Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-908

MITRE ↗

CWE-908

67
CRITICAL
244
HIGH
469
MEDIUM
30
LOW
821 CVEs · Page 11/17
3.3
CVE-2024-7541

oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attack

3.3
CVE-2024-7542

oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attac

9.8
CVE-2023-24941

Windows Network File System Remote Code Execution Vulnerability

8.8
CVE-2023-23413

Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

8.8
CVE-2023-24886

Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

8.8
CVE-2023-32213

When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113

8.8
CVE-2023-21127

In readSampleData of NuMediaExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could

8.8
CVE-2023-38151

Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability

8.8
CVE-2023-31275

An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elem

7.8
CVE-2023-29367

iSCSI Target WMI Provider Remote Code Execution Vulnerability

7.8
CVE-2023-36704

Windows Setup Files Cleanup Remote Code Execution Vulnerability

7.7
CVE-2021-32845

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of Hyper

7.7
CVE-2021-32846

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vts

7.5
CVE-2022-47012

Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.

7.5
CVE-2023-22281

On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versio

7.5
CVE-2023-27598

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, sending a malf

7.5
CVE-2022-25737

Information disclosure in modem due to missing NULL check while reading packets received from local network

7.5
CVE-2023-28967

A Use of Uninitialized Resource vulnerability in the Border Gateway Protocol (BGP) software of Juniper Networks Junos OS

7.5
CVE-2023-35847

VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not have an MSS lower bound (e.g., it could be zero).

7.5
CVE-2023-35325

Windows Print Spooler Information Disclosure Vulnerability

7.5
CVE-2023-21233

In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remot

7.5
CVE-2023-36567

Windows Deployment Services Information Disclosure Vulnerability

6.5
CVE-2023-22897

An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information dis

6.5
CVE-2023-32042

OLE Automation Information Disclosure Vulnerability

6.5
CVE-2023-36913

Microsoft Message Queuing Information Disclosure Vulnerability

6.5
CVE-2023-36398

Windows NTFS Information Disclosure Vulnerability

6.4
CVE-2023-4489

The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP G

6.2
CVE-2023-46100

in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitia

6.0
CVE-2023-22330

Use of uninitialized resource in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable infor

5.5
CVE-2023-21753

Event Tracing for Windows Information Disclosure Vulnerability

5.5
CVE-2023-32016

Windows Installer Information Disclosure Vulnerability

5.5
CVE-2023-32041

Windows Update Orchestrator Service Information Disclosure Vulnerability

5.5
CVE-2023-35326

Windows CDP User Components Information Disclosure Vulnerability

5.5
CVE-2021-0948

The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel memory to user space

5.5
CVE-2023-21276

In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could l

5.5
CVE-2023-38140

Windows Kernel Information Disclosure Vulnerability

5.5
CVE-2023-36713

Windows Common Log File System Driver Information Disclosure Vulnerability

5.3
CVE-2023-31192

An information disclosure vulnerability exists in the ClientConnect() functionality of SoftEther VPN 5.01.9674. A specia

5.3
CVE-2023-45663

stb_image is a single file MIT licensed library for processing images. The stbi__getn function reads a specified number

5.3
CVE-2023-36012

DHCP Server Service Information Disclosure Vulnerability

4.7
CVE-2023-36836

A Use of an Uninitialized Resource vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and J

4.7
CVE-2023-25585

A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application cra

4.7
CVE-2023-25586

A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an

4.7
CVE-2023-25588

A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_s

3.8
CVE-2023-3488

Uninitialized buffer in GBL parser in Silicon Labs GSDK v4.3.0 and earlier allows attacker to leak data from Secure stac

3.1
CVE-2023-2747

The initialization vector (IV) used by the secure engine (SE) for encrypting data stored in the SE flash memory is unini

9.8
CVE-2022-26437

In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation o

8.8
CVE-2022-0115

Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform ou

8.8
CVE-2022-35414

softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_r

8.8
CVE-2022-31741

A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further

Frequently Asked Questions

What is CWE-908?

CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-908?

There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.

How can I protect against CWE-908 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.

Detect CWE-908 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.

Get Started