Vulnerabilities > Use of Uninitialized Resource

DATE CVE VULNERABILITY TITLE RISK
2018-10-25 CVE-2018-3970 Use of Uninitialized Resource vulnerability in Sophos Hitmanpro.Alert 3.7.6.744
An exploitable memory disclosure vulnerability exists in the 0x222000 IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744.
local
low complexity
sophos CWE-908
5.5
2018-10-02 CVE-2018-9499 Use of Uninitialized Resource vulnerability in Google Android
In readVector of iCrypto.cpp, there is a possible invalid read due to uninitialized data.
local
low complexity
google CWE-908
5.5
2018-10-01 CVE-2018-3975 Use of Uninitialized Resource vulnerability in Atlantiswordprocessor Atlantis Word Processor 3.2.6
An exploitable uninitialized variable vulnerability exists in the RTF-parsing functionality of Atlantis Word Processor 3.2.6 version.
6.8
2018-08-28 CVE-2018-15911 Use of Uninitialized Resource vulnerability in multiple products
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
7.8
2018-07-23 CVE-2018-14551 Use of Uninitialized Resource vulnerability in multiple products
The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an uninitialized variable, leading to memory corruption.
network
low complexity
imagemagick canonical CWE-908
7.5
2018-06-11 CVE-2018-5095 Use of Uninitialized Resource vulnerability in multiple products
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM.
network
low complexity
debian redhat mozilla canonical CWE-908
7.5
2018-05-22 CVE-2018-11383 Use of Uninitialized Resource vulnerability in Radare Radare2 2.5.0
The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted ELF file because of an uninitialized variable in the CPSE handler in libr/anal/p/anal_avr.c.
network
radare CWE-908
4.3
2018-05-02 CVE-2018-10115 Use of Uninitialized Resource vulnerability in 7-Zip
Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
network
7-zip CWE-908
6.8
2018-04-12 CVE-2018-1037 Use of Uninitialized Resource vulnerability in Microsoft Visual Studio and Visual Studio 2017
An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory while compiling program database (PDB) files, aka "Microsoft Visual Studio Information Disclosure Vulnerability." This affects Microsoft Visual Studio.
network
microsoft CWE-908
4.3
2017-10-27 CVE-2017-5103 Use of Uninitialized Resource vulnerability in multiple products
Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
network
low complexity
google debian redhat CWE-908
4.3