Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-908

MITRE ↗

CWE-908

67
CRITICAL
244
HIGH
469
MEDIUM
30
LOW
821 CVEs · Page 3/17
5.5
CVE-2026-40422

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

5.5
CVE-2026-49801

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

5.5
CVE-2026-54997

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

5.5
CVE-2026-50455

Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose informatio

5.5
CVE-2026-50690

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

5.5
CVE-2026-55042

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-57083

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose informatio

5.5
CVE-2026-57084

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-53379

In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov8856: free control handler on error i

5.5
CVE-2026-64130

In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix initialization of tags of the hu

5.5
CVE-2026-64220

In the Linux kernel, the following vulnerability has been resolved: device property: set fwnode->secondary to NULL in f

5.5
CVE-2026-70629

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na

5.5
CVE-2026-70630

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na

5.5
CVE-2026-70631

FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in

5.5
CVE-2026-59136

Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally

5.5
CVE-2026-59137

Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information loc

5.5
CVE-2026-62709

Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

5.5
CVE-2026-62740

Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally

5.5
CVE-2026-68799

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-70317

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-49424

The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did n

5.5
CVE-2026-49425

The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first

5.5
CVE-2026-58084

To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer

5.3
CVE-2026-26825

A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reacha

5.3
CVE-2026-54500

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load

5.3
CVE-2026-53467

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-

5.3
CVE-2026-58247

SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This coul

5.3
CVE-2026-70459

rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remot

4.7
CVE-2026-23101

In the Linux kernel, the following vulnerability has been resolved: leds: led-class: Only Add LED to leds_list when it

4.6
CVE-2026-26175

Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with

4.6
CVE-2026-6686

FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-

4.4
CVE-2026-20962

Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose

4.4
CVE-2025-12474

A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This

4.4
CVE-2026-45736

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is v

4.3
CVE-2026-62377

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by h

4.3
CVE-2026-62986

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion pictu

4.3
CVE-2026-78962

Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engi

4.3
CVE-2026-79040

Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read me

4.3
CVE-2026-79269

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass

4.2
CVE-2026-48104

7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain an uninitialized heap read i

3.7
CVE-2026-56968

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could

3.7
CVE-2026-11809

The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z

3.3
CVE-2026-56085

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r

3.3
CVE-2026-68744

A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for

3.3
CVE-2026-49423

When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index

3.1
CVE-2026-76042

Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromi

CVE-2026-24826

Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reacha

CVE-2025-48513

Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a unini

CVE-2026-6368

Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return inva

CVE-2026-63381

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c wh

Frequently Asked Questions

What is CWE-908?

CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-908?

There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.

How can I protect against CWE-908 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.

Detect CWE-908 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.

Get Started