Vulnerability index

Browse CVEs

744 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use of Uninitialized ResourceCWE-908 × clear
MEDIUM 6.5 CVE-2026-11089 Uninitialized Use in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain poten… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 MEDIUM 5.3 CVE-2026-26825 A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() a… Libxls No fix yet Fix from $1,6002026-06-03 MEDIUM 5.5 CVE-2026-46257 In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/timer-sp804: Fix an Oops when read_current_timer is called o… Linux Kernel 6.19.4+ Fix from $1,6002026-06-03 MEDIUM 5.5 CVE-2026-46186 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: validate rx pkt_type header length virtbt_rx_handle() rea… Linux Kernel 5.15.209 / 6.1+ Fix from $1,6002026-05-28 MEDIUM 5.5 CVE-2026-46167 In the Linux kernel, the following vulnerability has been resolved: usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl Just like in a pr… Linux Kernel 5.10.258 / 5.15.209+ Fix from $1,6002026-05-28 MEDIUM 5.5 CVE-2026-46169 In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix uninit-value by validating catalog record size Syzbot reported a K… Linux Kernel 6.6.140 / 6.12.88+ Fix from $1,6002026-05-28 MEDIUM 5.5 CVE-2026-46139 In the Linux kernel, the following vulnerability has been resolved: smb: client: use kzalloc to zero-initialize security descriptor buffer Commit 6… Linux Kernel 6.12.88 / 6.14+ Fix from $1,6002026-05-28 MEDIUM 5.5 CVE-2026-46132 In the Linux kernel, the following vulnerability has been resolved: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfin… Linux Kernel 5.10.258 / 5.15.209+ Fix from $1,6002026-05-28 HIGH 7.1 CVE-2026-47272 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare() function in src/pad.c only … Mitigation only Fix from $1,9502026-05-27 MEDIUM 5.5 CVE-2026-45886 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix bpf_xdp_store_bytes proto for read-only arg While making some maps in … Linux Kernel 6.1.165 / 6.6.128+ Fix from $1,6002026-05-27 MEDIUM 5.5 CVE-2025-71311 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN reports an uninitialized value… Linux Kernel 6.12.75 / 6.18.14+ Fix from $1,6002026-05-27 MEDIUM 6.5 CVE-2026-32814 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false … Mitigation only Fix from $1,6002026-05-19 HIGH 7.5 CVE-2026-45736 ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized me… Ws 8.20.1+ Fix from $1,9502026-05-15 MEDIUM 6.9 CVE-2025-48513 Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory result… Mitigation only Fix from $1,6002026-05-15 HIGH 8.4 CVE-2026-40364 Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-05-12 MEDIUM 5.5 CVE-2026-43472 In the Linux kernel, the following vulnerability has been resolved: unshare: fix unshare_fs() handling There's an unpleasant corner case in unshare… Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,6002026-05-08 MEDIUM 5.5 CVE-2026-43474 In the Linux kernel, the following vulnerability has been resolved: fs: init flags_valid before calling vfs_fileattr_get syzbot reported a uninit-v… Linux Kernel 6.18.19 / 6.19.9+ Fix from $1,6002026-05-08 HIGH 7.8 CVE-2026-43456 In the Linux kernel, the following vulnerability has been resolved: bonding: fix type confusion in bond_setup_by_slave() kernel BUG at net/core/skb… Linux Kernel 6.12.78 / 6.18.19+ Fix from $1,9502026-05-08 HIGH 7.5 CVE-2026-43405 In the Linux kernel, the following vulnerability has been resolved: libceph: Use u32 for non-negative values in ceph_monmap_decode() This patch fix… Linux Kernel 5.15.203 / 6.1.167+ Fix from $1,9502026-05-08 MEDIUM 5.5 CVE-2026-43349 In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid uninit-value access in f2fs_sanity_check_node_footer syzbot … Linux Kernel 6.18.25 / 7.0+ Fix from $1,6002026-05-08 HIGH 8.3 CVE-2026-43291 In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Fix parameter validation for packet data Since commit 9c328f5474… Linux Kernel 5.15.202 / 6.1.165+ Fix from $1,9502026-05-08 MEDIUM 5.5 CVE-2026-43288 In the Linux kernel, the following vulnerability has been resolved: ext4: move ext4_percpu_param_init() before ext4_mb_init() When running `kvm-xfs… Linux Kernel 6.6.128 / 6.12.75+ Fix from $1,6002026-05-08 MEDIUM 5.5 CVE-2026-43221 In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: initialise event handler read bytes IPMB doesn't use i2c reads, but… Linux Kernel 6.1.165 / 6.6.128+ Fix from $1,6002026-05-06 MEDIUM 5.5 CVE-2026-43160 In the Linux kernel, the following vulnerability has been resolved: mfd: macsmc: Initialize mutex Initialize struct apple_smc's mutex in apple_smc_… Linux Kernel 6.18.16 / 6.19.6+ Fix from $1,6002026-05-06 HIGH 8.6 CVE-2026-43139 In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() xfrm6_get_saddr() does not … Linux Kernel 5.10.252 / 5.15.202+ Fix from $1,9502026-05-06 MEDIUM 5.5 CVE-2026-43035 In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to pr… Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,6002026-05-01 MEDIUM 5.5 CVE-2026-43036 In the Linux kernel, the following vulnerability has been resolved: net: use skb_header_pointer() for TCPv4 GSO frag_off check Syzbot reported a KM… Linux Kernel 6.12.81 / 6.18.22+ Fix from $1,6002026-05-01 HIGH 7.8 CVE-2026-31693 In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we … Linux Kernel 6.6.128 / 6.12.75+ Fix from $1,9502026-04-30 MEDIUM 5.6 CVE-2026-7141 A vulnerability was found in vllm up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of th… Vllm after 0.19.0 Fix from $1,6002026-04-27 MEDIUM 5.5 CVE-2026-31621 In the Linux kernel, the following vulnerability has been resolved: bnge: return after auxiliary_device_uninit() in error path When auxiliary_devic… Linux Kernel 6.19.14 / 7.0.1+ Fix from $1,6002026-04-24