Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-908'

View all threats tagged with 'cwe-908'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-908

Threats Tagged 'cwe-908'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-70317: CWE-908: Use of Uninitialized Resource in Microsoft Microsoft 365 Apps for EnterpriseCVE-2026-70317
0

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

Join the discussion
CVE-2026-68799: CWE-908: Use of Uninitialized Resource in Microsoft Microsoft 365 Apps for EnterpriseCVE-2026-68799
0

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Join the discussion
CVE-2026-62740: CWE-908: Use of Uninitialized Resource in Microsoft Windows 10 Version 1607CVE-2026-62740
0

Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.

Join the discussion
CVE-2026-62709: CWE-908: Use of Uninitialized Resource in Microsoft Windows 10 Version 1607CVE-2026-62709
0

Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

Join the discussion
CVE-2026-59137: CWE-908: Use of Uninitialized Resource in Microsoft Windows 10 Version 1607CVE-2026-59137
0

Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.

Join the discussion
CVE-2026-59136: CWE-908: Use of Uninitialized Resource in Microsoft Windows 10 Version 1607CVE-2026-59136
0

Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.

Join the discussion
CVE-2026-58247: CWE-908: Use of Uninitialized Resource in SAP_SE SAP ABAP PlatformCVE-2026-58247
0

SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading to a low on confidentiality, with no impact on integrity and availability of the application.

Join the discussion
CVE-2026-47247: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in strukturag libheifCVE-2026-47247
0

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue.

Join the discussion
CVE-2026-60005: CWE-908 Use of Uninitialized Resource in F5 NGINX PlusCVE-2026-60005
0

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Join the discussion
CVE-2026-58546: CWE-908: Use of Uninitialized Resource in Microsoft Windows 10 Version 1607CVE-2026-58546
0

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

Join the discussion

Showing 1 to 10 of 27 results

Filters:Tag: cwe-908
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses