CWE-909
108 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-909page 2 of 3
- CVE-2020-20739MEDIUMCVSS 5.3EG 5.32020-11-20
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
- CVE-2020-24455MEDIUMCVSS 6.7EG 6.72021-02-26
Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.
- CVE-2020-25579MEDIUMCVSS 5.3EG 5.32021-03-26
In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 11.4-RELEASE before p7 msdosfs(5) was failing to zero-fill a pair of padding fields in the dirent structure, resulting i…
- CVE-2020-6792MEDIUMCVSS 4.3EG 4.32020-03-02
When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 68.5.
- CVE-2020-9227MEDIUMCVSS 5.5EG 5.52020-07-17
Huawei Smart Phones Moana-AL00B with versions earlier than 10.1.0.166 have a missing initialization of resource vulnerability. An attacker tricks the user into installing then running a crafted application. Due to improper initialization o…
- CVE-2021-0423MEDIUMCVSS 5.5EG 5.52021-09-27
In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat…
- CVE-2021-0484MEDIUMCVSS 5.5EG 5.52021-06-11
In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not n…
- CVE-2021-0946HIGHCVSS 7.5EG 7.52022-08-24
The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolicAddr, and then copies the buffer to userspace. The method PMR_PDumpSymbolicAddr may fail, and if it…
- CVE-2021-0947HIGHCVSS 7.5EG 7.52022-08-24
The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM, and then copies the buffer to userspace. The method TLServerDiscoverStreamsKM may fail for severa…
- CVE-2021-0961MEDIUMCVSS 4.4EG 4.42021-12-15
In quota_proc_write of xt_quota2.c, there is a possible way to read kernel memory due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploi…
- CVE-2021-0966MEDIUMCVSS 5.5EG 5.52021-12-15
In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted parcelable to reveal uninitialized memory of a target process due to uninitialized data. This could lead to local information disclosure acro…
- CVE-2021-1405HIGHCVSS 7.5EG 7.52021-04-08
A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulner…
- CVE-2021-22482MEDIUMCVSS 5.3EG 5.32021-10-28
There is an Uninitialized variable vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause transmission of invalid data.
- CVE-2021-22898LOWCVSS 3.1EG 3.12021-06-11
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for…
- CVE-2021-23386HIGHCVSS 7.7EG 7.72021-05-20
This affects the package dns-packet before 5.2.2. It creates buffers with allocUnsafe and does not always fill them before forming network packets. This can expose internal application memory over unencrypted network when querying crafted …
- CVE-2021-23994HIGHCVSS 8.8EG 8.82021-06-24
A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
- CVE-2021-26333CVSS 0.0EG 5.52021-09-21
An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionary access control list (DACL) may allow low privileged users to open a handle and send requests to the driver resulting …
- CVE-2021-28167MEDIUMCVSS 6.5EG 6.52021-04-21
In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entries. This allows a user to call static methods or access static members without r…
- CVE-2021-28687MEDIUMCVSS 5.5EG 5.52021-06-11
HVM soft-reset crashes toolstack libxl requires all data structures passed across its public interface to be initialized before use and disposed of afterwards by calling a specific set of functions. Many internal data structures also requi…
- CVE-2021-29647MEDIUMCVSS 5.5EG 5.52021-03-30
An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624.
- CVE-2021-29980HIGHCVSS 8.8EG 8.82021-08-17
Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Fire…
- CVE-2021-31919HIGHCVSS 7.5EG 7.52021-04-30
An issue was discovered in the rkyv crate before 0.6.0 for Rust. When an archive is created via serialization, the archive content may contain uninitialized values of certain parts of a struct.
- CVE-2021-34693MEDIUMCVSS 5.5EG 5.52021-06-14
net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.
- CVE-2021-36386HIGHCVSS 7.5EG 7.52021-07-30
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error mes…
- CVE-2021-36513HIGHCVSS 7.5EG 7.52021-10-18
An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view sensitive information due to an uninitialized value.
- CVE-2021-3655LOWCVSS 3.3EG 3.32021-08-05
A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory.
