CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
896 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 17 of 18
- CVE-2026-54997MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
- CVE-2026-55003MEDIUMCVSS 6.5EG 6.52026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-55042MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-55949HIGHCVSS 7.8EG 7.82026-07-14
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-56085LOWCVSS 3.3EG 3.32026-07-03
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of uninitia…
- CVE-2026-56190CRITICALCVSS 9.8EG 9.82026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
- CVE-2026-56968MEDIUMCVSS 5.3EG 5.32026-06-23
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.
- CVE-2026-57083MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.
- CVE-2026-57084MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
- CVE-2026-57982MEDIUMCVSS 6.5EG 6.52026-07-14
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
- CVE-2026-58051MEDIUMCVSS 6.5EG 6.52026-06-28
libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an unini…
- CVE-2026-58084MEDIUMCVSS 5.5EG 5.52026-08-19
To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. For a timer using CLOCK_TAI this can fail when no TAI offset has been configured, but the error return was n…
- CVE-2026-58247MEDIUMCVSS 5.3EG 5.32026-08-11
SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading to a low on confidentiality, with no impact…
- CVE-2026-58533HIGHCVSS 7.5EG 7.52026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-58535HIGHCVSS 7.5EG 7.52026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-58546MEDIUMCVSS 6.5EG 6.52026-07-14
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
- CVE-2026-59136MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
- CVE-2026-59137MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
- CVE-2026-60005HIGHCVSS 8.2EG 8.22026-07-15
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send re…
- CVE-2026-62377MEDIUMCVSS 4.3EG 4.32026-08-18
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash when heif_context_get…
- CVE-2026-62709MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
- CVE-2026-62740MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.
- CVE-2026-62986MEDIUMCVSS 4.3EG 4.32026-08-25
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale heap…
- CVE-2026-63381MEDIUMCVSS 5.8EG 5.82026-08-20
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees…
- CVE-2026-6368LOWCVSS 2.1EG 2.12026-08-10
Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
- CVE-2026-64082HIGHCVSS 7.8EG 7.82026-07-19
In the Linux kernel, the following vulnerability has been resolved: riscv: Fix register corruption from uninitialized cregs on error compat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when user_regset_copyin() fails. Sinc…
- CVE-2026-64130MEDIUMCVSS 5.5EG 5.52026-07-19
In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free __GFP_ZEROTAGS semantics are currently a bit weird, but effectively this flag is only …
- CVE-2026-64220MEDIUMCVSS 5.5EG 5.52026-07-24
In the Linux kernel, the following vulnerability has been resolved: device property: set fwnode->secondary to NULL in fwnode_init() If a firmware node is allocated on the stack (for instance: temporary software node whose life-time we co…
- CVE-2026-64309MEDIUMCVSS 5.5EG 5.52026-07-25
In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) Sashiko notes: > if SEV initialization fails and KVM is actively running normal VMs, could a > userspace proce…
- CVE-2026-64360MEDIUMCVSS 5.5EG 5.52026-07-25
In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: zero-initialize buffer in hfs_bnode_read hfs_bnode_read() can return early without writing to the output buffer when is_bnode_offset_valid() fails or when c…
- CVE-2026-64413HIGHCVSS 7.0EG 7.02026-07-25
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko reports: looking at ebtables table translation, could a sparse cpu_possible_mask lead to an uninitialized pointer f…
- CVE-2026-66034HIGHCVSS 7.5EG 7.52026-07-24
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publick…
- CVE-2026-66038MEDIUMCVSS 6.5EG 6.52026-07-24
FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer…
- CVE-2026-6686MEDIUMCVSS 4.6EG 4.62026-07-01
FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-filling newly allocated clusters. This maps to CWE-908 (Use of Uninitialized Resource). Estimated CVSS v3.1 vector: CVS…
- CVE-2026-67386MEDIUMCVSS 6.5EG 6.52026-09-08
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-6749HIGHCVSS 7.5EG 7.52026-04-21
Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
- CVE-2026-67648MEDIUMCVSS 6.5EG 6.52026-09-08
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-68744LOWCVSS 3.3EG 3.32026-08-04
A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be trans…
- CVE-2026-68776MEDIUMCVSS 6.5EG 6.52026-09-08
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-68799MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-68852MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally.
- CVE-2026-68873MEDIUMCVSS 5.5EG 5.52026-09-08
Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.
- CVE-2026-69288MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
- CVE-2026-69349MEDIUMCVSS 5.7EG 5.72026-09-08
Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network.
- CVE-2026-69358HIGHCVSS 7.1EG 7.12026-09-08
Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.
- CVE-2026-69485HIGHCVSS 8.8EG 8.82026-09-08
Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.
- CVE-2026-69672MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.
- CVE-2026-69770MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
- CVE-2026-69853MEDIUMCVSS 4.7EG 4.72026-09-08
Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally.
- CVE-2026-70290MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →