VulnSea

CWE-908

CVEs classified under CWE-908, newest first.

104 CVEsRSS

CVE-2026-70290Medium· 5.5
1w ago

Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.

Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.40%via NVD
CVE-2026-69853Medium· 4.7
1w ago

Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally.

Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.30%via NVD
CVE-2026-69770Medium· 5.5
1w ago

Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via NVD
CVE-2026-69672Medium· 5.5
1w ago

Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.

Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via NVD
CVE-2026-69485High· 8.8
1w ago

Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.

Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.91%via NVD
CVE-2026-69358High· 7.1
1w ago

Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.

Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.52%via NVD
CVE-2026-69349Medium· 5.7
1w ago

Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network.

Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · windows_10_1607EPSS 0.84%via NVD
CVE-2026-69288Medium· 5.5
1w ago

Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.30%via NVD
CVE-2026-68873Medium· 5.5
1w ago

Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.

Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_11_23h2EPSS 0.46%via NVD
CVE-2026-68852Medium· 5.5
1w ago

Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally.

Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.35%via NVD
CVE-2026-68776Medium· 6.5
1w ago

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.55%via NVD
CVE-2026-67648Medium· 6.5
1w ago

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.55%via NVD
CVE-2026-67386Medium· 6.5
1w ago

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sql_server_2017EPSS 0.71%via NVD
CVE-2026-85089Medium· 6.5
2w ago

FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields

FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, …

Sunlitfreerdp · freerdpEPSS 0.42%via NVD
CVE-2026-79229Medium· 6.5
3w ago

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

SunlitGoogle · ChromeEPSS 0.41%via CVEORG
CVE-2026-79221Medium· 6.5
3w ago

Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page

Uninitialized resource in Dawn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

SunlitGoogle · ChromeEPSS 0.27%via CVEORG
CVE-2026-79270Medium· 6.5
3w ago

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

SunlitGoogle · ChromeEPSS 0.41%via CVEORG
CVE-2026-62986Medium· 4.3
3w ago

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale he…

SunlitEPSS 0.23%via NVD
CVE-2026-63381Medium· 6.6
1mo ago

Libevent is an event notification library

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains fre…

SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.12%via NVD
CVE-2026-62377Medium· 4.3
1mo ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash when heif_context_g…

SunlitEPSS 0.33%via NVD
CVE-2026-70317Medium· 5.5
1mo ago

Microsoft Office Information Disclosure Vulnerability

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.36%via CVEORG
CVE-2026-62740Medium· 5.5
1mo ago

Windows Imaging Component Information Disclosure Vulnerability

Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.39%via CVEORG
CVE-2026-68799Medium· 5.5
1mo ago

Microsoft Excel Information Disclosure Vulnerability

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.34%via CVEORG
CVE-2026-62709Medium· 5.5
1mo ago

Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.39%via NVD
CVE-2026-59137Medium· 5.5
1mo ago

Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.

Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.39%via NVD
CVE-2026-59136Medium· 5.5
1mo ago

Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.

Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.37%via NVD
CVE-2026-70631Medium· 5.5
1mo ago

FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c

FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supp…

SunlitEPSS 0.13%via NVD
CVE-2026-64413High· 7.0
1mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko reports: looking at ebtables table translation, could a sparse cpu_possible_mask lead to an uninitialized pointer …

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: zero chainstack array sashiko reports: looking at ebtables table translation, could a sparse cpu_possible_mask lead to an uninitialized pointer …

Twilightlinux · linux_kernelEPSS 0.12%via NVD
CVE-2026-64360Medium· 5.5
1mo ago

In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: zero-initialize buffer in hfs_bnode_read hfs_bnode_read() can return early without writing to the output buffer when is_bnode_offset_valid() fails or when…

In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: zero-initialize buffer in hfs_bnode_read hfs_bnode_read() can return early without writing to the output buffer when is_bnode_offset_valid() fails or when…

Sunlitlinux · linux_kernelEPSS 0.12%via NVD
CVE-2026-55003Medium· 6.5
2mo ago

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CWE-908 vulnerabilities (CVEs) — page 2 · VulnSea