Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-908

MITRE ↗

CWE-908

67
CRITICAL
244
HIGH
469
MEDIUM
30
LOW
821 CVEs · Page 16/17
6.5
CVE-2019-2167

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosu

6.5
CVE-2019-2168

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosu

6.5
CVE-2019-2169

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosu

6.5
CVE-2019-2170

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosu

6.5
CVE-2019-2171

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosu

6.5
CVE-2019-2172

In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosu

6.5
CVE-2019-9322

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di

6.5
CVE-2019-9334

In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information d

6.5
CVE-2019-9335

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di

6.5
CVE-2019-9336

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di

6.5
CVE-2019-9337

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di

6.5
CVE-2019-9338

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di

6.5
CVE-2019-9359

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di

6.5
CVE-2019-9361

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di

6.5
CVE-2019-9391

In libxaac, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure

6.5
CVE-2019-9406

In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information d

6.5
CVE-2019-9408

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di

6.5
CVE-2019-9409

In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information d

6.5
CVE-2019-9410

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di

6.5
CVE-2019-9411

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di

6.5
CVE-2019-9415

In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote inform

6.5
CVE-2019-9416

In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote inform

6.5
CVE-2019-13751

Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sens

5.9
CVE-2019-11323

HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, H

5.9
CVE-2019-18603

OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because unini

5.5
CVE-2018-12011

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized

5.5
CVE-2019-11459

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince thro

5.5
CVE-2019-11833

fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block,

5.5
CVE-2019-9824

tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leadin

5.5
CVE-2019-2004

In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized da

5.5
CVE-2019-2104

In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. T

5.5
CVE-2019-2118

In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables. These could lead t

5.5
CVE-2019-1010317

WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow

5.5
CVE-2019-1010319

WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow

5.5
CVE-2019-1254

An information disclosure vulnerability exists when Windows Hyper-V writes uninitialized memory to disk, aka 'Windows Hy

5.5
CVE-2019-9369

In Bluetooth, there is a use of uninitialized variable. This could lead to local information disclosure with no addition

5.5
CVE-2019-18786

In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized in rcar_drif_g_fmt_sdr_cap in drivers/media/plat

5.3
CVE-2019-6976

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image d

5.3
CVE-2019-11038

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD exten

5.3
CVE-2019-13117

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumb

5.3
CVE-2019-1010299

The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impac

5.3
CVE-2019-19240

Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect us

4.6
CVE-2019-19535

In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/

4.6
CVE-2019-19947

In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/ne

4.3
CVE-2018-3989

An exploitable kernel memory disclosure vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTE

4.3
CVE-2018-6132

Uninitialized data in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sens

9.8
CVE-2018-5095

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at l

9.8
CVE-2018-14551

The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an uninitialized variable, leading to memory cor

8.8
CVE-2018-6981

VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without E

7.8
CVE-2018-10115

Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memor

Frequently Asked Questions

What is CWE-908?

CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-908?

There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.

How can I protect against CWE-908 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.

Detect CWE-908 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.

Get Started