oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attack
oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attac
Windows Network File System Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113
In readSampleData of NuMediaExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could
Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability
An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elem
iSCSI Target WMI Provider Remote Code Execution Vulnerability
Windows Setup Files Cleanup Remote Code Execution Vulnerability
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of Hyper
HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vts
Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versio
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, sending a malf
Information disclosure in modem due to missing NULL check while reading packets received from local network
A Use of Uninitialized Resource vulnerability in the Border Gateway Protocol (BGP) software of Juniper Networks Junos OS
VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not have an MSS lower bound (e.g., it could be zero).
Windows Print Spooler Information Disclosure Vulnerability
In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remot
Windows Deployment Services Information Disclosure Vulnerability
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information dis
OLE Automation Information Disclosure Vulnerability
Microsoft Message Queuing Information Disclosure Vulnerability
Windows NTFS Information Disclosure Vulnerability
The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP G
in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitia
Use of uninitialized resource in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable infor
Event Tracing for Windows Information Disclosure Vulnerability
Windows Installer Information Disclosure Vulnerability
Windows Update Orchestrator Service Information Disclosure Vulnerability
Windows CDP User Components Information Disclosure Vulnerability
The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel memory to user space
In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could l
Windows Kernel Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
An information disclosure vulnerability exists in the ClientConnect() functionality of SoftEther VPN 5.01.9674. A specia
stb_image is a single file MIT licensed library for processing images. The stbi__getn function reads a specified number
DHCP Server Service Information Disclosure Vulnerability
A Use of an Uninitialized Resource vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and J
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application cra
A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an
A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_s
Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stac
The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is unini
In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation o
Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform ou
softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_r
A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further
Frequently Asked Questions
What is CWE-908?
CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-908?
There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.
How can I protect against CWE-908 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.
Detect CWE-908 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.
Get Started