VulnSea

CWE-908

CVEs classified under CWE-908, newest first.

104 CVEsRSS

CVE-2026-54997Medium· 5.5
2mo ago

Windows SMB Information Disclosure Vulnerability

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-49801Medium· 5.5
2mo ago

Windows SMB Information Disclosure Vulnerability

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-50455Medium· 5.5
2mo ago

Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability

Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-50497Medium· 6.5
2mo ago

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-50690Medium· 5.5
2mo ago

Windows SMB Information Disclosure Vulnerability

Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.40%via CVEORG
CVE-2026-55042Medium· 5.5
2mo ago

Microsoft Office Information Disclosure Vulnerability

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.54%via CVEORG
CVE-2026-55949High· 7.8
2mo ago

Microsoft Excel Remote Code Execution Vulnerability

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-56190Critical· 9.8
2mo ago

Remote Desktop Protocol Remote Code Execution Vulnerability

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.

MidnightMicrosoft · Windows 10 Version 1607EPSS 0.97%via CVEORG
CVE-2026-57982Medium· 6.5
2mo ago

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.

SunlitMicrosoft · Windows 10 Version 1607EPSS 1.00%via CVEORG
CVE-2026-58546Medium· 6.5
2mo ago

Windows Remote Desktop Client Information Disclosure Vulnerability

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-58535Medium· 6.5
2mo ago

Windows Remote Desktop Client Information Disclosure Vulnerability

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-58533Medium· 6.5
2mo ago

Windows Remote Desktop Client Information Disclosure Vulnerability

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-50376Medium· 6.5
2mo ago

Windows Remote Desktop Client Information Disclosure Vulnerability

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.92%via CVEORG
CVE-2026-57084Medium· 5.5
2mo ago

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.54%via NVD
CVE-2026-57083Medium· 5.5
2mo ago

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.

Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.54%via NVD
CVE-2026-49165High· 7.1
2mo ago

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

Twilightmicrosoft · windows_10_1607EPSS 0.34%via NVD
CVE-2026-40422Medium· 5.5
2mo ago

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.40%via NVD
CVE-2026-56085Low· 3.3
2mo ago

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of uninit…

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of uninit…

SunlitEPSS 0.14%via NVD
CVE-2026-53225Critical· 9.1
2mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a p…

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a p…

Midnightlinux · linux_kernelEPSS 0.51%via NVD
CVE-2026-53218Medium· 5.5
2mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag nft_exthdr_init() passes user-controlled priv->len to nft_parse_register_store(), which marks that many…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag nft_exthdr_init() passes user-controlled priv->len to nft_parse_register_store(), which marks that many…

Sunlitlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-56968Low· 3.7
3mo ago

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.

Sunlitgnu · saslEPSS 0.29%via NVD
CVE-2026-11576High· 7.5
3mo ago

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file …

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file …

Twilighteclipse · threadx_netx_duoEPSS 0.46%via NVD
CVE-2026-54500Medium· 5.3
3mo ago

Oj: intern.c form_attr (uninitialized stack read)

Oj: intern.c form_attr (uninitialized stack read)

Sunlitoj · ojEPSS 0.20%via GHSA
CVE-2026-46132Medium· 5.5
3mo ago

In the Linux kernel, the following vulnerability has been resolved: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo rtnl_fill_vfinfo() declares struct ifla_vf_broadcast on the stack without initialisa…

In the Linux kernel, the following vulnerability has been resolved: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo rtnl_fill_vfinfo() declares struct ifla_vf_broadcast on the stack without initialisa…

Sunlitlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-45736Medium· 4.4PoC
4mo ago

ws is an open source WebSocket client and server for Node.js

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability i…

Twilightws_project · wsEPSS 0.74%via NVD
CVE-2026-3497Low· 2.7
6mo ago

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of s…

SunlitUbuntu · opensshEPSS 2.2%via CVEORG
CVE-2026-22188Medium· 5.5
8mo ago

The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due to unbounded stack allocation

The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due to unbounded stack allocation. The deploy-stub executable allocates argv_copy and argv_copy2 using alloca() based di…

Sunlitcmu · panda3dEPSS 0.20%via NVD
CVE-2025-9640Medium· 4.3
11mo ago

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, …

SunlitEPSS 0.46%via NVD
CVE-2025-39931Medium· 5.5
11mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Set merge to zero early in af_alg_sendmsg If an error causes af_alg_sendmsg to abort, ctx->merge may contain a garbage value from the previous loop

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Set merge to zero early in af_alg_sendmsg If an error causes af_alg_sendmsg to abort, ctx->merge may contain a garbage value from the previous loop. …

Sunlitlinux · linux_kernelEPSS 0.16%via NVD
CVE-2025-39833Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: mISDN: hfcpci: Fix warning when deleting uninitialized timer With CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpci module leads to the following splat: [ 250.215892] ODE…

In the Linux kernel, the following vulnerability has been resolved: mISDN: hfcpci: Fix warning when deleting uninitialized timer With CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpci module leads to the following splat: [ 250.215892] ODE…

Sunlitlinux · linux_kernelEPSS 0.14%via NVD
CWE-908 vulnerabilities (CVEs) — page 3 · VulnSea