Skip to main content

CWE archive

CWE-908 CVEs

Programmatic archive

810 CVEs tagged with CWE-90880 Critical, 216 High, 484 Medium, 30 Low, 0 Unrated.

CVE-2024-44999

Published Sep 4, 2024

In the Linux kernel, the following vulnerability has been resolved: gtp: pull network headers in gtp_dev_xmit() syzbot/KMSAN reported use of uninit-value in get_dev_xmit() [1]…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-44983

Published Sep 4, 2024

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: validate vlan header Ensure there is sufficient room to access the protocol field of th…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43845

Published Aug 17, 2024

In the Linux kernel, the following vulnerability has been resolved: udf: Fix bogus checksum computation in udf_rename() Syzbot reports uninitialized memory access in udf_rename(…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-43815

Published Aug 17, 2024

In the Linux kernel, the following vulnerability has been resolved: crypto: mxs-dcp - Ensure payload is zero when using key slot We could leak stack memory through the payload f…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42312

Published Aug 17, 2024

In the Linux kernel, the following vulnerability has been resolved: sysctl: always initialize i_uid/i_gid Always initialize i_uid/i_gid inside the sysfs core so set_ownership()…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42311

Published Aug 17, 2024

In the Linux kernel, the following vulnerability has been resolved: hfs: fix to initialize fields of hfs_inode_info after hfs_alloc_inode() Syzbot reports uninitialized value ac…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42283

Published Aug 17, 2024

In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Initialize all fields in dumped nexthops struct nexthop_grp contains two reserved fields that a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42272

Published Aug 17, 2024

In the Linux kernel, the following vulnerability has been resolved: sched: act_ct: take care of padding in struct zones_ht_key Blamed commit increased lookup key size from 2 byt…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7868

Published Aug 15, 2024

In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault at…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-7542

Published Aug 6, 2024

oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installa…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-7541

Published Aug 6, 2024

oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installat…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-7540

Published Aug 6, 2024

oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installa…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-6990

Published Aug 1, 2024

Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-42228

Published Jul 30, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc Initialize the size before calli…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42225

Published Jul 30, 2024

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42161

Published Jul 30, 2024

In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid uninitialized value in BPF_CORE_READ_BITFIELD [Changes from V1: - Use a default branch in the swi…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42129

Published Jul 30, 2024

In the Linux kernel, the following vulnerability has been resolved: leds: mlxreg: Use devm_mutex_init() for mutex initialization In this driver LEDs are registered using devm_le…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 810 CVEsPage 14 of 33