Skip to main content

CWE archive

CWE-908 CVEs

Programmatic archive

808 CVEs tagged with CWE-90880 Critical, 214 High, 484 Medium, 30 Low, 0 Unrated.

CVE-2022-31026

Published Jun 9, 2022

Trilogy is a client library for MySQL. When authenticating, a malicious server could return a specially crafted authentication packet, causing the client to read and return up to…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29205

Published May 20, 2022

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, there is a potential for segfault / denial of service in TensorFlow b…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20119

Published May 10, 2022

In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additio…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20008

Published May 10, 2022

In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This could lead to local information disclosure if reading from an…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28488

Published May 4, 2022

The function wav_format_write in libwav.c in libwav through 2017-04-20 has an Use of Uninitialized Variable vulnerability.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20079

Published Apr 11, 2022

In vow, there is a possible read of uninitialized data due to a improper input validation. This could lead to local information disclosure with System execution privileges needed.…

CVSS 4.4 · Medium

CVE-2021-21966

Published Feb 16, 2022

An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP re…

CVSS 5.3 · Medium

CVE-2022-0115

Published Feb 12, 2022

Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39671

Published Feb 11, 2022

In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to information disclosure with no additional exe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23573

Published Feb 4, 2022

Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitialized data to a new tensor. This later results in undefined…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43848

Published Feb 1, 2022

h2o is an open source http server. In code prior to the `8c0eca3` commit h2o may attempt to access uninitialized memory. When receiving QUIC frames in certain order, HTTP/3 server…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39680

Published Jan 14, 2022

In sec_SHA256_Transform of sha256_core.c, there is a possible way to read heap data due to uninitialized data. This could lead to local information disclosure with System executio…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45694

Published Dec 27, 2021

An issue was discovered in the rdiff crate through 2021-02-03 for Rust. Window may read from uninitialized memory locations.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 526-550 of 808 CVEsPage 22 of 33