In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() er
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9
Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in
In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup(
GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attacke
In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uninitialize
In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr in xfrm6_get_saddr()
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t
In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Fix parameter validation for packet
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN r
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of uninitialized
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Return the correct value in vmw_transla
In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In se
In the Linux kernel, the following vulnerability has been resolved: bonding: fix type confusion in bond_setup_by_slave(
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for netw
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cau
In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tn
Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixe
Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in
In the Linux kernel, the following vulnerability has been resolved: libceph: Use u32 for non-negative values in ceph_mo
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process t
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Fi
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak p
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious S
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an u
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare(
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information local
in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitial
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is
n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, an authenticated user
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid imag
Uninitialized Use in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the ren
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory d
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsin
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a netwo
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Frequently Asked Questions
What is CWE-908?
CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-908?
There are 161 CVE records associated with CWE-908 in our database. Of these, 6 are critical severity, 30 are high severity, and 104 are medium severity.
How can I protect against CWE-908 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.
Detect CWE-908 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.
Get Started