- CVE-2021-39636MEDIUMCVSS 4.4EG 4.42021-12-15
In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is…
- CVE-2021-39966HIGHCVSS 7.5EG 7.52022-01-03
There is an Uninitialized AOD driver structure in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-40403MEDIUMCVSS 6.3EG 5.52022-02-04
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initializ…
- CVE-2022-0175MEDIUMCVSS 5.5EG 5.52022-08-26
A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the guest kernel and read…
- CVE-2022-0382MEDIUMCVSS 5.5EG 5.52022-02-11
An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way a user sends a TIPC datagram to one or more destinations. This flaw allows a local user to read some kernel memory. Th…
- CVE-2022-1016MEDIUMCVSS 5.5EG 5.52022-08-29
A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem cause…
- CVE-2022-20357MEDIUMCVSS 5.5EG 5.52022-08-10
In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo…
- CVE-2022-22704CRITICALCVSS 9.8EG 9.82022-01-06
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.
- CVE-2022-24448LOWCVSS 3.3EG 3.32022-02-04
An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR shou…
- CVE-2022-29925HIGHCVSS 7.8EG 7.82022-06-14
Access of uninitialized pointer vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a us…
- CVE-2022-29968HIGHCVSS 7.8EG 7.82022-05-02
An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.
- CVE-2022-49217MEDIUMCVSS 5.5EG 5.52025-02-26
In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix abort all task initialization In pm80xx_send_abort_all(), the n_elem field of the ccb used is not initialized to 0. This missing initialization sometim…
- CVE-2022-49865HIGHCVSS 7.1EG 7.12025-05-01
In the Linux kernel, the following vulnerability has been resolved: ipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network When copying a `struct ifaddrlblmsg` to the network, __ifal_reserved remained uninitialized, re…
- CVE-2022-50169HIGHCVSS 7.1EG 7.12025-06-18
In the Linux kernel, the following vulnerability has been resolved: wifi: wil6210: debugfs: fix info leak in wil_write_file_wmi() The simple_write_to_buffer() function will succeed if even a single byte is initialized. However, we need …
- CVE-2023-5138MEDIUMCVSS 6.8EG 6.82024-01-03
Glitch detection is not enabled by default for the CortexM33 core in Silicon Labs secure vault high parts EFx32xG2xB, except EFR32xG21B.
- CVE-2024-26635MEDIUMCVSS 5.5EG 5.52024-03-18
In the Linux kernel, the following vulnerability has been resolved: llc: Drop support for ETH_P_TR_802_2. syzbot reported an uninit-value bug below. [0] llc supports ETH_P_802_2 (0x0004) and used to support ETH_P_TR_802_2 (0x0011), and …
- CVE-2024-27913MEDIUMCVSS 6.5EG 6.52024-02-28
ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.
- CVE-2024-32945LOWCVSS 2.6EG 2.62024-07-15
Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
- CVE-2024-43873HIGHCVSS 7.8EG 7.82024-08-21
In the Linux kernel, the following vulnerability has been resolved: vhost/vsock: always initialize seqpacket_allow There are two issues around seqpacket_allow: 1. seqpacket_allow is not initialized when socket is created. Thus if feat…
- CVE-2024-50076MEDIUMCVSS 6.5EG 6.52024-10-29
In the Linux kernel, the following vulnerability has been resolved: vt: prevent kernel-infoleak in con_font_get() font.data may not initialize all memory spaces depending on the implementation of vc->vc_sw->con_font_get. This may cause i…
- CVE-2024-52870HIGHCVSS 7.1EG 7.12025-01-17
Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) that can result in a client user accessing arbitrary remote w…
- CVE-2024-53845MEDIUMCVSS 6.6EG 0.02024-12-12
ESPTouch is a connection protocol for internet of things devices. In the ESPTouchV2 protocol, while there is an option to use a custom AES key, there is no option to set the IV (Initialization Vector) prior to versions 5.3.2, 5.2.4, 5.1.6,…
- CVE-2024-56676MEDIUMCVSS 5.5EG 5.52024-12-28
In the Linux kernel, the following vulnerability has been resolved: thermal: testing: Initialize some variables annoteded with _free() Variables annotated with __free() need to be initialized if the function can return before they get up…
- CVE-2024-8178HIGHCVSS 8.8EG 8.82024-09-05
The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to achieve code ex…
Map vulnerabilities like CWE-909 to your infrastructure
EchelonGraph correlates every CVE — across CWE-909 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →