CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
896 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 18 of 18
- CVE-2026-70317MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-70459MEDIUMCVSS 5.3EG 5.32026-08-13
rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The …
- CVE-2026-70629MEDIUMCVSS 5.5EG 5.52026-08-06
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted vid…
- CVE-2026-70630MEDIUMCVSS 5.5EG 5.52026-08-06
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by sup…
- CVE-2026-70631MEDIUMCVSS 5.5EG 5.52026-08-06
FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply…
- CVE-2026-7141MEDIUMCVSS 5.6EG 5.62026-04-27
A vulnerability was found in vLLM up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of the component KV Block Handler. Performing a manipulation results in uninitialized resource.…
- CVE-2026-72945MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.
- CVE-2026-72989HIGHCVSS 7.5EG 7.52026-09-08
Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.
- CVE-2026-76042LOWCVSS 3.1EG 3.12026-08-18
Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-78519HIGHCVSS 8.8EG 8.82026-09-08
Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- CVE-2026-78914MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-78958LOWCVSS 3.1EG 3.12026-08-25
Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-78962MEDIUMCVSS 4.3EG 4.32026-08-25
Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-78965MEDIUMCVSS 4.3EG 4.32026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-78969MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in Video in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-78977MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-78984LOWCVSS 3.4EG 3.42026-08-25
Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: M…
- CVE-2026-78986LOWCVSS 3.1EG 3.12026-08-25
Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-79007LOWCVSS 3.1EG 3.12026-08-25
Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: M…
- CVE-2026-79040MEDIUMCVSS 4.3EG 4.32026-08-25
Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-79118MEDIUMCVSS 4.3EG 4.32026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-79120MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79221MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79229MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79269MEDIUMCVSS 4.3EG 4.32026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79270MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-79285MEDIUMCVSS 6.5EG 6.52026-08-25
Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-80091MEDIUMCVSS 6.5EG 6.52026-09-08
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.
- CVE-2026-81391MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-81958MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-84267MEDIUMCVSS 4.3EG 4.32026-09-01
A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving …
- CVE-2026-84326HIGHCVSS 8.8EG 8.82026-09-01
Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-84622MEDIUMCVSS 6.2EG 6.22026-09-14
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27.…
- CVE-2026-85089MEDIUMCVSS 6.5EG 6.52026-09-03
FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, an…
- CVE-2026-85880CRITICALCVSS 7.8EG 9.0⚠ KEV2026-09-08
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
- CVE-2026-87456LOWCVSS 3.4EG 3.42026-09-09
Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-87497MEDIUMCVSS 4.3EG 4.32026-09-09
Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-87555MEDIUMCVSS 4.7EG 4.72026-09-09
Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-87576LOWCVSS 3.4EG 3.42026-09-09
Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity:…
- CVE-2026-87642MEDIUMCVSS 4.3EG 4.32026-09-09
Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-87647LOWCVSS 3.4EG 3.42026-09-09
Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-91720MEDIUMCVSS 4.7EG 4.72026-09-15
Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-91740MEDIUMCVSS 4.3EG 4.32026-09-15
Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-91946MEDIUMCVSS 6.5EG 6.52026-09-15
FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialize…
- CVE-2026-93018UnratedEG not assessed2026-09-18
Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader adds …
- CVE-2026-94056HIGHCVSS 7.5EG 7.52026-09-19
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →