In the Linux kernel, the following vulnerability has been resolved: efi: libstub: only free priv.runtime_map when alloc
A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitiali
A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to unini
In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix uninit-value in copy_name [syzbot rep
In the Linux kernel, the following vulnerability has been resolved: sched: act_ct: take care of padding in struct zones
In the Linux kernel, the following vulnerability has been resolved: hfs: fix to initialize fields of hfs_inode_info aft
In the Linux kernel, the following vulnerability has been resolved: udf: Fix bogus checksum computation in udf_rename()
Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate use
A maliciously crafted DXF file when parsed in acdb25.dll through Autodesk AutoCAD can force to access a variable prior t
In the Linux kernel, the following vulnerability has been resolved: udf: fix uninit-value use in udf_get_fileshortad C
In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix access to uninitialized variable i
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: do not pass a stopped vif to the dr
Microsoft Excel Remote Code Execution Vulnerability
In the Linux kernel, the following vulnerability has been resolved: btrfs: reinitialize delayed ref list after deleting
In the Linux kernel, the following vulnerability has been resolved: regulator: rtq2208: Fix uninitialized use of regula
PDF-XChange Editor RTF File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allow
Trimble SketchUp Viewer SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability
In the Linux kernel, the following vulnerability has been resolved: powerpc/fadump: Move fadump_cma_init to setup_arch(
Windows Networking Information Disclosure Vulnerability
When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management M
Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerab
Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the cur
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, a
In the Linux kernel, the following vulnerability has been resolved: block: Fix wrong offset in bio_truncate() bio_trun
Windows TCP/IP Information Disclosure Vulnerability
Microsoft AllJoyn API Information Disclosure Vulnerability
In the Linux kernel, the following vulnerability has been resolved: NFSD: Initialize struct nfsd4_copy earlier Ensure
In gatts_process_read_by_type_req of gatt_sr.c, there is a possible information disclosure due to uninitialized data. Th
In the Linux kernel, the following vulnerability has been resolved: geneve: make sure to pull inner header in geneve_rx
In the Linux kernel, the following vulnerability has been resolved: erspan: make sure erspan_base_hdr is present in skb
Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect
In the Linux kernel, the following vulnerability has been resolved: net: bridge: xmit: make sure we have at least eth h
Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow
In the Linux kernel, the following vulnerability has been resolved: asix: fix uninit-value in asix_mdio_read() asix_re
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix possible bogus match
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix information leak in btrfs_ioctl_logical_
In the Linux kernel, the following vulnerability has been resolved: virtio/vsock: Fix uninit-value in virtio_transport_
In the Linux kernel, the following vulnerability has been resolved: tipc: Change nla_policy for bearer-related names to
In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: fix uninitialised kfifo If a line i
In the Linux kernel, the following vulnerability has been resolved: crypto: mxs-dcp - Ensure payload is zero when using
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: validate vlan header Ensure
In the Linux kernel, the following vulnerability has been resolved: gtp: pull network headers in gtp_dev_xmit() syzbot
Windows Kernel Elevation of Privilege Vulnerability
In the Linux kernel, the following vulnerability has been resolved: jfs: Fix uninit-value access of new_ea in ea_buffer
In the Linux kernel, the following vulnerability has been resolved: ppp: fix ppp_async_encode() illegal access syzbot
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix uninitialized value in ocfs2_file_read_i
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash problem in concurrent s
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Using uninitialized value *size when ca
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.20), CP-8050 MASTER MODULE (All
ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak s
Frequently Asked Questions
What is CWE-908?
CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-908?
There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.
How can I protect against CWE-908 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.
Detect CWE-908 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.
Get Started