Skip to main content

CWE archive

CWE-909 CVEs

Programmatic archive

102 CVEs tagged with CWE-9091 Critical, 35 High, 52 Medium, 14 Low, 0 Unrated.

CVE-2026-43040

Published May 1, 2026

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak Wh…

CVSS 7.1 · High
evidence mentions
10
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2026-40687

Published Apr 30, 2026

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or er…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-8117

Published Sep 30, 2025

PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-38601

Published Aug 19, 2025

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: clear initialized flag for deinit-ed srng lists In a number of cases we see kernel panics on re…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-38532

Published Aug 16, 2025

In the Linux kernel, the following vulnerability has been resolved: net: libwx: properly reset Rx ring descriptor When device reset is triggered by feature changes such as toggl…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54410

Published Jul 30, 2025

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/product…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-54388

Published Jul 30, 2025

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/product…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-50169

Published Jun 18, 2025

In the Linux kernel, the following vulnerability has been resolved: wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi() The simple_write_to_buffer() function will succ…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-49865

Published May 1, 2025

In the Linux kernel, the following vulnerability has been resolved: ipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network When copying a `struct ifaddrlblmsg…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-49217

Published Feb 26, 2025

In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix abort all task initialization In pm80xx_send_abort_all(), the n_elem field of the ccb used…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52870

Published Jan 17, 2025

Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) t…

CVSS 7.1 · High

CVE-2024-56676

Published Dec 28, 2024

In the Linux kernel, the following vulnerability has been resolved: thermal: testing: Initialize some variables annoteded with _free() Variables annotated with __free() need to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53845

Published Dec 12, 2024

ESPTouch is a connection protocol for internet of things devices. In the ESPTouchV2 protocol, while there is an option to use a custom AES key, there is no option to set the IV (I…

CVSS 6.6 · Medium

CVE-2024-50076

Published Oct 29, 2024

In the Linux kernel, the following vulnerability has been resolved: vt: prevent kernel-infoleak in con_font_get() font.data may not initialize all memory spaces depending on the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8178

Published Sep 5, 2024

The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running in a guest VM that exposes vi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43873

Published Aug 21, 2024

In the Linux kernel, the following vulnerability has been resolved: vhost/vsock: always initialize seqpacket_allow There are two issues around seqpacket_allow: 1. seqpacket_allo…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32945

Published Jul 15, 2024

Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creat…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-26635

Published Mar 18, 2024

In the Linux kernel, the following vulnerability has been resolved: llc: Drop support for ETH_P_TR_802_2. syzbot reported an uninit-value bug below. [0] llc supports ETH_P_802_…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27913

Published Feb 28, 2024

ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, becau…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0947

Published Aug 24, 2022

The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM, and then copies the buffer to userspa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0946

Published Aug 24, 2022

The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolicAddr, and then copies the buffer to use…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 102 CVEsPage 1 of 5