In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosu
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosu
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosu
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosu
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosu
In libxaac there is a possible information disclosure due to uninitialized data. This could lead to information disclosu
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di
In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information d
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di
In libxaac, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure
In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information d
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di
In libhevc there is a possible information disclosure due to uninitialized data. This could lead to remote information d
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di
In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information di
In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote inform
In libstagefright there is a possible information disclosure due to uninitialized data. This could lead to remote inform
Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sens
HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, H
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because unini
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince thro
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block,
tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leadin
In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized da
In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. T
In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables. These could lead t
WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow
WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow
An information disclosure vulnerability exists when Windows Hyper-V writes uninitialized memory to disk, aka 'Windows Hy
In Bluetooth, there is a use of uninitialized variable. This could lead to local information disclosure with no addition
In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized in rcar_drif_g_fmt_sdr_cap in drivers/media/plat
libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image d
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD exten
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumb
The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impac
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect us
In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/
In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/ne
An exploitable kernel memory disclosure vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTE
Uninitialized data in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sens
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at l
The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an uninitialized variable, leading to memory cor
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without E
Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memor
Frequently Asked Questions
What is CWE-908?
CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-908?
There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.
How can I protect against CWE-908 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.
Detect CWE-908 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.
Get Started