Zydis is an x86/x86-64 disassembler library. Users of Zydis versions v3.2.0 and older that use the string functions prov
In convertToHidl of convert.cpp, there is a possible out of bounds read due to uninitialized data from ReturnFrameworkMe
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sens
md_analyze_line in md4c.c in md4c 0.4.7 allows attackers to trigger use of uninitialized memory, and cause a denial of s
In memzero_explicit of compiler-clang.h, there is a possible bypass of defense in depth due to uninitialized data. This
TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's Grappler optimizer has a u
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used
TensorFlow is an end-to-end open source platform for machine learning. In affected versions all TFLite operations that u
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada
An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The
Adobe Prelude version 10.0 (and earlier) are affected by an uninitialized variable vulnerability when parsing a speciall
TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FractionalMaxPo
TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.CTCBeamS
Dell EMC PowerScale OneFS versions 8.2.x - 9.1.0.x contain a use of uninitialized resource vulnerability. This can poten
u'Accessing an uninitialized data structure could result in partially copying of contents and thus incorrect processing'
A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow a
An issue was discovered in the ozone crate through 2020-07-04 for Rust. Memory safety is violated because of the droppin
An issue was discovered in the arr crate through 2020-08-25 for Rust. Uninitialized memory is dropped by Array::new_from
Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially expl
In the mp3 extractor, there is a possible out of bounds write due to uninitialized data. This could lead to remote code
An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to c
Out of bound access due to access of uninitialized memory segment in an array of pointers while normal camera open close
Access to the uninitialized variable when the driver tries to unmap the dma buffer of a request which was never mapped i
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan hors
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle o
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle o
In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger su
When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method,
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in jan
In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosu
md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial
An issue was discovered in the simple-slab crate before 0.3.3 for Rust. remove() has an off-by-one error, causing memory
In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_dlpack` can be made to use uninitialized
An issue was discovered on LG mobile devices with Android OS 8.0 and 8.1 software for the DTAG carrier. RILD in the radi
In NFC, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privil
In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uni
When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location.
In onReadBuffer() of StreamingSource.cpp, there is a possible information disclosure due to uninitialized data. This cou
An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due to an uninitialized
In ihevcd_iquant_itrans_recon_ctb of ihevcd_iquant_itrans_recon_ctb.c and related functions, there is a possible informa
In libcodec2_soft_mp3dec, there is a possible information disclosure due to uninitialized data. This could lead to remot
In libDRCdec, there is a possible information disclosure due to uninitialized data. This could lead to remote informatio
In ~AACExtractor() of AACExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could le
Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap
Azure Sphere Information Disclosure Vulnerability
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that ar
Frequently Asked Questions
What is CWE-908?
CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-908?
There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.
How can I protect against CWE-908 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.
Detect CWE-908 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.
Get Started