE-908

6
CRITICAL
30
HIGH
104
MEDIUM
6
LOW
156 CVEs · Page 1/4
9.8
CVE-2026-52989

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() er

9.8
CVE-2026-56190

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.

9.1
CVE-2026-2806

Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

9.1
CVE-2026-4715

Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9

9.1
CVE-2026-4716

Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in

9.1
CVE-2026-53225

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup(

8.8
CVE-2026-2044

GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attacke

8.8
CVE-2026-53170

In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uninitialize

8.6
CVE-2026-43139

In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr in xfrm6_get_saddr()

8.4
CVE-2026-40364

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t

8.3
CVE-2026-43291

In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Fix parameter validation for packet

8.2
CVE-2025-71311

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN r

8.2
CVE-2026-60005

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and

8.1
CVE-2026-16868

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized

7.8
CVE-2026-23317

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Return the correct value in vmw_transla

7.8
CVE-2026-31693

In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In se

7.8
CVE-2026-43456

In the Linux kernel, the following vulnerability has been resolved: bonding: fix type confusion in bond_setup_by_slave(

7.8
CVE-2026-55949

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.5
CVE-2026-0915

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for netw

7.5
CVE-2025-15281

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cau

7.5
CVE-2026-23003

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tn

7.5
CVE-2026-2794

Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixe

7.5
CVE-2026-3497

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI

7.5
CVE-2026-34543

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the

7.5
CVE-2026-6749

Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in

7.5
CVE-2026-43405

In the Linux kernel, the following vulnerability has been resolved: libceph: Use u32 for non-negative values in ceph_mo

7.5
CVE-2026-11576

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process t

7.5
CVE-2026-16384

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi

7.5
CVE-2026-16385

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi

7.5
CVE-2026-16386

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi

7.5
CVE-2026-47247

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak p

7.5
CVE-2026-66034

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious S

7.5
CVE-2026-0301

An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an u

7.1
CVE-2026-31626

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_

7.1
CVE-2026-47272

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare(

7.1
CVE-2026-49165

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information local

6.5
CVE-2025-12736

in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitial

6.5
CVE-2026-4147

An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is

6.5
CVE-2026-27496

n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, an authenticated user

6.5
CVE-2026-32814

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid imag

6.5
CVE-2026-11089

Uninitialized Use in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the ren

6.5
CVE-2026-48101

7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory d

6.5
CVE-2026-58051

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsin

6.5
CVE-2026-55003

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-50376

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-50497

Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a netwo

6.5
CVE-2026-57982

Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.

6.5
CVE-2026-58533

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-58535

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-58546

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

Frequently Asked Questions

What is CWE-908?

CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-908?

There are 161 CVE records associated with CWE-908 in our database. Of these, 6 are critical severity, 30 are high severity, and 104 are medium severity.

How can I protect against CWE-908 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.

Detect CWE-908 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.

Get Started