In the Linux kernel, the following vulnerability has been resolved: mptcp: ensure snd_una is properly initialized on co
In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninitialized ratelimit_state->lock acces
In the Linux kernel, the following vulnerability has been resolved: ice: Fix KASAN error in LAG NETDEV_UNREGISTER handl
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Init the count variable in collecting hot
In the Linux kernel, the following vulnerability has been resolved: bpf: Mark bpf prog stack with kmsan_unposion_memory
In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: Initialize unused data in j1939_se
In the Linux kernel, the following vulnerability has been resolved: x86: stop playing stack games in profile_pc() The
In the Linux kernel, the following vulnerability has been resolved: inet_diag: Initialize pad field in struct inet_diag
In the Linux kernel, the following vulnerability has been resolved: net: txgbe: initialize num_q_vectors for MSI/INTx i
In the Linux kernel, the following vulnerability has been resolved: leds: an30259a: Use devm_mutex_init() for mutex ini
In the Linux kernel, the following vulnerability has been resolved: leds: mlxreg: Use devm_mutex_init() for mutex initi
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Initialize all fields in dumped nexth
In the Linux kernel, the following vulnerability has been resolved: sysctl: always initialize i_uid/i_gid Always initi
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: fix validity interception issue when gis
Windows Authentication Information Disclosure Vulnerability
Windows Kernel-Mode Driver Information Disclosure Vulnerability
In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix error handling in mana_create_txq/rx
In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix invalid mr resource destroy Certain
In the Linux kernel, the following vulnerability has been resolved: drm/xe/hdcp: Check GSC structure validity Sometime
In the Linux kernel, the following vulnerability has been resolved: ext4: fix access to uninitialised lock in fc replay
In the Linux kernel, the following vulnerability has been resolved: igb: Initialize mailbox message for VF reset When
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix one more kernel-infoleak in algo dumping
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since
In the Linux kernel, the following vulnerability has been resolved: usb: typec: qcom-pmic: init value of hdr_len/txbuf_
In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uniniti
In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uniniti
In BnCameraService::onTransact of CameraService.cpp, there is a possible information disclosure due to uninitialized dat
In writeInplace of Parcel.cpp, there is a possible information leak across processes, using Binder, due to uninitialized
In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized value issue in from_kuid and
In getIntentForIntentSender of ActivityManagerService.java, there is a possible way to access user metadata due to a pen
In the Linux kernel, the following vulnerability has been resolved: ocfs2: free inode when ocfs2_get_init_inode() fails
In the Linux kernel, the following vulnerability has been resolved: net: hsr: avoid potential out-of-bound access in fi
In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: Check num_codecs is not zero to avo
In the Linux kernel, the following vulnerability has been resolved: rtc: check if __rtc_read_time was successful in rtc
The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a
Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 S
Windows Mobile Hotspot Information Disclosure Vulnerability
MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are calle
In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix uninit-value access in __ip_make_skb() K
In the Linux kernel, the following vulnerability has been resolved: nbd: always initialize struct msghdr completely sy
Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memor
In the Linux kernel, the following vulnerability has been resolved: ALSA: rawmidi - fix the uninitalized user_pversion
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initial
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted
A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which woul
OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows lo
oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attac
Frequently Asked Questions
What is CWE-908?
CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-908?
There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.
How can I protect against CWE-908 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.
Detect CWE-908 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.
Get Started