CWE-908
CVEs classified under CWE-908, newest first.
104 CVEsRSS
CVE-2026-94056High· 7.5Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
CVE-2026-93018NoneImager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader add…
Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader add…
CVE-2026-54634High· 7.3Hamlib is a ham radio control library for radios, rotators, and amplifiers
Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld send_raw command on TCP port 4532 reaches rigctl_send_raw() in tests/rigctl_parse.c, which writes a NUL byte at buf[b…
CVE-2026-54604Medium· 5.3OpenSlide is a C library for reading whole slide image files
OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes the indirect TIFF tile path in src/openslide-decode-tiff.c and _openslide_tiff_read_tile() to request a full-height d…
CVE-2026-91740Medium· 4.3⚖ disputedUninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page
Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVE-2026-91720Medium· 4.7⚖ disputedUninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page
Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-91946Medium· 6.5FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format
FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitiali…
CVE-2026-84622Medium· 6.2A memory initialization issue was addressed with improved memory handling
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 2…
CVE-2026-89773Medium· 5.5kernel: drm/amd/display: Skip Update HDCP Config In Transition State (CVE-2026-89773)
A flaw was found in the `drm/amd/display` component of the Linux kernel. This vulnerability occurs because the High-bandwidth Digital Content Protection (HDCP) configuration routine is skipped during a transition state when an invalid `dm_…
CVE-2026-81016Medium· 5.5⚖ disputedkernel: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address (CVE-2026-81016)
A flaw was found in the Linux kernel. Specifically, within the AMD Platform Management Controller (PMC) component, the `amd_stb_s2d_init()` function does not properly validate memory addresses returned by System Management Unit (SMU) comma…
CVE-2026-89687Medium· 5.5kernel: nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file (CVE-2026-89687)
A flaw was found in the Linux kernel's Network File System Daemon (nfsd). The `nfsd_file_do_acquire()` function might attempt to use a file that has not been fully opened, as the `->atomic_open` operation could return success prematurely. …
CVE-2026-80970High· 7.0kernel: ALSA: FCP: do not copy out an uninitialised init response (CVE-2026-80970)
A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) FireWire Control Protocol (FCP) subsystem. This vulnerability allows a local attacker to trigger the copying of uninitialized kernel memory to userspace. By se…
CVE-2026-89456High· 7.0kernel: s390/dasd: Propagate partial completion length across ERP recovery (CVE-2026-89456)
A flaw was found in the Linux kernel. Specifically, within the s390/dasd component, an issue exists during error recovery for disk read operations. When a request is partially completed and then recovered, the system fails to correctly pro…
CVE-2026-89599Medium· 5.5⚖ disputedkernel: fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (CVE-2026-89599)
A flaw was found in the Linux kernel's `fbdev: omapfb: panel-dsi-cm` component. The `dsicm_probe()` function registers a display before its associated lock (mutex) is properly initialized. This timing issue allows another process to attemp…
CVE-2026-89616Medium· 5.5⚖ disputedkernel: fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() (CVE-2026-89616)
A flaw was found in the Linux kernel's NTFS3 filesystem driver. When decompressing LZNT data, the `ni_read_frame()` function may not fully zero out memory after a partial decompression. This can lead to the disclosure of previously used ke…
CVE-2026-89462Medium· 5.5kernel: power: supply: max17040: propagate register read errors (CVE-2026-89462)
A flaw was found in the Linux kernel's power supply subsystem, specifically within the max17040 driver. This vulnerability occurs when the `max17040_get_vcell()` and `max17040_get_soc()` functions fail to properly handle errors returned by…
CVE-2026-15710Medium· 6.8An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141
An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the…
CVE-2026-87647Low· 3.4⚖ disputedUninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page
Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-87456Low· 3.4⚖ disputedUninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page
Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87642Medium· 4.3⚖ disputedUninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page
Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87576Low· 3.4⚖ disputedUninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page
Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severit…
CVE-2026-87497Medium· 4.3Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page
Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87555Medium· 4.7⚖ disputedUninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page
Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-85880High· 7.8CISA KEV0dayPoCHeap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-81958Medium· 5.5Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-81391Medium· 5.5Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-80091Medium· 6.5Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.
CVE-2026-78519High· 8.8Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-72989High· 7.5Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.
Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.
CVE-2026-72945Medium· 5.5Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.