VulnSea

CWE-908

CVEs classified under CWE-908, newest first.

107 CVEsRSS

CVE-2025-9640Medium· 4.3
11mo ago

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams

A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, …

▾ SunlitEPSS 0.46%via NVD
CVE-2025-39931Medium· 5.5
11mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Set merge to zero early in af_alg_sendmsg If an error causes af_alg_sendmsg to abort, ctx->merge may contain a garbage value from the previous loop

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Set merge to zero early in af_alg_sendmsg If an error causes af_alg_sendmsg to abort, ctx->merge may contain a garbage value from the previous loop. …

▾ Sunlitlinux · linux_kernelEPSS 0.16%via NVD
CVE-2025-39833Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: mISDN: hfcpci: Fix warning when deleting uninitialized timer With CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpci module leads to the following splat: [ 250.215892] ODE…

In the Linux kernel, the following vulnerability has been resolved: mISDN: hfcpci: Fix warning when deleting uninitialized timer With CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpci module leads to the following splat: [ 250.215892] ODE…

▾ Sunlitlinux · linux_kernelEPSS 0.14%via NVD
CVE-2025-5777High· 7.5CISA KEVPoC
1y ago

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

▾ Abyssalcitrix · netscaler_application_delivery_controllerEPSS 100%via NVD
CVE-2025-21959Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() Since commit b36e4523d4d5 ("netfilter: nf_conncount: fix garbage collection confir…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() Since commit b36e4523d4d5 ("netfilter: nf_conncount: fix garbage collection confir…

▾ Sunlitlinux · linux_kernelEPSS 0.43%via NVD
CVE-2025-21707Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: mptcp: consolidate suboption status MPTCP maintains the received sub-options status is the bitmask carrying the received suboptions and in several bitfields carrying p…

In the Linux kernel, the following vulnerability has been resolved: mptcp: consolidate suboption status MPTCP maintains the received sub-options status is the bitmask carrying the received suboptions and in several bitfields carrying p…

▾ Sunlitlinux · linux_kernelEPSS 0.48%via NVD
CVE-2022-49132Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: ath11k: pci: fix crash on suspend if board file is not found Mario reported that the kernel was crashing on suspend if ath11k was not able to find a board file: [ 47…

In the Linux kernel, the following vulnerability has been resolved: ath11k: pci: fix crash on suspend if board file is not found Mario reported that the kernel was crashing on suspend if ath11k was not able to find a board file: [ 47…

▾ Sunlitlinux · linux_kernelEPSS 0.26%via NVD
CVE-2024-12085High· 7.5PoC
1y ago

A flaw was found in rsync which could be triggered when rsync compares file checksums

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak o…

▾ Midnightsamba · rsyncEPSS 8.8%via NVD
CVE-2024-50014Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: ext4: fix access to uninitialised lock in fc replay path The following kernel trace can be triggered with fstest generic/629 when executed against a filesystem with fa…

In the Linux kernel, the following vulnerability has been resolved: ext4: fix access to uninitialised lock in fc replay path The following kernel trace can be triggered with fstest generic/629 when executed against a filesystem with fa…

▾ Sunlitlinux · linux_kernelEPSS 0.22%via NVD
CVE-2024-45618Low· 3.9
2y ago

A vulnerability was found in pkcs15-init in OpenSC

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values …

▾ Sunlitopensc_project · openscEPSS 0.31%via NVD
CVE-2024-45617Low· 3.9
2y ago

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient o…

▾ Sunlitopensc_project · openscEPSS 0.30%via NVD
CVE-2024-45616Low· 3.9
2y ago

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following …

▾ Sunlitopensc_project · openscEPSS 0.36%via NVD
CVE-2024-45615Low· 3.9
2y ago

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).

▾ Sunlitopensc_project · openscEPSS 0.36%via NVD
CVE-2024-36927Medium· 4.7
2y ago

In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix uninit-value access in __ip_make_skb() KMSAN reported uninit-value access in __ip_make_skb() [1]

In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix uninit-value access in __ip_make_skb() KMSAN reported uninit-value access in __ip_make_skb() [1]. __ip_make_skb() tests HDRINCL to know if the skb has icmph…

▾ Sunlitlinux · linux_kernelEPSS 0.17%via NVD
CVE-2024-36903Medium· 5.5
2y ago

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix potential uninit-value access in __ip6_make_skb() As it was done in commit fc1092f51567 ("ipv4: Fix uninit-value access in __ip_make_skb()") for IPv4, check …

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix potential uninit-value access in __ip6_make_skb() As it was done in commit fc1092f51567 ("ipv4: Fix uninit-value access in __ip_make_skb()") for IPv4, check …

▾ Sunlitlinux · linux_kernelEPSS 0.23%via NVD
CVE-2024-26641High· 8.6
2y ago

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, a…

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, a…

▾ Twilightnetapp · active_iq_unified_managerEPSS 0.57%via NVD
CVE-2021-36512High· 7.5
4y ago

An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers to view sensitive information due to an uninitialized value.

An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers to view sensitive information due to an uninitialized value.

▾ Twilightsynchro · bulletin_board_systemEPSS 0.95%via NVD
CWE-908 vulnerabilities (CVEs) — page 4 · VulnSea