Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin
Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the
Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the
Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Update read pointer only after buffer
In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix free of uninitialized nfs4_label on refe
In the Linux kernel, the following vulnerability has been resolved: mptcp: consolidate suboption status MPTCP maintain
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: Initialize ctx to avoid
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: fix crash due to removal o
Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a net
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix oops due to uninitialised variable Fix s
In the Linux kernel, the following vulnerability has been resolved: 9p: set req refcount to zero to avoid uninitialized
In the Linux kernel, the following vulnerability has been resolved: netrom: check buffer length before accessing it Sy
In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix channel survey memory allocation
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix uninitialized memcache pointer in u
In the Linux kernel, the following vulnerability has been resolved: nvmet: pci-epf: Do not complete commands twice if n
A privilege escalation vulnerability exists in the ControlVault WBDI Driver WBIO_USH_ADD_RECORD functionality of Dell Co
A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to
In the Linux kernel, the following vulnerability has been resolved: pptp: ensure minimal skb length in pptp_xmit() Com
In the Linux kernel, the following vulnerability has been resolved: bpf, ktls: Fix data corruption when using bpf_msg_p
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize allocated memory before use K
Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix crash when mount with quota enabled The
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnera
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnera
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnera
In the Linux kernel, the following vulnerability has been resolved: sched_ext: bpf_iter_scx_dsq_new() should always ini
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix iteration of extrefs during log replay
In the Linux kernel, the following vulnerability has been resolved: comedi: Fix initialization of data for instructions
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix KMSAN uninit-value in extent_info usage
In the Linux kernel, the following vulnerability has been resolved: sctp: linearize cloned gso packets in sctp_rcv A c
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Set merge to zero early in af_alg_
In the Linux kernel, the following vulnerability has been resolved: net: qrtr: Fix an uninit variable access bug in qrt
In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninititialized value in 'ext4_evict_inod
Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privi
A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uni
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to m
Microsoft Message Queuing Information Disclosure Vulnerability
Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilitie
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual serv
Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.
A Use of Uninitialized Resource vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX4
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1119: fix information leak in trigg
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads8688: fix information leak in trigg
Frequently Asked Questions
What is CWE-908?
CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-908?
There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.
How can I protect against CWE-908 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.
Detect CWE-908 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.
Get Started