Windows Mobile Broadband Driver Denial of Service Vulnerability
In buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitialized data. This coul
In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid uninitialized value in BPF_CORE_READ_BIT
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 uses uninitialized variables when deploying that could allow
HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_s
Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of wri
Windows CoreMessaging Information Disclosure Vulnerability
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - ADF_STATUS_PF_RUNNING should be set a
In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc75xx: Fix uninit-value access in __sm
In the Linux kernel, the following vulnerability has been resolved: dccp: fix dccp_v4_err()/dccp_v6_err() again dh->dc
In the Linux kernel, the following vulnerability has been resolved: net: hns3: put off calling register_netdev() until
In the Linux kernel, the following vulnerability has been resolved: btrfs: don't abort filesystem when attempting to sn
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad4130: zero-initialize clock init data
In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-qdma: init irq after reg initializat
In the Linux kernel, the following vulnerability has been resolved: netlink: Fix kernel-infoleak-after-free in __skb_da
there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure wi
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
In the Linux kernel, the following vulnerability has been resolved: netlink: add nla be16/32 types to minlen array BUG
In the Linux kernel, the following vulnerability has been resolved: hsr: Fix uninit-value access in hsr_get_node() KMS
In the Linux kernel, the following vulnerability has been resolved: drm/bridge: adv7511: fix crash on irq during probe
In the Linux kernel, the following vulnerability has been resolved: do_sys_name_to_handle(): use kzalloc() to fix kerne
In the Linux kernel, the following vulnerability has been resolved: fat: fix uninitialized field in nostale filehandles
PDF-XChange Editor PDF File Parsing Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allo
PDF-XChange Editor J2K File Parsing Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allo
PDF-XChange Editor J2K File Parsing Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allo
PDF-XChange Editor U3D File Parsing Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allo
PDF-XChange Editor J2K File Parsing Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allo
OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows lo
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_skbmod: prevent kernel-infoleak syz
In the Linux kernel, the following vulnerability has been resolved: geneve: fix header validation in geneve[6]_xmit_skb
In the Linux kernel, the following vulnerability has been resolved: net: fix uninit-value in caif_seqpkt_sendmsg When
In the Linux kernel, the following vulnerability has been resolved: media: v4l2-core: explicitly clear ioctl input data
In the Linux kernel, the following vulnerability has been resolved: i40e: Fix freeing of uninitialized misc IRQ vector
In the Linux kernel, the following vulnerability has been resolved: net/usb: kalmia: Don't pass act_len in usb_bulk_msg
In the Linux kernel, the following vulnerability has been resolved: cxl/region: Do not try to cleanup after cxl_region_
In the Linux kernel, the following vulnerability has been resolved: llc: verify mac len before reading mac header LLC
In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: do not allow illegal MPOL_F_NUMA_BALA
In the Linux kernel, the following vulnerability has been resolved: vdpa_sim: avoid putting an uninitialized iova_domai
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when devlink reload dur
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when devlink reload dur
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix potential uninit-value access in __ip6_ma
In hwbcc_ns_deprivilege of trusty/user/base/lib/hwbcc/client/hwbcc.c, there is a possible uninitialized stack data discl
In aur_get_state of aurora.c, there is a possible information disclosure due to uninitialized data. This could lead to l
In handle_msg_shm_map_req of trusty/user/base/lib/spi/srv/tipc/tipc.c, there is a possible stack data disclosure due to
In the Linux kernel, the following vulnerability has been resolved: net: micrel: Fix receiving the timestamp in the fra
In the Linux kernel, the following vulnerability has been resolved: media: mxl111sf: change mutex_init() location Syzb
In the Linux kernel, the following vulnerability has been resolved: inet_diag: fix kernel-infoleak for UDP sockets KMS
In the Linux kernel, the following vulnerability has been resolved: usb-storage: alauda: Check whether the media is ini
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l56: Fix lifetime of cs_dsp instance
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: don't attempt to schedule hpd_work on
Frequently Asked Questions
What is CWE-908?
CWE-908 (CWE-908) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-908?
There are 956 CVE records associated with CWE-908 in our database. Of these, 67 are critical severity, 244 are high severity, and 469 are medium severity.
How can I protect against CWE-908 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-908 using AI-powered security agents.
Detect CWE-908 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-908 vulnerabilities across your infrastructure.
Get Started