Vulnerabilities > Use of Uninitialized Resource

DATE CVE VULNERABILITY TITLE RISK
2024-08-13 CVE-2024-38118 Use of Uninitialized Resource vulnerability in Microsoft products
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
local
low complexity
microsoft CWE-908
5.5
2024-08-13 CVE-2024-38122 Use of Uninitialized Resource vulnerability in Microsoft products
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
local
low complexity
microsoft CWE-908
5.5
2024-08-06 CVE-2024-7526 Use of Uninitialized Resource vulnerability in Mozilla Firefox
ANGLE failed to initialize parameters which lead to reading from uninitialized memory.
network
low complexity
mozilla CWE-908
6.5
2024-08-06 CVE-2024-7540 Use of Uninitialized Resource vulnerability in Ofono Project Ofono 1.34
oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability.
local
low complexity
ofono-project CWE-908
3.3
2024-08-06 CVE-2024-7541 Use of Uninitialized Resource vulnerability in Ofono Project Ofono 1.34
oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability.
local
low complexity
ofono-project CWE-908
3.3
2024-08-06 CVE-2024-7542 Use of Uninitialized Resource vulnerability in Ofono Project Ofono 1.34
oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability.
local
low complexity
ofono-project CWE-908
3.3
2024-08-01 CVE-2024-6990 Use of Uninitialized Resource vulnerability in Google Chrome
Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
network
low complexity
google CWE-908
8.8
2024-07-30 CVE-2024-42161 Use of Uninitialized Resource vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid uninitialized value in BPF_CORE_READ_BITFIELD [Changes from V1: - Use a default branch in the switch statement to initialize `val'.] GCC warns that `val' may be used uninitialized in the BPF_CRE_READ_BITFIELD macro, defined in bpf_core_read.h as: [...] unsigned long long val; \ [...] \ switch (__CORE_RELO(s, field, BYTE_SIZE)) { \ case 1: val = *(const unsigned char *)p; break; \ case 2: val = *(const unsigned short *)p; break; \ case 4: val = *(const unsigned int *)p; break; \ case 8: val = *(const unsigned long long *)p; break; \ } \ [...] val; \ } \ This patch adds a default entry in the switch statement that sets `val' to zero in order to avoid the warning, and random values to be used in case __builtin_preserve_field_info returns unexpected values for BPF_FIELD_BYTE_SIZE. Tested in bpf-next master. No regressions.
local
low complexity
linux CWE-908
7.8
2024-07-30 CVE-2024-42225 Use of Uninitialized Resource vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data
high complexity
linux CWE-908
7.5
2024-07-30 CVE-2024-42228 Use of Uninitialized Resource vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc Initialize the size before calling amdgpu_vce_cs_reloc, such as case 0x03000001. V2: To really improve the handling we would actually need to have a separate value of 0xffffffff.(Christian)
local
high complexity
linux CWE-908
7.0