CWE-908
CVEs classified under CWE-908, newest first.
104 CVEsRSS
CVE-2026-70290Medium· 5.5Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.
CVE-2026-69853Medium· 4.7Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-69770Medium· 5.5Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
CVE-2026-69672Medium· 5.5Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.
CVE-2026-69485High· 8.8Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.
Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.
CVE-2026-69358High· 7.1Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.
Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.
CVE-2026-69349Medium· 5.7Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network.
Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network.
CVE-2026-69288Medium· 5.5Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
CVE-2026-68873Medium· 5.5Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.
Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.
CVE-2026-68852Medium· 5.5Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally.
CVE-2026-68776Medium· 6.5Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67648Medium· 6.5Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67386Medium· 6.5Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-85089Medium· 6.5FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields
FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, …
CVE-2026-79229Medium· 6.5Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79221Medium· 6.5Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page
Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79270Medium· 6.5Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-62986Medium· 4.3OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale he…
CVE-2026-63381Medium· 6.6Libevent is an event notification library
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains fre…
CVE-2026-62377Medium· 4.3libheif is a HEIF and AVIF file format decoder and encoder
libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash when heif_context_g…
CVE-2026-70317Medium· 5.5Microsoft Office Information Disclosure Vulnerability
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-62740Medium· 5.5Windows Imaging Component Information Disclosure Vulnerability
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.
CVE-2026-68799Medium· 5.5Microsoft Excel Information Disclosure Vulnerability
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-62709Medium· 5.5Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
CVE-2026-59137Medium· 5.5Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CVE-2026-59136Medium· 5.5Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
CVE-2026-70631Medium· 5.5FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c
FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supp…
CVE-2026-64413High· 7.0In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko reports: looking at ebtables table translation, could a sparse cpu_possible_mask lead to an uninitialized pointer …
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko reports: looking at ebtables table translation, could a sparse cpu_possible_mask lead to an uninitialized pointer …
CVE-2026-64360Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: zero-initialize buffer in hfs_bnode_read hfs_bnode_read() can return early without writing to the output buffer when is_bnode_offset_valid() fails or when…
In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: zero-initialize buffer in hfs_bnode_read hfs_bnode_read() can return early without writing to the output buffer when is_bnode_offset_valid() fails or when…
CVE-2026-55003Medium· 6.5Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.