CWE-908: CWE-908

204
Total CVEs
22
Critical
72
High
6.7
Avg CVSS

Yearly Trend

2026
7
2025
85
2024
70
2023
10
2022
3

Top Affected Vendors

1 Linux 117
2 Debian 25
3 Microsoft 24
4 Google 11
5 Mozilla 3
6 Gnu 2
7 Redhat 2
8 Messagepack Rs Project 2
9 Ivanti 1
10 Synchro 1

All CWE-908 CVEs (204)

CVE-2022-49350
5.5

This CVE describes a Linux kernel vulnerability where the mdio_bus_init() function was incorrectly marked with both EXPORT_SYMBOL and __init annotatio...

Feb 26, 2025
CVE-2022-49326
5.5

A kernel panic vulnerability in Linux kernel's rtl818x wireless driver allows denial of service when using rtl8180/rtl8185 wireless cards. The driver ...

Feb 26, 2025
CVE-2022-49235
5.5

This CVE-2022-49235 is an uninitialized memory vulnerability in the Linux kernel's ath9k_htc wireless driver that can leak kernel memory contents to U...

Feb 26, 2025
CVE-2022-49132
5.5

A race condition vulnerability in the Linux kernel's ath11k PCI driver causes a kernel crash when the system enters suspend mode if the driver fails t...

Feb 26, 2025
CVE-2024-57802
5.5

This CVE describes a kernel memory corruption vulnerability in the Linux kernel's NetRom protocol implementation where insufficient buffer length vali...

Jan 15, 2025
CVE-2024-56769
5.5

This CVE describes an uninitialized memory vulnerability in the Linux kernel's DVB frontend driver for dib3000mb devices. When i2c_transfer() fails, u...

Jan 6, 2025
CVE-2024-56739
5.5

A Linux kernel vulnerability in the RTC subsystem where a failed __rtc_read_time call leads to uninitialized data being processed, potentially causing...

Dec 29, 2024
CVE-2024-56677
5.5

A Linux kernel vulnerability in the PowerPC fadump (firmware-assisted dump) feature causes improper memory alignment during CMA (Contiguous Memory All...

Dec 28, 2024
CVE-2024-56648
5.5

This vulnerability in the Linux kernel's HSR (High-availability Seamless Redundancy) protocol implementation allows an attacker to trigger an out-of-b...

Dec 27, 2024
CVE-2024-56630
5.5

A memory leak vulnerability in the Linux kernel's OCFS2 filesystem driver occurs when dquot_initialize() fails after new_inode() succeeds, causing bus...

Dec 27, 2024
CVE-2018-9377
5.5

This vulnerability in Android's ActivityManagerService allows malicious apps to access user metadata through a pending intent flaw. It enables local p...

Nov 28, 2024
CVE-2018-9420
5.5

CVE-2018-9420 is an information disclosure vulnerability in Android's camera service that allows local attackers to read uninitialized memory. This co...

Nov 19, 2024
CVE-2018-9345
5.5

This vulnerability in Android's AudioPolicyService allows local attackers to read uninitialized memory, potentially exposing sensitive information. It...

Nov 19, 2024
CVE-2024-50299
5.5

A vulnerability in the Linux kernel's SCTP protocol implementation allows attackers to cause a kernel crash (denial of service) by sending specially c...

Nov 19, 2024
CVE-2024-50273
5.5

A use-after-free vulnerability in the Linux kernel's Btrfs filesystem occurs when deleting delayed references without properly reinitializing the list...

Nov 19, 2024
CVE-2024-50110
5.5

This CVE-2024-50110 is a kernel information leak vulnerability in the Linux kernel's xfrm subsystem where uninitialized memory containing potentially ...

Nov 5, 2024
CVE-2024-46784
5.5

A race condition in the Linux kernel's Microsoft Azure Network Adapter (MANA) driver causes kernel panic when network queue cleanup occurs before NAPI...

Sep 18, 2024
CVE-2024-38256
5.5

This Windows kernel-mode driver vulnerability allows attackers to read sensitive kernel memory information. It affects Windows systems with the vulner...

Sep 10, 2024
CVE-2024-45005
5.5

A vulnerability in the Linux kernel's KVM subsystem for s390 architecture allows a guest VM to trigger a host kernel warning when GISA (Guest Informat...

Sep 4, 2024
CVE-2024-42311
5.5

This CVE describes an uninitialized memory vulnerability in the Linux kernel's HFS filesystem driver. When creating HFS inodes, certain fields in the ...

Aug 17, 2024
CVE-2024-38122
5.5

This vulnerability in Microsoft's Local Security Authority (LSA) server allows authenticated attackers to disclose sensitive information from system m...

Aug 13, 2024
CVE-2024-38118
5.5

This vulnerability in Microsoft's Local Security Authority (LSA) Server allows an authenticated attacker to read sensitive information from memory. It...

Aug 13, 2024
CVE-2024-42129
5.5

This CVE describes a use-after-free vulnerability in the Linux kernel's mlxreg LED driver. When the driver module is removed, a mutex is destroyed whi...

Jul 30, 2024
CVE-2024-42106
5.5

This CVE describes an uninitialized memory access vulnerability in the Linux kernel's inet_diag subsystem. When converting between diagnostic request ...

Jul 30, 2024
CVE-2024-42096
5.5

This CVE describes a kernel memory access vulnerability in the Linux kernel's profile_pc() function that improperly accesses stack memory. It affects ...

