CWE-909 · 80 records
Missing Initialization of Resource
CVEs in this class
80 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-22704No exploit | The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expezabbix · zabbix-agent2 · CWE-909 | Critical9.8 | — | 1.3% | Jan 6, 2022 |
36Monitor | CVE-2021-23994No exploit | A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write.mozilla · firefox · CWE-909 | High8.8 | — | 1.8% | Jun 24, 2021 |
36Monitor | CVE-2020-12523No exploit | Phoenix Contact mGuard Devices versions before 8.8.3: LAN ports get functional after reboot even if they are disabled in the device configurationphoenixcontact · tc mguard rs4000 4g vzw vpn firmware · CWE-909 | Critical9.1 | — | 0.9% | Dec 17, 2020 |
36Monitor | CVE-2026-40687No exploit | In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write thatexim · exim · CWE-909 | Critical9.1 | — | 0.7% | Apr 30, 2026 |
35Monitor | CVE-2021-29980No exploit | Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable cramozilla · firefox · CWE-909 | High8.8 | — | 1.4% | Aug 17, 2021 |
35Monitor | CVE-2020-11741No exploit | An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information axen · xen · CWE-909 | High8.8 | — | 0.4% | Apr 14, 2020 |
34Monitor | CVE-2025-8117No exploit | Account Takeover via Reset Password Functionality in PAD CMSwidzialni · pad cms · CWE-909 | High8.7 | — | 0.3% | Sep 30, 2025 |
32Monitor | CVE-2018-10811No exploit | strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.strongswan · strongswan · CWE-909 | High7.5 | — | 6.2% | Jun 19, 2018 |
31Monitor | CVE-2019-3804No exploit | It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack.cockpit-project · cockpit · CWE-909 | High7.5 | — | 4.9% | Mar 26, 2019 |
31Monitor | CVE-2019-12410No exploit | While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, leftapache · arrow · CWE-909 | High7.5 | — | 4.6% | Nov 8, 2019 |
31Monitor | CVE-2019-19553No exploit | In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash.wireshark · wireshark · CWE-909 | High7.5 | — | 4.1% | Dec 4, 2019 |
31Monitor | CVE-2019-12408No exploit | It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had apache · arrow · CWE-909 | High7.5 | — | 3.3% | Nov 8, 2019 |
31Monitor | CVE-2019-16714No exploit | In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack mlinux · linux kernel · CWE-909 | High7.5 | — | 2.7% | Sep 23, 2019 |
31Monitor | CVE-2021-36386No exploit | report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow maifetchmail · fetchmail · CWE-909 | High7.5 | — | 2.6% | Jul 30, 2021 |
31Monitor | CVE-2018-21247No exploit | An issue was discovered in LibVNCServer before 0.9.13.libvnc project · libvncserver · CWE-909 | High7.5 | — | 2.5% | Jun 17, 2020 |
31Monitor | CVE-2021-36513No exploit | An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to viewsignalwire · freeswitch · CWE-909 | High7.5 | — | 1.9% | Oct 18, 2021 |
31Monitor | CVE-2022-29968Proof of concept | An issue was discovered in the Linux kernel through 5.17.5.linux · linux kernel · CWE-909 | High7.8 | — | 1.1% | May 2, 2022 |
31Monitor | CVE-2005-1036No exploit | FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allowfreebsd · freebsd · CWE-909 | High7.8 | — | 0.4% | May 2, 2005 |
31Monitor | CVE-2024-43873No exploit | vhost/vsock: always initialize seqpacket_allowlinux · linux kernel · CWE-909 | High7.8 | — | 0.2% | Aug 20, 2024 |
30Monitor | CVE-2021-31919No exploit | An issue was discovered in the rkyv crate before 0.6.0 for Rust.rkyv project · rkyv · CWE-909 | High7.5 | — | 1.1% | Apr 29, 2021 |
30Monitor | CVE-2019-25054No exploit | An issue was discovered in the pnet crate before 0.27.2 for Rust.pnet project · pnet · CWE-909 | High7.5 | — | 1.0% | Dec 26, 2021 |
30Monitor | CVE-2021-39966No exploit | There is an Uninitialized AOD driver structure in Smartphones.Successful exploitation of this vulnerability may affect service confidentialihuawei · emui · CWE-909 | High7.5 | — | 0.7% | Jan 3, 2022 |
30Monitor | CVE-2021-0946No exploit | The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolicgoogle · android · CWE-909 | High7.5 | — | 0.3% | Aug 24, 2022 |
30Monitor | CVE-2021-0947No exploit | The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKMgoogle · android · CWE-909 | High7.5 | — | 0.3% | Aug 24, 2022 |
28Monitor | CVE-2020-12352Proof of concept | Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.bluez · bluez · CWE-909 | Medium6.5 | — | 5.7% | Nov 23, 2020 |
- CVE-2022-2270439Monitor
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expe
CriticalCVSS 9.8No exploitEPSS 1%zabbix · zabbix-agent2Jan 6, 2022
- CVE-2021-2399436Monitor
A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write.
