FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video de
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decaps
Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read mem
Uninitialized resource in Video in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside
Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potenti
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain
Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read mem
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised th
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside
Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtai
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use
A vulnerability was found in vLLM up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v
The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Check for the presence of LS_NLA_TYPE_DG
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - zero initialize memory allocated v
In the Linux kernel, the following vulnerability has been resolved: um: init cpu_tasks[] earlier This is currently don
In the Linux kernel, the following vulnerability has been resolved: block: zero non-PI portion of auto integrity buffer
In the Linux kernel, the following vulnerability has been resolved: interconnect: debugfs: initialize src_node and dst_
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix oops due to uninitialised var in s
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix error handling in slot reset If th
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix use of uninitializ
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: fix uninitialized padding
In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Initialize free_qp completion before us
In the Linux kernel, the following vulnerability has been resolved: bnge: return after auxiliary_device_uninit() in err
In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_api: fix tc_chain_fill_node to init
In the Linux kernel, the following vulnerability has been resolved: net: use skb_header_pointer() for TCPv4 GSO frag_of
In the Linux kernel, the following vulnerability has been resolved: mfd: macsmc: Initialize mutex Initialize struct ap
In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: initialise event handler read bytes IP
In the Linux kernel, the following vulnerability has been resolved: ext4: move ext4_percpu_param_init() before ext4_mb_
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid uninit-value access in f2fs_sani
In the Linux kernel, the following vulnerability has been resolved: unshare: fix unshare_fs() handling There's an unpl
In the Linux kernel, the following vulnerability has been resolved: fs: init flags_valid before calling vfs_fileattr_ge
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix bpf_xdp_store_bytes proto for read-only ar
In the Linux kernel, the following vulnerability has been resolved: net: rtnetlink: zero ifla_vf_broadcast to avoid sta
In the Linux kernel, the following vulnerability has been resolved: smb: client: use kzalloc to zero-initialize securit
In the Linux kernel, the following vulnerability has been resolved: usb: usblp: fix uninitialized heap leak via LPGETST
In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix uninit-value by validating catalog rec
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: validate rx pkt_type header l
In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/timer-sp804: Fix an Oops when r
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locall
In the Linux kernel, the following vulnerability has been resolved: netdevsim: zero initialize struct iphdr in dummy sk
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: prevent uninitialized lcn caused by zero
In the Linux kernel, the following vulnerability has been resolved: net: hamradio: 6pack: fix uninit-value in sixpack_r
In the Linux kernel, the following vulnerability has been resolved: drm/xe/display: fix oops in suspend/shutdown withou
In the Linux kernel, the following vulnerability has been resolved: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_exthdr: fix register tracking for F_
In the Linux kernel, the following vulnerability has been resolved: rseq: Fix using an uninitialized stack variable in
In the Linux kernel, the following vulnerability has been resolved: fuse: fix uninit-value in fuse_dentry_revalidate()
In the Linux kernel, the following vulnerability has been resolved: pinctrl: mcp23s08: Initialize mcp->dev and mcp->add
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS D
Frequently Asked Questions
What is CWE-908?
CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-908?
There are 161 CVE records associated with CWE-908 in our database. Of these, 6 are critical severity, 30 are high severity, and 104 are medium severity.
How can I protect against CWE-908 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.
Detect CWE-908 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.
Get Started