CWE-908: CWE-908
Yearly Trend
Top Affected Vendors
All CWE-908 CVEs (203)
This vulnerability in HyperKit allows a malicious guest virtual machine to crash the host system, causing denial of service. Under certain conditions,...
Feb 17, 2023This vulnerability in TensorFlow's AssignOp implementation allows copying uninitialized data to new tensors, leading to undefined behavior. It affects...
Feb 4, 2022This vulnerability allows attackers to read uninitialized memory in Firefox and Firefox Focus for Android, potentially exposing sensitive information....
Feb 24, 2026A memory corruption vulnerability in GNU C Library's wordexp function when using WRDE_REUSE with WRDE_APPEND flags can return uninitialized memory. Th...
Jan 20, 2026This vulnerability in GNU C Library (glibc) allows stack memory contents to be leaked to DNS resolvers when getnetbyaddr functions query for a zero-va...
Jan 15, 2026An uninitialized resource vulnerability in Juniper SRX4700 devices with forwarding-options sampling enabled allows unauthenticated network attackers t...
Oct 9, 2025This vulnerability in SQL Server involves improper initialization of resources, allowing unauthorized attackers to read uninitialized memory contents ...
Jul 8, 2025This CVE describes memory corruption vulnerabilities in Fortinet VPN products that could allow authenticated VPN users to execute arbitrary code or co...
Apr 8, 2025Microsoft Message Queuing (MSMQ) contains an information disclosure vulnerability that allows authenticated attackers to read sensitive data from memo...
Jan 14, 2025This vulnerability in rsync allows attackers to leak uninitialized stack memory one byte at a time by manipulating checksum length during file compari...
Jan 14, 2025This vulnerability in Android's Bluetooth GATT server allows remote attackers to read uninitialized memory from affected devices without user interact...
Dec 2, 2024This vulnerability in Microsoft's AllJoyn API allows attackers to read sensitive information from memory without proper authorization. It affects syst...
Sep 10, 2024This CVE addresses an information disclosure vulnerability in the Linux kernel's MediaTek MT76 WiFi driver. The vulnerability could allow attackers to...
Jul 30, 2024CVE-2024-38064 is a Windows TCP/IP information disclosure vulnerability that allows attackers to read sensitive memory contents from affected systems....
Jul 9, 2024A vulnerability in the Linux kernel's bio_truncate() function could allow reading uninitialized data from block devices. This occurs when both a corru...
Jun 20, 2024This vulnerability affects F5 BIG-IP and BIG-IP Next SPK systems with HTTP/2 configured. Undisclosed HTTP/2 responses can cause the Traffic Management...
Feb 14, 2024This vulnerability in Android's AVRCP (Audio/Video Remote Control Profile) implementation allows uninitialized heap memory to be leaked to remote Blue...
Aug 14, 2023This vulnerability in Windows Print Spooler allows attackers to read sensitive information from memory without authentication. It affects Windows syst...
Jul 11, 2023CVE-2023-35847 is a vulnerability in VirtualSquare picoTCP (PicoTCP-NG) where the TCP implementation lacks a minimum MSS (Maximum Segment Size) value,...
Jun 19, 2023This vulnerability in the rdiff crate for Rust allows reading from uninitialized memory locations, potentially exposing sensitive data or causing cras...
Dec 27, 2021This vulnerability in Synchronet BBS allows attackers to view sensitive information due to an uninitialized value in the scanallsubs function. Attacke...
Oct 19, 2021This vulnerability in the toodee Rust crate allows attackers to read uninitialized memory contents through the row-insertion feature. This affects any...
Mar 5, 2021This vulnerability in h2o HTTP server allows attackers to read uninitialized memory when HTTP/3 is enabled, potentially exposing internal server state...
Feb 1, 2022This CVE-2024-57909 is an information leak vulnerability in the Linux kernel's BH1745 light sensor driver. It allows uninitialized kernel memory to be...
Jan 19, 2025This CVE describes an information leak vulnerability in the Linux kernel's vcnl4035 light sensor driver. When triggered buffer data is sent to userspa...
Jan 19, 2025This CVE describes an information leak vulnerability in the Linux kernel's IIO (Industrial I/O) dummy driver. When triggered buffer data is pushed to ...
