Skip to main content

CWE archive

CWE-908 CVEs

Programmatic archive

810 CVEs tagged with CWE-90880 Critical, 216 High, 484 Medium, 30 Low, 0 Unrated.

CVE-2024-53155

Published Dec 24, 2024

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix uninitialized value in ocfs2_file_read_iter() Syzbot has reported the following KMSAN splat: BUG:…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11364

Published Dec 19, 2024

Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software t…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47540

Published Dec 12, 2024

GStreamer is a library for constructing graphs of media-handling components. An uninitialized stack variable vulnerability has been identified in the gst_matroska_demux_add_wvpk_h…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-11991

Published Dec 9, 2024

Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of write barriers in a few locations. This vulnerability could po…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9429

Published Dec 2, 2024

In buildImageItemsIfPossible of ItemTable.cpp there is a possible out of bound read due to uninitialized data. This could lead to information disclosure with no additional executi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9381

Published Dec 2, 2024

In gatts_process_read_by_type_req of gatt_sr.c, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no addi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9377

Published Nov 28, 2024

In getIntentForIntentSender of ActivityManagerService.java, there is a possible way to access user metadata due to a pending intent. This could lead to local escalation of privile…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53101

Published Nov 25, 2024

In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized value issue in from_kuid and from_kgid ocfs2_setattr() uses attr->ia_mode, attr->ia_uid…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9717

Published Nov 22, 2024

Trimble SketchUp Viewer SKP File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9421

Published Nov 19, 2024

In writeInplace of Parcel.cpp, there is a possible information leak across processes, using Binder, due to uninitialized data. This could lead to local information disclosure with…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9420

Published Nov 19, 2024

In BnCameraService::onTransact of CameraService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9346

Published Nov 19, 2024

In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosur…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9345

Published Nov 19, 2024

In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosur…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53083

Published Nov 19, 2024

In the Linux kernel, the following vulnerability has been resolved: usb: typec: qcom-pmic: init value of hdr_len/txbuf_len earlier If the read of USB_PDPHY_RX_ACKNOWLEDGE_REG fa…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53066

Published Nov 19, 2024

In the Linux kernel, the following vulnerability has been resolved: nfs: Fix KMSAN warning in decode_getfattr_attrs() Fix the following KMSAN warning: CPU: 1 UID: 0 PID: 7651 C…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50300

Published Nov 19, 2024

In the Linux kernel, the following vulnerability has been resolved: regulator: rtq2208: Fix uninitialized use of regulator_config Fix rtq2208 driver uninitialized use to cause k…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50299

Published Nov 19, 2024

In the Linux kernel, the following vulnerability has been resolved: sctp: properly validate chunk size in sctp_sf_ootb() A size validation fix similar to that in Commit 50619dbf…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50273

Published Nov 19, 2024

In the Linux kernel, the following vulnerability has been resolved: btrfs: reinitialize delayed ref list after deleting it from the list At insert_delayed_ref() if we need to up…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50241

Published Nov 9, 2024

In the Linux kernel, the following vulnerability has been resolved: NFSD: Initialize struct nfsd4_copy earlier Ensure the refcount and async_copies fields are initialized early.…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50237

Published Nov 9, 2024

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: do not pass a stopped vif to the driver in .get_txpower Avoid potentially crashing in the dri…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50173

Published Nov 8, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix access to uninitialized variable in tick_ctx_cleanup() The group variable can't be used to r…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 810 CVEsPage 12 of 33