A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify t
Scylla is a real-time big data database that is API-compatible with Apache Cassandra and Amazon DynamoDB. When decompres
Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerabilit
Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerabilit
Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitia
The function wav_format_write in libwav.c in libwav through 2017-04-20 has an Use of Uninitialized Variable vulnerabilit
All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder
In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing th
A segmentation fault was discovered in radare2 with adf command. In libr/core/cmd_anal.c, when command "adf" has no or w
HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack m
Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially e
h2o is an open source http server. In code prior to the `8c0eca3` commit h2o may attempt to access uninitialized memory.
In ccd, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privil
In isp, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privil
In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This
A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6,
Trilogy is a client library for MySQL. When authenticating, a malicious server could return a specially crafted authenti
FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command
A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_nex
In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to uninitialized data. This
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, there is a
The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in
The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (appl
In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could
In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could
In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This co
drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel me
An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 S
In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification w
In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This co
A vulnerability was found in ewxrjk sftpserver. It has been declared as problematic. Affected by this vulnerability is t
In kd_camera_hw driver, there is a possible information disclosure due to uninitialized data. This could lead to local i
In seninf driver, there is a possible information disclosure due to uninitialized data. This could lead to local informa
In sec_SHA256_Transform of sha256_core.c, there is a possible way to read heap data due to uninitialized data. This coul
A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kerne
In vow, there is a possible read of uninitialized data due to a improper input validation. This could lead to local info
In camera, there is a possible information disclosure due to uninitialized data. This could lead to local information di
In auth_store of sjtag-driver.c, there is a possible read of uninitialized memory due to a missing bounds check. This co
Information leakage in le_ecred_conn_req(). Zephyr versions >= v2.4.0 Use of Uninitialized Resource (CWE-908). For more
FreeRDP is a free remote desktop protocol library and clients. FreeRDP based clients on unix systems using `/parallel` c
An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag,
An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local attacker to read uninitial
An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implement
An issue was discovered in the calamine crate before 0.17.0 for Rust. It allows attackers to overwrite heap-memory locat
An issue was discovered in the byte_struct crate before 0.6.1 for Rust. There can be a drop of uninitialized memory if a
An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a drop of unin
An issue was discovered in the adtensor crate through 2021-01-11 for Rust. There is a drop of uninitialized memory via t
An issue was discovered in the telemetry crate through 2021-02-17 for Rust. There is a drop of uninitialized memory if a
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
Frequently Asked Questions
What is CWE-908?
CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-908?
There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.
How can I protect against CWE-908 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.
Detect CWE-908 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.
Get Started