Jan 19, 2025This CVE-2024-57912 is an information leak vulnerability in the Linux kernel's zpa2326 pressure sensor driver. When triggered buffer data is sent to u...
Jan 19, 2025This CVE describes an information leak vulnerability in the Linux kernel's TI ADS1119 ADC driver. When triggered buffer data is sent to userspace, uni...
Jan 19, 2025This CVE-2024-57906 is an information leak vulnerability in the Linux kernel's TI ADS8688 ADC driver. When triggered buffer data is sent to userspace,...
Jan 19, 2025This CVE-2024-57907 is an information leak vulnerability in the Linux kernel's Rockchip SARADC driver. It allows uninitialized kernel memory to be exp...
Jan 19, 2025This CVE describes an information leak vulnerability in the Linux kernel's kmx61 IMU driver. When triggered buffer data is sent to userspace, uninitia...
Jan 19, 2025This CVE-2024-53155 is an uninitialized variable vulnerability in the Linux kernel's OCFS2 filesystem driver. It allows attackers to potentially read ...
Dec 24, 2024This vulnerability in the Linux kernel's SLIP (Serial Line Internet Protocol) compression handler allows attackers to trigger uninitialized memory acc...
Oct 21, 2024A vulnerability in the Linux kernel's PPP (Point-to-Point Protocol) implementation allows illegal memory access when processing empty network packets....
Oct 21, 2024This vulnerability in the Linux kernel's JFS filesystem allows attackers to read uninitialized memory from the kernel stack, potentially leaking sensi...
Oct 21, 2024This CVE addresses an uninitialized variable vulnerability in the Linux kernel's FOU (Foo over UDP) module. If exploited, it could lead to kernel memo...
Sep 27, 2024This CVE describes a kernel memory corruption vulnerability in the Linux kernel's GTP (GPRS Tunneling Protocol) implementation. Attackers could exploi...
Sep 4, 2024A vulnerability in the Linux kernel's netfilter flowtable component allows uninitialized memory access when processing VLAN headers. This could lead t...
Sep 4, 2024This vulnerability in the Linux kernel's NFC (Near Field Communication) subsystem allows uninitialized memory access when processing received packets....
Jun 21, 2024This CVE describes an uninitialized memory vulnerability in the Linux kernel's virtio/vsock subsystem. An attacker could exploit this to read uninitia...
May 21, 2024This vulnerability in the Linux kernel's btrfs filesystem allows uninitialized kernel memory to be leaked to user-space via the btrfs_ioctl_logical_to...
May 17, 2024This vulnerability in the Linux kernel's ASIX USB Ethernet driver allows reading uninitialized memory when the asix_mdio_read() function receives less...
Mar 4, 2024This CVE involves an uninitialized variable vulnerability in the AMD GPU driver within the Linux kernel. Attackers could exploit this to cause kernel ...
Jul 30, 2024Microsoft Outlook contains a remote code execution vulnerability that allows attackers to execute arbitrary code on a victim's system by sending a spe...
Jan 14, 2025This vulnerability in Windows Routing and Remote Access Service (RRAS) allows attackers to read uninitialized memory contents, potentially exposing se...
May 13, 2025CVE-2025-29830 is an information disclosure vulnerability in Windows Routing and Remote Access Service (RRAS) where uninitialized memory resources can...
May 13, 2025This vulnerability in Windows COM Server allows attackers to read sensitive information from memory without proper authorization. It affects Windows s...
Jan 14, 2025This vulnerability in Windows COM Server allows attackers to read sensitive information from memory without proper authorization. It affects Windows s...
Jan 14, 2025This CVE addresses an uninitialized variable vulnerability in the Linux kernel's BPF subsystem. The BPF_CORE_READ_BITFIELD macro could use uninitializ...
Jul 30, 2024This vulnerability allows local attackers to read uninitialized memory from the Android audio policy service, potentially exposing sensitive informati...
Jan 28, 2025About CWE-908 (CWE-908)
Our database tracks 203 CVEs classified as CWE-908, with 22 rated critical and 71 rated high severity. The average CVSS score for CWE-908 vulnerabilities is 6.7.
External reference: View CWE-908 on MITRE CWE →
Monitor CWE-908 Vulnerabilities
Get alerted when new CWE-908 CVEs affect your infrastructure.
Start Monitoring Free