CWE-908

Medium likelihood

Use of Uninitialized Resource

Parent: CWE-665 - Improper Initialization

The product uses or accesses a resource that has not been initialized.

762 vulnerabilities with CWE-908
CVE-2019-12730 CRITICAL
FFmpeg < 3.2.14 and 4.x < 4.1.4 - Use of Uninitialized Resource in aa_read_header
CVSS 9.8
CVE-2019-9824 MEDIUM
QEMU 3.0.0 - Information Disclosure via Uninitialized Data in tcp_emu
CVSS 5.5
CVE-2019-11833 MEDIUM
Linux kernel <5.1.2 - Info Disclosure
CVSS 5.5
CVE-2019-11323 MEDIUM
HAProxy 1.9.2-1.9.6 - Use of Uninitialized HMAC Keys During Reload with Rotated Keys
CVSS 5.9
CVE-2019-9805 CRITICAL
Firefox < 66.0 - Memory Corruption via Uninitialized Memory Read in Prio Library
CVSS 9.8
CVE-2019-11459 MEDIUM
GNOME Evince <3.32.0 - Memory Corruption
CVSS 5.5
CVE-2019-9641 CRITICAL
PHP <7.1.27-7.3.3 - Info Disclosure
CVSS 9.8
CVE-2019-9639 HIGH
PHP <7.1.27-7.3.3 - Uninitialized Read
CVSS 7.5
CVE-2019-9578 HIGH
Yubico libu2f-host <1.1.8 - Memory Corruption
CVSS 7.5
CVE-2019-6976 MEDIUM
libvips < 8.7.4 - Information Disclosure via Uninitialized Memory in Image Processing
CVSS 5.3
CVE-2019-0006 CRITICAL
Juniper Junos - Use-After-Free in Packet Forwarding Engine Manager
CVSS 9.8
CVE-2018-9378 MEDIUM
Android - Local Information Disclosure via Uninitialized Data in BnAudioPolicyService
CVSS 6.2
CVE-2018-9429 MEDIUM
Android - Information Disclosure via Uninitialized Data in ItemTable.cpp
CVSS 6.5
CVE-2018-9381 HIGH
Android - Information Disclosure via Uninitialized Data in gatts_process_read_by_type_req
CVSS 7.5
CVE-2018-9377 MEDIUM
Android - Local Privilege Escalation via Pending Intent Metadata Access
CVSS 5.5
CVE-2018-9421 MEDIUM
Android - Information Disclosure via Uninitialized Data in Parcel.cpp
CVSS 5.5
CVE-2018-9420 MEDIUM
Android - Information Disclosure via Uninitialized Data in BnCameraService::onTransact
CVSS 5.5
CVE-2018-9346 MEDIUM
Android - Information Disclosure via Uninitialized Data in BnAudioPolicyService
CVSS 5.5
CVE-2018-9345 MEDIUM
Android - Information Disclosure via Uninitialized Data in BnAudioPolicyService
CVSS 5.5
CVE-2018-25023 HIGH
smallvec <0.6.13 - Memory Corruption
CVSS 7.5
CVE-2018-25014 CRITICAL
libwebp < 1.0.1 - Use of Uninitialized Resource in ReadSymbol()
CVSS 9.8
CVE-2018-20992 MEDIUM
claxon < 0.4.1 - Uninitialized Memory Exposure via Decode Buffer Mishandling
CVSS 6.5
CVE-2018-6132 MEDIUM
Google Chrome <67.0.3396.62 - Info Disclosure
CVSS 4.3
CVE-2018-18366 MEDIUM
Symantec Endpoint Protection - Kernel Memory Disclosure via IRP Request
CVSS 6.5
CVE-2018-12011 MEDIUM
Android - Information Exposure via Uninitialized Socket Address Data
CVSS 5.5
Details
Vulnerabilities 762
Exploit Likelihood Medium