Vulnerabilities > Use of Uninitialized Resource

DATE CVE VULNERABILITY TITLE RISK
2021-10-19 CVE-2021-36512 Use of Uninitialized Resource vulnerability in Synchro Bulletin Board System
An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers to view sensitive information due to an uninitialized value.
network
low complexity
synchro CWE-908
7.5
2021-09-23 CVE-2021-1619 Use of Uninitialized Resource vulnerability in Cisco products
A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory corruption that results in a denial of service (DoS) on an affected device This vulnerability is due to an uninitialized variable.
network
low complexity
cisco CWE-908
critical
9.1
2021-08-30 CVE-2021-29631 Use of Uninitialized Resource vulnerability in Freebsd 11.4/12.2/13.0
In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, certain VirtIO-based device models in bhyve failed to handle errors when fetching I/O descriptors.
local
low complexity
freebsd CWE-908
7.8
2021-08-18 CVE-2021-21781 Use of Uninitialized Resource vulnerability in multiple products
An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54.
local
low complexity
linux oracle CWE-908
3.3
2021-08-16 CVE-2021-36282 Use of Uninitialized Resource vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS versions 8.2.x - 9.1.0.x contain a use of uninitialized resource vulnerability.
local
low complexity
dell CWE-908
3.3
2021-08-13 CVE-2021-1104 Use of Uninitialized Resource vulnerability in Risc-V Instruction SET Manual
The RISC-V Instruction Set Manual contains a documented ambiguity for the Machine Trap Vector Base Address (MTVEC) register that may lead to a vulnerability due to the initial state of the register not being defined, potentially leading to information disclosure, data tampering and denial of service.
network
low complexity
risc-v CWE-908
critical
9.8
2021-08-08 CVE-2020-36432 Use of Uninitialized Resource vulnerability in ALG DS Project ALG DS
An issue was discovered in the alg_ds crate through 2020-08-25 for Rust.
network
low complexity
alg-ds-project CWE-908
critical
9.8
2021-08-08 CVE-2020-36443 Use of Uninitialized Resource vulnerability in Libp2P Libp2P-Deflate
An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust.
network
low complexity
libp2p CWE-908
critical
9.8
2021-08-08 CVE-2020-36452 Use of Uninitialized Resource vulnerability in Array-Tools Project Array-Tools
An issue was discovered in the array-tools crate before 0.3.2 for Rust.
network
low complexity
array-tools-project CWE-908
critical
9.8
2021-08-05 CVE-2021-22925 Use of Uninitialized Resource vulnerability in multiple products
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl.
5.3