Skip to main content

CWE archive

CWE-908 CVEs

Programmatic archive

806 CVEs tagged with CWE-90880 Critical, 214 High, 482 Medium, 30 Low, 0 Unrated.

CVE-2018-6132

Published Jun 27, 2019

Uninitialized data in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-2004

Published Jun 19, 2019

In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized data leading to local information disclosure with no addition…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11038

Published Jun 19, 2019

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19…

CVSS 5.3 · Medium

CVE-2019-7321

Published Jun 13, 2019

Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12730

Published Jun 4, 2019

aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of uninitialized variables.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9824

Published Jun 3, 2019

tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11323

Published May 9, 2019

HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h er…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9805

Published Apr 26, 2019

A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11459

Published Apr 22, 2019

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOrie…

CVSS 5.5 · Medium

CVE-2019-9578

Published Mar 5, 2019

In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12011

Published Feb 11, 2019

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized data for socket address leads to information exposure.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-3989

Published Feb 5, 2019

An exploitable kernel memory disclosure vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400).A specially crafte…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2019-6976

Published Jan 26, 2019

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c does not zero out allocated me…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0006

Published Jan 15, 2019

A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on all EX, QFX and MX Series dev…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2018-19974

Published Dec 17, 2018

In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libyara/exec.c. This can allow attackers to discover addresses i…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9557

Published Dec 6, 2018

In really_install_package of install.cpp, there is a possible free of arbitrary memory due to uninitialized data. This could lead to local escalation of privilege with no addition…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 726-750 of 806 CVEsPage 30 of 33