CWE-908: CWE-908

203
Total CVEs
22
Critical
71
High
6.7
Avg CVSS

Yearly Trend

2026
7
2025
85
2024
70
2023
10
2022
3

Top Affected Vendors

1 Linux 117
2 Debian 25
3 Microsoft 24
4 Google 11
5 Mozilla 3
6 Gnu 2
7 Redhat 2
8 Messagepack Rs Project 2
9 Ivanti 1
10 Synchro 1

All CWE-908 CVEs (203)

CVE-2021-32845
7.7

This vulnerability in HyperKit allows a malicious guest virtual machine to crash the host system, causing denial of service. Under certain conditions,...

Feb 17, 2023
CVE-2022-23573
7.6

This vulnerability in TensorFlow's AssignOp implementation allows copying uninitialized data to new tensors, leading to undefined behavior. It affects...

Feb 4, 2022
CVE-2026-2794
7.5

This vulnerability allows attackers to read uninitialized memory in Firefox and Firefox Focus for Android, potentially exposing sensitive information....

Feb 24, 2026
CVE-2025-15281
7.5

A memory corruption vulnerability in GNU C Library's wordexp function when using WRDE_REUSE with WRDE_APPEND flags can return uninitialized memory. Th...

Jan 20, 2026
CVE-2026-0915
7.5

This vulnerability in GNU C Library (glibc) allows stack memory contents to be leaked to DNS resolvers when getnetbyaddr functions query for a zero-va...

Jan 15, 2026
CVE-2025-59964
7.5

An uninitialized resource vulnerability in Juniper SRX4700 devices with forwarding-options sampling enabled allows unauthenticated network attackers t...

Oct 9, 2025
CVE-2025-49718
7.5

This vulnerability in SQL Server involves improper initialization of resources, allowing unauthorized attackers to read uninitialized memory contents ...

Jul 8, 2025
CVE-2023-37930
7.5

This CVE describes memory corruption vulnerabilities in Fortinet VPN products that could allow authenticated VPN users to execute arbitrary code or co...

Apr 8, 2025
CVE-2025-21220
7.5

Microsoft Message Queuing (MSMQ) contains an information disclosure vulnerability that allows authenticated attackers to read sensitive data from memo...

Jan 14, 2025
CVE-2024-12085
EPSS 13% 7.5

This vulnerability in rsync allows attackers to leak uninitialized stack memory one byte at a time by manipulating checksum length during file compari...

Jan 14, 2025
CVE-2018-9381
7.5

This vulnerability in Android's Bluetooth GATT server allows remote attackers to read uninitialized memory from affected devices without user interact...

Dec 2, 2024
CVE-2024-38257
7.5

This vulnerability in Microsoft's AllJoyn API allows attackers to read sensitive information from memory without proper authorization. It affects syst...

Sep 10, 2024
CVE-2024-42225
7.5

This CVE addresses an information disclosure vulnerability in the Linux kernel's MediaTek MT76 WiFi driver. The vulnerability could allow attackers to...

Jul 30, 2024
CVE-2024-38064
7.5

CVE-2024-38064 is a Windows TCP/IP information disclosure vulnerability that allows attackers to read sensitive memory contents from affected systems....

Jul 9, 2024
CVE-2022-48747
7.5

A vulnerability in the Linux kernel's bio_truncate() function could allow reading uninitialized data from block devices. This occurs when both a corru...

Jun 20, 2024
CVE-2024-23314
7.5

This vulnerability affects F5 BIG-IP and BIG-IP Next SPK systems with HTTP/2 configured. Undisclosed HTTP/2 responses can cause the Traffic Management...

Feb 14, 2024
CVE-2023-21233
7.5

This vulnerability in Android's AVRCP (Audio/Video Remote Control Profile) implementation allows uninitialized heap memory to be leaked to remote Blue...

Aug 14, 2023
CVE-2023-35325
7.5

This vulnerability in Windows Print Spooler allows attackers to read sensitive information from memory without authentication. It affects Windows syst...

Jul 11, 2023
CVE-2023-35847
7.5

CVE-2023-35847 is a vulnerability in VirtualSquare picoTCP (PicoTCP-NG) where the TCP implementation lacks a minimum MSS (Maximum Segment Size) value,...

Jun 19, 2023
CVE-2021-45694
7.5

This vulnerability in the rdiff crate for Rust allows reading from uninitialized memory locations, potentially exposing sensitive data or causing cras...

Dec 27, 2021
CVE-2021-36512
7.5

This vulnerability in Synchronet BBS allows attackers to view sensitive information due to an uninitialized value in the scanallsubs function. Attacke...

Oct 19, 2021
CVE-2021-28029
7.5

This vulnerability in the toodee Rust crate allows attackers to read uninitialized memory contents through the row-insertion feature. This affects any...

Mar 5, 2021
CVE-2021-43848
7.4

This vulnerability in h2o HTTP server allows attackers to read uninitialized memory when HTTP/3 is enabled, potentially exposing internal server state...

Feb 1, 2022
CVE-2024-57909
7.1

This CVE-2024-57909 is an information leak vulnerability in the Linux kernel's BH1745 light sensor driver. It allows uninitialized kernel memory to be...

Jan 19, 2025
CVE-2024-57910
7.1

This CVE describes an information leak vulnerability in the Linux kernel's vcnl4035 light sensor driver. When triggered buffer data is sent to userspa...

