Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-908

Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.

807
Assigned CVEs
53rd
Commonality Rank
6.5
Avg CVSS
0.4%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-908 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 12, 2007
19 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

807 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-5777HIGH
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
Jun 17, 20257.598YESYES
CVE-2023-24941CRITICAL
Windows Network File System Remote Code Execution Vulnerability
May 9, 20239.881NONO
CVE-2008-0081CRITICAL
Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via cra
Jan 16, 20089.873NOYES
CVE-2011-1255HIGH
The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remot
Jun 16, 20119.367NOYES
CVE-2007-1751HIGH
Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to p
Jun 12, 20079.359NONO
CVE-2024-50302MEDIUM
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in variou
Nov 19, 20245.558YESNO
CVE-2024-29745MEDIUM
there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interacti
Apr 5, 20245.557YESNO
CVE-2009-2692HIGH
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local use
Aug 14, 20097.853NOYES
CVE-2012-1891CRITICAL
Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary cod
Jul 10, 20129.847NONO
CVE-2020-1934MEDIUM
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
Apr 1, 20205.346NONO
View all 807 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
43%
19%
5.0-5.9
11%
16%
6.0-6.9
23%
26%
7.0-7.9
11%
8.0-8.9
10%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
3 CVEs
0.4% of CVEs· 83rd percentile
Metasploit
1 CVE
0.1% of CVEs· 79th percentile
Nuclei
2 CVEs
0.2% of CVEs· 78th percentile
ExploitDB
6 CVEs
0.7% of CVEs· 79th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products