CWE-909: CWE-909

12
Total CVEs
1
Critical
8
High
7.3
Avg CVSS

Yearly Trend

2025
6
2024
1
2022
1
2021
4

Top Affected Vendors

1 Linux 4
2 Mozilla 2
3 Zabbix 1
4 Debian 1
5 Widzialni 1
6 Mobyproject 1
7 Signalwire 1
8 Dns Packet Project 1

All CWE-909 CVEs (12)

CVE-2022-22704
9.8

CVE-2022-22704 is a privilege escalation vulnerability in zabbix-agent2 on Alpine Linux that allows local users to gain root privileges. The vulnerabi...

Jan 6, 2022
CVE-2021-29980
8.8

This vulnerability involves uninitialized memory in a canvas object in Mozilla Thunderbird and Firefox, which could lead to incorrect memory deallocat...

Aug 17, 2021
CVE-2021-23994
8.8

This vulnerability allows attackers to exploit uninitialized WebGL framebuffers in Mozilla browsers, leading to memory corruption and potential arbitr...

Jun 24, 2021
CVE-2024-43873
7.8

This CVE addresses an uninitialized variable vulnerability in the Linux kernel's vhost/vsock subsystem. The seqpacket_allow variable is not properly i...

Aug 21, 2024
CVE-2021-23386
7.7

CVE-2021-23386 is a memory disclosure vulnerability in the dns-packet npm package where uninitialized buffers can leak internal application memory ove...

May 20, 2021
CVE-2025-8117
7.5

CVE-2025-8117 is an authentication bypass vulnerability in PAD CMS where improper initialization of password recovery parameters allows attackers to r...

Sep 30, 2025
CVE-2021-36513
7.5

This vulnerability in SignalWire FreeSWITCH allows attackers to view sensitive information due to an uninitialized value in the sofia_handle_sip_i_not...

Oct 18, 2021
CVE-2022-49865
7.1

This CVE describes an information leak vulnerability in the Linux kernel's IPv6 address label implementation. When sending network messages containing...

May 1, 2025
CVE-2024-52870
7.1

Teradata Vantage Editor 1.0.1 contains unintended functionality that allows client users to access arbitrary remote websites through Chromium Develope...

Jan 17, 2025
CVE-2025-38601
5.5

A use-after-free vulnerability in the Linux kernel's ath11k WiFi driver allows kernel memory corruption when the driver fails to properly clear initia...

Aug 19, 2025
CVE-2025-38532
5.5

A Linux kernel vulnerability in the libwx network driver allows kernel panics when device resets occur due to feature changes like toggling Rx VLAN of...

Aug 16, 2025
CVE-2025-54388
4.6

This vulnerability in Moby/Docker Engine allows containers with ports published only to localhost (127.0.0.1) to become remotely accessible after fire...

Jul 30, 2025

About CWE-909 (CWE-909)

Our database tracks 12 CVEs classified as CWE-909, with 1 rated critical and 8 rated high severity. The average CVSS score for CWE-909 vulnerabilities is 7.3.

External reference: View CWE-909 on MITRE CWE →

Monitor CWE-909 Vulnerabilities

Get alerted when new CWE-909 CVEs affect your infrastructure.

Start Monitoring Free