Skip to content
Noroxi

CWE-909 · 80 records

Missing Initialization of Resource

CVEs in this class

80 records

  • The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expe

    CriticalCVSS 9.8No exploitEPSS 1%

    zabbix · zabbix-agent2Jan 6, 2022

  • A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write.

    HighCVSS 8.8No exploitEPSS 2%

    mozilla · firefoxJun 24, 2021

  • Phoenix Contact mGuard Devices versions before 8.8.3: LAN ports get functional after reboot even if they are disabled in the device configuration

    CriticalCVSS 9.1No exploitEPSS 1%

    phoenixcontact · tc mguard rs4000 4g vzw vpn firmwareDec 17, 2020

  • In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that

    CriticalCVSS 9.1No exploitEPSS 1%

    exim · eximApr 30, 2026

  • Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable cra

    HighCVSS 8.8No exploitEPSS 1%

    mozilla · firefoxAug 17, 2021

  • An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information a

    HighCVSS 8.8No exploitEPSS 0%

    xen · xenApr 14, 2020

  • CVE-2025-8117
    34Monitor

    Account Takeover via Reset Password Functionality in PAD CMS

    HighCVSS 8.7No exploitEPSS 0%

    widzialni · pad cmsSep 30, 2025

  • strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.

    HighCVSS 7.5No exploitEPSS 6%

    strongswan · strongswanJun 19, 2018

  • CVE-2019-3804
    31Monitor

    It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack.

    HighCVSS 7.5No exploitEPSS 5%

    cockpit-project · cockpitMar 26, 2019

  • While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left

    HighCVSS 7.5No exploitEPSS 5%

    apache · arrowNov 8, 2019

  • In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash.

    HighCVSS 7.5No exploitEPSS 4%

    wireshark · wiresharkDec 4, 2019

  • It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had

    HighCVSS 7.5No exploitEPSS 3%

    apache · arrowNov 8, 2019

  • In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack m

    HighCVSS 7.5No exploitEPSS 3%

    linux · linux kernelSep 23, 2019

  • report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mai

    HighCVSS 7.5No exploitEPSS 3%

    fetchmail · fetchmailJul 30, 2021

  • An issue was discovered in LibVNCServer before 0.9.13.

    HighCVSS 7.5No exploitEPSS 2%

    libvnc project · libvncserverJun 17, 2020

  • An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view

    HighCVSS 7.5No exploitEPSS 2%

    signalwire · freeswitchOct 18, 2021

  • An issue was discovered in the Linux kernel through 5.17.5.

    HighCVSS 7.8Proof of conceptEPSS 1%

    linux · linux kernelMay 2, 2022

  • CVE-2005-1036
    31Monitor

    FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allow

    HighCVSS 7.8No exploitEPSS 0%

    freebsd · freebsdMay 2, 2005

  • vhost/vsock: always initialize seqpacket_allow

    HighCVSS 7.8No exploitEPSS 0%

    linux · linux kernelAug 20, 2024

  • An issue was discovered in the rkyv crate before 0.6.0 for Rust.

    HighCVSS 7.5No exploitEPSS 1%

    rkyv project · rkyvApr 29, 2021

  • An issue was discovered in the pnet crate before 0.27.2 for Rust.

    HighCVSS 7.5No exploitEPSS 1%

    pnet project · pnetDec 26, 2021

  • There is an Uninitialized AOD driver structure in Smartphones.Successful exploitation of this vulnerability may affect service confidentiali

    HighCVSS 7.5No exploitEPSS 1%

    huawei · emuiJan 3, 2022

  • CVE-2021-0946
    30Monitor

    The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolic

    HighCVSS 7.5No exploitEPSS 0%

    google · androidAug 24, 2022

  • CVE-2021-0947
    30Monitor

    The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM

    HighCVSS 7.5No exploitEPSS 0%

    google · androidAug 24, 2022

  • Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

    MediumCVSS 6.5Proof of conceptEPSS 6%

    bluez · bluezNov 23, 2020

All vulnerability classes