HighCVSS 8.8No exploitEPSS 2%mozilla · firefoxJun 24, 2021
- CVE-2020-1252336Monitor
Phoenix Contact mGuard Devices versions before 8.8.3: LAN ports get functional after reboot even if they are disabled in the device configuration
CriticalCVSS 9.1No exploitEPSS 1%phoenixcontact · tc mguard rs4000 4g vzw vpn firmwareDec 17, 2020
- CVE-2026-4068736Monitor
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that
CriticalCVSS 9.1No exploitEPSS 1%exim · eximApr 30, 2026
- CVE-2021-2998035Monitor
Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable cra
HighCVSS 8.8No exploitEPSS 1%mozilla · firefoxAug 17, 2021
- CVE-2020-1174135Monitor
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information a
HighCVSS 8.8No exploitEPSS 0%xen · xenApr 14, 2020
- CVE-2025-811734Monitor
Account Takeover via Reset Password Functionality in PAD CMS
HighCVSS 8.7No exploitEPSS 0%widzialni · pad cmsSep 30, 2025
- CVE-2018-1081132Monitor
strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.
HighCVSS 7.5No exploitEPSS 6%strongswan · strongswanJun 19, 2018
- CVE-2019-380431Monitor
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack.
HighCVSS 7.5No exploitEPSS 5%cockpit-project · cockpitMar 26, 2019
- CVE-2019-1241031Monitor
While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left
HighCVSS 7.5No exploitEPSS 5%apache · arrowNov 8, 2019
- CVE-2019-1955331Monitor
In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash.
HighCVSS 7.5No exploitEPSS 4%wireshark · wiresharkDec 4, 2019
- CVE-2019-1240831Monitor
It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had
HighCVSS 7.5No exploitEPSS 3%apache · arrowNov 8, 2019
- CVE-2019-1671431Monitor
In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack m
HighCVSS 7.5No exploitEPSS 3%linux · linux kernelSep 23, 2019
- CVE-2021-3638631Monitor
report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, which might allow mai
HighCVSS 7.5No exploitEPSS 3%fetchmail · fetchmailJul 30, 2021
- CVE-2018-2124731Monitor
An issue was discovered in LibVNCServer before 0.9.13.
HighCVSS 7.5No exploitEPSS 2%libvnc project · libvncserverJun 17, 2020
- CVE-2021-3651331Monitor
An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view
HighCVSS 7.5No exploitEPSS 2%signalwire · freeswitchOct 18, 2021
- CVE-2022-2996831Monitor
An issue was discovered in the Linux kernel through 5.17.5.
HighCVSS 7.8Proof of conceptEPSS 1%linux · linux kernelMay 2, 2022
- CVE-2005-103631Monitor
FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allow
HighCVSS 7.8No exploitEPSS 0%freebsd · freebsdMay 2, 2005
- CVE-2024-4387331Monitor
vhost/vsock: always initialize seqpacket_allow
HighCVSS 7.8No exploitEPSS 0%linux · linux kernelAug 20, 2024
- CVE-2021-3191930Monitor
An issue was discovered in the rkyv crate before 0.6.0 for Rust.
HighCVSS 7.5No exploitEPSS 1%rkyv project · rkyvApr 29, 2021
- CVE-2019-2505430Monitor
An issue was discovered in the pnet crate before 0.27.2 for Rust.
HighCVSS 7.5No exploitEPSS 1%pnet project · pnetDec 26, 2021
- CVE-2021-3996630Monitor
There is an Uninitialized AOD driver structure in Smartphones.Successful exploitation of this vulnerability may affect service confidentiali
HighCVSS 7.5No exploitEPSS 1%huawei · emuiJan 3, 2022
- CVE-2021-094630Monitor
The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolic
HighCVSS 7.5No exploitEPSS 0%google · androidAug 24, 2022
- CVE-2021-094730Monitor
The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM
HighCVSS 7.5No exploitEPSS 0%google · androidAug 24, 2022
- CVE-2020-1235228Monitor
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
MediumCVSS 6.5Proof of conceptEPSS 6%bluez · bluezNov 23, 2020