Skip to main content

CWE archive

CWE-908 CVEs

Programmatic archive

829 CVEs tagged with CWE-90891 Critical, 255 High, 450 Medium, 33 Low, 0 Unrated.

CVE-2023-4489

Published Dec 14, 2023

The first S0 encryption key is generated with an uninitialized PRNG in Z/IP Gateway products running Silicon Labs Z/IP Gateway SDK v7.18.3 and earlier. This makes the first S0 key…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31275

Published Nov 27, 2023

An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel file. A specially crafted malformed file c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46100

Published Nov 20, 2023

in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitialized resource.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45663

Published Oct 21, 2023

stb_image is a single file MIT licensed library for processing images. The stbi__getn function reads a specified number of bytes from context (typically a file) into the specified…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31192

Published Oct 12, 2023

An information disclosure vulnerability exists in the ClientConnect() functionality of SoftEther VPN 5.01.9674. A specially crafted network packet can lead to a disclosure of sens…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25588

Published Sep 14, 2023

A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25586

Published Sep 14, 2023

A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local den…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25585

Published Sep 14, 2023

A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21276

Published Aug 14, 2023

In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional exec…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21233

Published Aug 14, 2023

In multiple locations of avrc, there is a possible leak of heap data due to uninitialized data. This could lead to remote information disclosure with no additional execution privi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36836

Published Jul 14, 2023

A Use of an Uninitialized Resource vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0948

Published Jul 13, 2023

The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel memory to user space. The contents of this memory could contain sensitive infor…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 476-500 of 829 CVEsPage 20 of 34