Skip to main content

CWE archive

CWE-908 CVEs

Programmatic archive

806 CVEs tagged with CWE-90880 Critical, 214 High, 482 Medium, 30 Low, 0 Unrated.

CVE-2021-1104

Published Aug 13, 2021

The RISC-V Instruction Set Manual contains a documented ambiguity for the Machine Trap Vector Base Address (MTVEC) register that may lead to a vulnerability due to the initial sta…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-37682

Published Aug 12, 2021

TensorFlow is an end-to-end open source platform for machine learning. In affected versions all TFLite operations that use quantization can be made to use unitialized values. [For…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36452

Published Aug 8, 2021

An issue was discovered in the array-tools crate before 0.3.2 for Rust. FixedCapacityDequeLike::clone() has a drop of uninitialized memory.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-36443

Published Aug 8, 2021

An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust. An uninitialized buffer is passed to AsyncRead::poll_read(), which is a user-provided trait function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-36432

Published Aug 8, 2021

An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matrix::new().

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-0530

Published Jun 21, 2021

In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0526

Published Jun 21, 2021

In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0495

Published Jun 11, 2021

In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0473

Published Jun 11, 2021

In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remote code execution over NFC with no additional execution pri…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-3545

Published Jun 2, 2021

An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. The flaw exists in virgl_cmd_ge…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29581

Published May 14, 2021

TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.CTCBeamSearchDecoder`, an attacker can trigger denial of service vi…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-29580

Published May 14, 2021

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FractionalMaxPoolGrad` triggers an undefined behavior if one of the input…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-29623

Published May 13, 2021

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versi…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-31423

Published Apr 29, 2021

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first obtain the ability…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31419

Published Apr 29, 2021

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker must first obtain the ability…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31418

Published Apr 29, 2021

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker must first obtain the ability…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31417

Published Apr 29, 2021

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker must first obtain the ability…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30027

Published Apr 29, 2021

md_analyze_line in md4c.c in md4c 0.4.7 allows attackers to trigger use of uninitialized memory, and cause a denial of service via a malformed Markdown document.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29937

Published Apr 1, 2021

An issue was discovered in the telemetry crate through 2021-02-17 for Rust. There is a drop of uninitialized memory if a value.clone() call panics within misc::vec_with_size().

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-29936

Published Apr 1, 2021

An issue was discovered in the adtensor crate through 2021-01-11 for Rust. There is a drop of uninitialized memory via the FromIterator implementation for Vector and Matrix.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 576-600 of 806 CVEsPage 24 of 33