Skip to main content

CWE archive

CWE-908 CVEs

Programmatic archive

806 CVEs tagged with CWE-90880 Critical, 214 High, 482 Medium, 30 Low, 0 Unrated.

CVE-2021-45688

Published Dec 27, 2021

An issue was discovered in the ash crate before 0.33.1 for Rust. util::read_spv may read from uninitialized memory locations.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45686

Published Dec 27, 2021

An issue was discovered in the csv-sniffer crate through 2021-01-05 for Rust. preamble_skipcount may read from uninitialized memory locations.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45685

Published Dec 27, 2021

An issue was discovered in the columnar crate through 2021-01-07 for Rust. ColumnarReadExt::read_typed_vec may read from uninitialized memory locations.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45684

Published Dec 27, 2021

An issue was discovered in the flumedb crate through 2021-01-07 for Rust. read_entry may read from uninitialized memory locations.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45683

Published Dec 27, 2021

An issue was discovered in the binjs_io crate through 2021-01-03 for Rust. The Read method may read from uninitialized memory locations.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-36514

Published Dec 27, 2021

An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. fill_buf may read from uninitialized memory locations.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-36513

Published Dec 27, 2021

An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. read_up_to may read from uninitialized memory locations.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-36512

Published Dec 27, 2021

An issue was discovered in the buffoon crate through 2020-12-31 for Rust. InputStream::read_exact may read from uninitialized memory locations.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-36511

Published Dec 27, 2021

An issue was discovered in the bite crate through 2020-12-31 for Rust. read::BiteReadExpandedExt::read_framed_max may read from uninitialized memory locations.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-25023

Published Dec 27, 2021

An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40418

Published Dec 22, 2021

When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property containing an object referring to a UUI…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-41253

Published Nov 8, 2021

Zydis is an x86/x86-64 disassembler library. Users of Zydis versions v3.2.0 and older that use the string functions provided in `zycore` in order to append untrusted user data to…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41225

Published Nov 5, 2021

TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's Grappler optimizer has a use of unitialized variable. If the `train_nodes` vector (ob…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34855

Published Oct 25, 2021

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the abilit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0938

Published Oct 25, 2021

In memzero_explicit of compiler-clang.h, there is a possible bypass of defense in depth due to uninitialized data. This could lead to local information disclosure with no addition…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0634

Published Oct 25, 2021

In display driver, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36512

Published Oct 19, 2021

An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers to view sensitive information due to an uninitialized value.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-1619

Published Sep 23, 2021

A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or R…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-29631

Published Aug 30, 2021

In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE befor…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36007

Published Aug 20, 2021

Adobe Prelude version 10.0 (and earlier) are affected by an uninitialized variable vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-36282

Published Aug 16, 2021

Dell EMC PowerScale OneFS versions 8.2.x - 9.1.0.x contain a use of uninitialized resource vulnerability. This can potentially allow an authenticated user with ISI_PRIV_LOGIN_CONS…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort
Showing 551-575 of 806 CVEsPage 23 of 33