Skip to main content

CWE archive

CWE-908 CVEs

Programmatic archive

826 CVEs tagged with CWE-90891 Critical, 254 High, 448 Medium, 33 Low, 0 Unrated.

CVE-2022-48807

Published Jul 16, 2024

In the Linux kernel, the following vulnerability has been resolved: ice: Fix KASAN error in LAG NETDEV_UNREGISTER handler Currently, the same handler is called for both a NETDEV…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40998

Published Jul 12, 2024

In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninitialized ratelimit_state->lock access in __ext4_fill_super() In the following concurrency we w…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40931

Published Jul 12, 2024

In the Linux kernel, the following vulnerability has been resolved: mptcp: ensure snd_una is properly initialized on connect This is strictly related to commit fb7a0d334894 ("mp…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-40926

Published Jul 12, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: don't attempt to schedule hpd_work on headless cards If the card doesn't have display hardware,…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39507

Published Jul 12, 2024

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash problem in concurrent scenario When link status change, the nic driver need to no…

CVSS 7.0 · High
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2024-39491

Published Jul 10, 2024

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l56: Fix lifetime of cs_dsp instance The cs_dsp instance is initialized in the driver probe()…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23159

Published Jun 25, 2024

A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vu…

CVSS 7.8 · High

CVE-2024-37002

Published Jun 25, 2024

A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnera…

CVSS 7.8 · High

CVE-2024-38381

Published Jun 21, 2024

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: Fix uninit-value in nci_rx_work syzbot reported the following uninit-value access issue [1] nci_rx…

CVSS 8.8 · High
evidence mentions
11
Buzz score
36.4
Vendor/product tagsBeta · best-effort

CVE-2024-33619

Published Jun 21, 2024

In the Linux kernel, the following vulnerability has been resolved: efi: libstub: only free priv.runtime_map when allocated priv.runtime_map is only allocated when efi_novamap i…

CVSS 7.8 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2022-48747

Published Jun 20, 2024

In the Linux kernel, the following vulnerability has been resolved: block: Fix wrong offset in bio_truncate() bio_truncate() clears the buffer outside of last block of bdev, how…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38619

Published Jun 20, 2024

In the Linux kernel, the following vulnerability has been resolved: usb-storage: alauda: Check whether the media is initialized The member "uzonesize" of struct alauda_info will…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47597

Published Jun 19, 2024

In the Linux kernel, the following vulnerability has been resolved: inet_diag: fix kernel-infoleak for UDP sockets KMSAN reported a kernel-infoleak [1], that can exploited by un…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47583

Published Jun 19, 2024

In the Linux kernel, the following vulnerability has been resolved: media: mxl111sf: change mutex_init() location Syzbot reported, that mxl111sf_ctrl_msg() uses uninitialized mu…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38593

Published Jun 19, 2024

In the Linux kernel, the following vulnerability has been resolved: net: micrel: Fix receiving the timestamp in the frame for lan8841 The blamed commit started to use the ptp wo…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38592

Published Jun 19, 2024

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Init `ddp_comp` with devm_kcalloc() In the case where `conn_routes` is true we allocate an extr…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-38538

Published Jun 19, 2024

In the Linux kernel, the following vulnerability has been resolved: net: bridge: xmit: make sure we have at least eth header len bytes syzbot triggered an uninit value[1] error…

CVSS 7.3 · High
evidence mentions
10
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2024-36503

Published Jun 14, 2024

Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32910

Published Jun 13, 2024

In handle_msg_shm_map_req of trusty/user/base/lib/spi/srv/tipc/tipc.c, there is a possible stack data disclosure due to uninitialized data. This could lead to local information di…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32906

Published Jun 13, 2024

In AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. U…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-29785

Published Jun 13, 2024

In aur_get_state of aurora.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution pr…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29780

Published Jun 13, 2024

In hwbcc_ns_deprivilege of trusty/user/base/lib/hwbcc/client/hwbcc.c, there is a possible uninitialized stack data disclosure due to uninitialized data. This could lead to local i…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36454

Published Jun 12, 2024

Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 Series V01L07NF0201 and earlier. If this vulnerability is ex…

CVSS 5.3 · Medium

CVE-2024-36933

Published May 30, 2024

In the Linux kernel, the following vulnerability has been resolved: nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment(). syzbot triggered various…

CVSS 7.8 · High
evidence mentions
11
Buzz score
36.4
Vendor/product tagsBeta · best-effort
Showing 376-400 of 826 CVEsPage 16 of 34