Threats Tagged 'cwe-908'
View all threats tagged with 'cwe-908'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-908'
Click on any threat for detailed analysis and mitigation recommendations
0 Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader adds count as populated. The TGA reader stores pixel indexes without checking them against the colour map. i_gpix_p() rejects only an index greater than the count, so an index equal to it reads the first unpopulated entry, and getpixel() returns it. i_glin_p() skips any index at or beyond the count without writing that pixel to the caller's buffer. The palette-to-RGB conversion reads each row through an uninitialised buffer, so those pixels of the converted image hold prior heap contents. Reading an attacker-supplied image through Imager->read() and then fetching its pixels or converting it to RGB discloses process heap memory. Join the discussion | CVE Database V5 | 09/18/2026, 13:57:37 UTC Added: 09/18/2026, 14:03:09 UTC |
0 CVE-2026-84267 is a vulnerability in the SFTP backend of GNOME gvfs where a malicious SFTP server can cause the client to leak uninitialized heap memory. This occurs because the read_string() function allocates a buffer without verifying it is fully filled, leading to uninitialized bytes being used as a file handle and echoed back to the server. The leaked memory includes the heap base and the load address of the libgio library, allowing deterministic defeat of ASLR. The vulnerability requires user interaction to connect to a malicious SFTP share and results in limited information disclosure without exposing user data. It has been rated with moderate severity and affects gvfs versions from 1.10.0 up to but not including 1.60.2. Join the discussion | CVE Database V5 | 09/15/2026, 00:00:00 UTC Added: 09/01/2026, 15:52:57 UTC |
0 This update for kimi-code fixes the following issues: Changes in kimi-code: Update to version 0.42.0: * Add an experimental Updates panel with paginated progress messages from the main agent and subagents, enabled with KIMI_CODE_EXPERIMENTAL_NOTIFY_USER=1 * Turn the subagent model pool, Remote Control and the minidb session-index read model with the global search worker always on; their experimental flags and opt-out variables are gone, search persistence is now tuned via the [database] section * Give tower worker and reviewer briefings the full mission context, follow the subagent timeout for tower agents, and show each background agent's model in /tasks * Retrieve file search matches beyond the first 100 results, accept HEIC, HEIF and BMP images with Kimi-served models, and warn in kimi -p when project MCP servers are skipped in an untrusted folder * Read files with configurable character limits and resumable long-line reads, decode malformed UTF-16 with a warning, and preserve image and video filenames in session history * Rework the dashboard: deletable sessions, reorderable media rail, collapsed tool calls revealed with Ctrl-O, and less jank on long conversations and session reloads Update to version 0.41.0: * Add experimental tower mode for multi-agent orchestration and Remote Control for reaching a local web session remotely * Add the WaitFor tool so the agent can wait for a background task inside the current turn, and an optional fork parameter that starts a subagent from a snapshot of the caller's history * Support two OAuth login methods, kimi.ai and kimi.com, and activate several skills in one prompt * Enable the subagent model pool in every launch mode by default and make turn-level file history unconditional * Add a dangerous-command guard that always asks before shutdown, reboot or rm -rf in manual and YOLO permission modes, disabled with [permission] dangerous_command_guard; auto mode never blocks * Remove kimi web --allow-remote-terminals; PTY terminal routes are served on loopback binds only * Require Edit and Write to read a file first, and reject a write when the file changed on disk since that read * Rework the bundled web dashboard: multi-tab right sidebar, Open/Done/Workspaces session tabs, a plugin marketplace panel and mobile bottom sheets * ... see upstream's release notes for the full list - Vendor the runtime dependencies upstream stopped inlining in 0.39.0: * Add ws, qrcode and qrcode's own pngjs and dijkstrajs as sources, installed into the package's private node_modules * Unpack the npm tarball directly instead of running npm install, which would resolve the new dependencies against the registry and pull in qrcode's CLI-only yargs tree * Declare the vendored trees with Provides: bundled(...) - CVE-2026-48779: ws denial of service from a high volume of tiny WebSocket fragments; the ws inlined in the old bundle predated the 8.21.0 fix, the vendored ws is 8.21.3 (boo#1268927) - CVE-2026-45736: ws uninitialized memory disclosure via websocket.close() with a TypedArray, fixed by the same ws version (boo#1269951) - Load the compiled node-pty addon during the build check as well Join the discussion | GCVE Database | 09/14/2026, 13:20:22 UTC Added: 06/19/2026, 19:05:59 UTC |
An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the kernel driver to the daemon lacked proper token-based message validation, allowing local unprivileged processes to send unauthorized queries. Additionally, a reply buffer used by the port message handler was not properly initialized before returning data, leaking residual kernel pool memory from prior allocations. A local unprivileged attacker could exploit this vulnerability to enumerate DLP configuration and feature flags, extract live session tokens, and read kernel memory fragments from other users' operations. Join the discussion | CVE Database V5 | 09/11/2026, 13:57:02 UTC Added: 09/11/2026, 14:02:29 UTC |
0 Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:18:57 UTC Added: 09/08/2026, 17:27:15 UTC |
0 Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:18:56 UTC Added: 09/08/2026, 17:27:11 UTC |
0 Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 09/08/2026, 17:18:46 UTC Added: 09/08/2026, 17:27:04 UTC |
0 Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. Join the discussion | CVE Database V5 | 09/08/2026, 17:18:37 UTC Added: 09/08/2026, 17:27:00 UTC |
0 Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 09/08/2026, 17:17:48 UTC Added: 09/08/2026, 17:26:37 UTC |
0 Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:16:35 UTC Added: 09/08/2026, 17:26:12 UTC |
Showing 1 to 10 of 121 results