Skip to main content

CWE archive

CWE-908 CVEs

Programmatic archive

815 CVEs tagged with CWE-90891 Critical, 254 High, 440 Medium, 30 Low, 0 Unrated.

CVE-2021-32846

Published Feb 17, 2023

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vtsock_proc_tx` in `virtio-sock` can lead to to uninitialized…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32845

Published Feb 17, 2023

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, the implementation of `qnotify` at `pci_vtrnd_notify`…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22281

Published Feb 1, 2023

On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP AFM NAT policy with a destinati…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36617

Published Dec 18, 2022

A vulnerability was found in ewxrjk sftpserver. It has been declared as problematic. Affected by this vulnerability is the function sftp_parse_path of the file parse.c. The manipu…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2950

Published Dec 13, 2022

Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an un…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2949

Published Dec 13, 2022

Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an un…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39282

Published Oct 12, 2022

FreeRDP is a free remote desktop protocol library and clients. FreeRDP based clients on unix systems using `/parallel` command line switch might read uninitialized data and send i…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-29240

Published Sep 15, 2022

Scylla is a real-time big data database that is API-compatible with Apache Cassandra and Amazon DynamoDB. When decompressing CQL frame received from user, Scylla assumes that user…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2308

Published Sep 1, 2022

A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of the device config space is in line with the features advert…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32745

Published Aug 25, 2022

A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting in a segmentation fault.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0887

Published Aug 24, 2022

In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0698

Published Aug 24, 2022

In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information disclosure with no additional ex…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38668

Published Aug 22, 2022

HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfilling a request for a static file smaller t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27795

Published Aug 19, 2022

A segmentation fault was discovered in radare2 with adf command. In libr/core/cmd_anal.c, when command "adf" has no or wrong argument, anal_fcn_data (core, input + 1) --> RAnalFun…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20357

Published Aug 10, 2022

In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional ex…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33716

Published Aug 5, 2022

An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local attacker to read uninitialized memory.

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort
Showing 501-525 of 815 CVEsPage 21 of 33