Jan 19, 2025
CVE-2024-57911
7.1

This CVE describes an information leak vulnerability in the Linux kernel's IIO (Industrial I/O) dummy driver. When triggered buffer data is pushed to ...

Jan 19, 2025
CVE-2024-57912
7.1

This CVE-2024-57912 is an information leak vulnerability in the Linux kernel's zpa2326 pressure sensor driver. When triggered buffer data is sent to u...

Jan 19, 2025
CVE-2024-57905
7.1

This CVE describes an information leak vulnerability in the Linux kernel's TI ADS1119 ADC driver. When triggered buffer data is sent to userspace, uni...

Jan 19, 2025
CVE-2024-57906
7.1

This CVE-2024-57906 is an information leak vulnerability in the Linux kernel's TI ADS8688 ADC driver. When triggered buffer data is sent to userspace,...

Jan 19, 2025
CVE-2024-57907
7.1

This CVE-2024-57907 is an information leak vulnerability in the Linux kernel's Rockchip SARADC driver. It allows uninitialized kernel memory to be exp...

Jan 19, 2025
CVE-2024-57908
7.1

This CVE describes an information leak vulnerability in the Linux kernel's kmx61 IMU driver. When triggered buffer data is sent to userspace, uninitia...

Jan 19, 2025
CVE-2024-53155
7.1

This CVE-2024-53155 is an uninitialized variable vulnerability in the Linux kernel's OCFS2 filesystem driver. It allows attackers to potentially read ...

Dec 24, 2024
CVE-2024-50033
7.1

This vulnerability in the Linux kernel's SLIP (Serial Line Internet Protocol) compression handler allows attackers to trigger uninitialized memory acc...

Oct 21, 2024
CVE-2024-50035
7.1

A vulnerability in the Linux kernel's PPP (Point-to-Point Protocol) implementation allows illegal memory access when processing empty network packets....

Oct 21, 2024
CVE-2024-49900
7.1

This vulnerability in the Linux kernel's JFS filesystem allows attackers to read uninitialized memory from the kernel stack, potentially leaking sensi...

Oct 21, 2024
CVE-2024-46865
7.1

This CVE addresses an uninitialized variable vulnerability in the Linux kernel's FOU (Foo over UDP) module. If exploited, it could lead to kernel memo...

Sep 27, 2024
CVE-2024-44999
7.1

This CVE describes a kernel memory corruption vulnerability in the Linux kernel's GTP (GPRS Tunneling Protocol) implementation. Attackers could exploi...

Sep 4, 2024
CVE-2024-44983
7.1

A vulnerability in the Linux kernel's netfilter flowtable component allows uninitialized memory access when processing VLAN headers. This could lead t...

Sep 4, 2024
CVE-2024-38381
7.1

This vulnerability in the Linux kernel's NFC (Near Field Communication) subsystem allows uninitialized memory access when processing received packets....

Jun 21, 2024
CVE-2023-52842
7.1

This CVE describes an uninitialized memory vulnerability in the Linux kernel's virtio/vsock subsystem. An attacker could exploit this to read uninitia...

May 21, 2024
CVE-2024-35849
7.1

This vulnerability in the Linux kernel's btrfs filesystem allows uninitialized kernel memory to be leaked to user-space via the btrfs_ioctl_logical_to...

May 17, 2024
CVE-2021-47101
7.1

This vulnerability in the Linux kernel's ASIX USB Ethernet driver allows reading uninitialized memory when the asix_mdio_read() function receives less...

Mar 4, 2024
CVE-2024-42228
7.0

This CVE involves an uninitialized variable vulnerability in the AMD GPU driver within the Linux kernel. Attackers could exploit this to cause kernel ...

Jul 30, 2024
CVE-2025-21357
6.7

Microsoft Outlook contains a remote code execution vulnerability that allows attackers to execute arbitrary code on a victim's system by sending a spe...

Jan 14, 2025
CVE-2025-29959
6.5

This vulnerability in Windows Routing and Remote Access Service (RRAS) allows attackers to read uninitialized memory contents, potentially exposing se...

May 13, 2025
CVE-2025-29830
6.5

CVE-2025-29830 is an information disclosure vulnerability in Windows Routing and Remote Access Service (RRAS) where uninitialized memory resources can...

May 13, 2025
CVE-2025-21288
6.5

This vulnerability in Windows COM Server allows attackers to read sensitive information from memory without proper authorization. It affects Windows s...

Jan 14, 2025
CVE-2025-21272
6.5

This vulnerability in Windows COM Server allows attackers to read sensitive information from memory without proper authorization. It affects Windows s...

Jan 14, 2025
CVE-2024-42161
6.3

This CVE addresses an uninitialized variable vulnerability in the Linux kernel's BPF subsystem. The BPF_CORE_READ_BITFIELD macro could use uninitializ...

Jul 30, 2024
CVE-2018-9378
6.2

This vulnerability allows local attackers to read uninitialized memory from the Android audio policy service, potentially exposing sensitive informati...

Jan 28, 2025

About CWE-908 (CWE-908)

Our database tracks 203 CVEs classified as CWE-908, with 22 rated critical and 71 rated high severity. The average CVSS score for CWE-908 vulnerabilities is 6.7.

External reference: View CWE-908 on MITRE CWE →

Monitor CWE-908 Vulnerabilities

Get alerted when new CWE-908 CVEs affect your infrastructure.

Start Monitoring Free