Jul 29, 2024
CVE-2024-42076
5.5

This CVE describes a kernel information leak vulnerability in the Linux kernel's J1939 CAN bus subsystem. The j1939_send_one() function fails to initi...

Jul 29, 2024
CVE-2022-48864
5.5

This CVE addresses a vulnerability in the Linux kernel's vDPA (Virtual Data Path Acceleration) mlx5 driver where insufficient validation of VIRTIO_NET...

Jul 16, 2024
CVE-2022-48807
5.5

A kernel memory corruption vulnerability in the Linux kernel's Intel Ethernet Controller ice driver allows attackers to trigger a KASAN stack-out-of-b...

Jul 16, 2024
CVE-2024-40998
5.5

This CVE describes a race condition vulnerability in the Linux kernel's ext4 filesystem driver where uninitialized lock state can be accessed during s...

Jul 12, 2024
CVE-2024-40926
5.5

A vulnerability in the Linux kernel's Nouveau graphics driver causes a kernel panic when attempting to schedule hotplug detection work on headless gra...

Jul 12, 2024
CVE-2024-40931
5.5

This CVE addresses an uninitialized variable vulnerability in the Linux kernel's MPTCP (Multipath TCP) implementation. Attackers could potentially tri...

Jul 12, 2024
CVE-2024-38619
5.5

This vulnerability in the Linux kernel's usb-storage alauda driver could cause a divide-by-zero error when accessing uninitialized USB storage media. ...

Jun 20, 2024
CVE-2024-36933
5.5

A vulnerability in the Linux kernel's NSH (Network Service Header) GSO segmentation handler could cause kernel memory corruption when processing speci...

May 30, 2024
CVE-2024-36900
5.5

A race condition vulnerability in the Linux kernel's HNS3 network driver allows kernel crashes when devlink reload operations occur during hardware in...

May 30, 2024
CVE-2024-36021
5.5

A race condition vulnerability in the Linux kernel's HNS3 network driver allows kernel crashes when devlink reload commands are issued during PF (Phys...

May 30, 2024
CVE-2021-47462
5.5

This CVE describes a Linux kernel memory policy vulnerability where mbind() allows illegal combinations of MPOL_F_NUMA_BALANCING and MPOL_LOCAL flags,...

May 22, 2024
CVE-2021-47451
5.5

A kernel panic vulnerability in the Linux kernel's netfilter xt_IDLETIMER module occurs when adding IDLETIMER rules with uninitialized timer_type valu...

May 22, 2024
CVE-2023-52703
5.5

This CVE involves an uninitialized variable being passed to error handling code in the Linux kernel's Kalmia USB network driver. The vulnerability cou...

May 21, 2024
CVE-2021-47424
5.5

This vulnerability in the Linux kernel's i40e network driver causes a kernel Oops (crash) when driver initialization fails, leading to an attempt to f...

May 21, 2024
CVE-2021-47297
5.5

This vulnerability in the Linux kernel's CAIF socket implementation allows reading uninitialized stack memory when sending messages with zero segments...

May 21, 2024
CVE-2024-35973
5.5

A vulnerability in the Linux kernel's GENEVE (Generic Network Virtualization Encapsulation) implementation allows uninitialized memory access when pro...

May 20, 2024
CVE-2024-35915
5.5

A vulnerability in the Linux kernel's NFC (Near Field Communication) subsystem allows reading uninitialized memory when processing packets with zero-l...

May 19, 2024
CVE-2024-35888
5.5

A Linux kernel vulnerability in ERSPAN (Encapsulated Remote SPAN) packet processing allows attackers to trigger kernel memory corruption by sending sp...

May 19, 2024
CVE-2024-27431
5.5

This CVE describes an information disclosure vulnerability in the Linux kernel's cpumap XDP (eXpress Data Path) subsystem. When XDP programs run on cp...

May 17, 2024
CVE-2021-34999
5.5

This vulnerability in OpenBSD's kernel multicast routing implementation allows local attackers to read uninitialized kernel memory, potentially disclo...

May 7, 2024
CVE-2024-26973
5.5

This vulnerability in the Linux kernel's FAT filesystem driver leaks uninitialized memory when generating file handles without parent directories. It ...

May 1, 2024
CVE-2018-20029
5.5

This vulnerability in NoMachine's DokanFS library allows local users on Windows 10 systems to cause a Blue Screen of Death (BSOD) denial of service by...

Dec 10, 2018
CVE-2025-27810
5.4

This vulnerability in Mbed TLS occurs when memory allocation fails or hardware errors happen, causing the library to use uninitialized stack memory wh...

Mar 25, 2025
CVE-2025-26803
5.3

A vulnerability in Phusion Passenger's HTTP parser allows denial of service attacks when processing requests with invalid HTTP methods. This affects w...

Feb 24, 2025
CVE-2024-36454
5.3

A use of uninitialized resource vulnerability in Fujitsu IPCOM EX2 and VE2 series network devices allows attackers to cause denial of service by sendi...

Jun 12, 2024

About CWE-908 (CWE-908)

Our database tracks 204 CVEs classified as CWE-908, with 22 rated critical and 72 rated high severity. The average CVSS score for CWE-908 vulnerabilities is 6.7.

External reference: View CWE-908 on MITRE CWE →

Monitor CWE-908 Vulnerabilities

Get alerted when new CWE-908 CVEs affect your infrastructure.

Start Monitoring Free