In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. Th
In onTransact of IAudioFlinger.cpp, there is a possible stack information leak due to uninitialized data. This could lea
In BnCrypto::onTransact of ICrypto.cpp, there is a possible information disclosure due to uninitialized data. This could
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninit
<p>An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uni
Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sens
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate va
An issue was discovered in USC iLab cereal through 1.3.0. Serialization of an (initialized) C/C++ long double variable i
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP serve
In FreeBSD 12.1-STABLE before r358739, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r358740, and 11.3-RELEASE
An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG),
An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attacke
In libhwbinder, there is a possible information disclosure due to uninitialized data. This could lead to local informati
In affected versions of TensorFlow under certain cases, loading a saved model can result in accessing uninitialized memo
In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code
When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. Thi
An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to inser
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. Gallery has uninitialized me
A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local
An issue was discovered in romfs_dev_read in fs/romfs/storage.c in the Linux kernel before 5.8.4. Uninitialized memory l
A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwar
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There i
A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, l
aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and
Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vuln
An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object poi
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strton
Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Au
ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.
In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This
Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potential
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle
In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There i
A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a
An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninit
An issue was discovered in the generator crate before 0.6.18 for Rust. Uninitialized memory is used by Scope, done, and
In Bluetooth, there is a possible out of bounds read due to uninitialized data. This could lead to remote information di
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIF
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the rel
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized s
Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker t
Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 R
Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sens
An issue was discovered in the claxon crate before 0.4.1 for Rust. Uninitialized memory can be exposed because certain d
A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affe
In libxaac, there is a possible information disclosure due to uninitialized data. This could lead to information disclos
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosu
Frequently Asked Questions
What is CWE-908?
CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-908?
There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.
How can I protect against CWE-908 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.
Detect CWE-908 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.
Get Started