Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose informatio
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose informatio
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov8856: free control handler on error i
In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix initialization of tags of the hu
In the Linux kernel, the following vulnerability has been resolved: device property: set fwnode->secondary to NULL in f
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na
FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information loc
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did n
The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first
To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer
A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reacha
Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This coul
rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remot
In the Linux kernel, the following vulnerability has been resolved: leds: led-class: Only Add LED to leds_list when it
Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with
FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose
A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This
ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is v
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by h
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion pictu
Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engi
Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read me
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass
7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain an uninitialized heap read i
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could
The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for
When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index
Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromi
Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reacha
Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a unini
Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return inva
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c wh
Frequently Asked Questions
What is CWE-908?
CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-908?
There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.
How can I protect against CWE-908 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.
Detect CWE-908 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.
Get Started