An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matr
An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust. An uninitialized buffer is passed to AsyncRe
An issue was discovered in the array-tools crate before 0.3.2 for Rust. FixedCapacityDequeLike::clone() has a drop of un
The RISC-V Instruction Set Manual contains a documented ambiguity for the Machine Trap Vector Base Address (MTVEC) regis
A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow
When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assig
An issue was discovered in the buffoon crate through 2020-12-31 for Rust. InputStream::read_exact may read from uninitia
An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. read_up_to may read from uninitialized memo
An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. fill_buf may read from uninitialized memory
An issue was discovered in the bronzedb-protocol crate through 2021-01-03 for Rust. ReadKVExt may read from uninitialize
An issue was discovered in the binjs_io crate through 2021-01-03 for Rust. The Read method may read from uninitialized m
An issue was discovered in the flumedb crate through 2021-01-07 for Rust. read_entry may read from uninitialized memory
An issue was discovered in the columnar crate through 2021-01-07 for Rust. ColumnarReadExt::read_typed_vec may read from
An issue was discovered in the csv-sniffer crate through 2021-01-05 for Rust. preamble_skipcount may read from uninitial
An issue was discovered in the ash crate before 0.33.1 for Rust. util::read_spv may read from uninitialized memory locat
An issue was discovered in the gfx-auxil crate through 2021-01-07 for Rust. gfx_auxil::read_spirv may read from uninitia
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_binary may read from uninit
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string may read from uninit
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_extension_others may read f
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string_primitive may read f
An issue was discovered in the tectonic_xdv crate before 0.1.12 for Rust. XdvParser::<T>::process may read from uninitia
An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized mem
Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sens
In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remo
Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform out of bounds me
An improper free of uninitialized memory can occur in DIAG services in Snapdragon Compute, Snapdragon Industrial IOT, Sn
An issue was discovered in the autorand crate before 0.2.3 for Rust. Because of impl Random on arrays, uninitialized mem
In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local
In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local
In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local
In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE
vim is vulnerable to Use of Uninitialized Variable
An issue was discovered in the ms3d crate before 0.1.3 for Rust. It might allow attackers to obtain sensitive informatio
An issue was discovered in the postscript crate before 0.14.0 for Rust. It might allow attackers to obtain sensitive inf
An issue was discovered in the toodee crate before 0.3.0 for Rust. The row-insertion feature allows attackers to read th
An issue was discovered in the truetype crate before 0.30.1 for Rust. Attackers can read the contents of uninitialized m
An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers t
An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type,
An issue was discovered in the bite crate through 2020-12-31 for Rust. read::BiteReadExpandedExt::read_framed_max may re
An issue was discovered in the rdiff crate through 2021-02-03 for Rust. Window may read from uninitialized memory locati
An issue was discovered in PartialReader in the uu_od crate before 0.0.4 for Rust. Attackers can read the contents of un
In display driver, there is a possible memory corruption due to uninitialized data. This could lead to local escalation
Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt
An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versio
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt
Frequently Asked Questions
What is CWE-908?
CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-908?
There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.
How can I protect against CWE-908 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.
Detect CWE-908 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.
Get Started