<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Uninitialized Memory (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/uninit-memory.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/uninit-memory-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Uninitialized Memory (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:27 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-46123 – In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46123</guid>
    <pubDate>Thu, 28 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46123</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: virtio_bt: clamp rx length before skb_put  virtbt_rx_work() calls skb_put(skb, len) where len comes directly from virtqueue_get_buf() with no validation against the buffer we posted to the device. The RX skb is allocated in virtbt_add_inbuf() and exposed to virtio as exactly 1000 bytes via sg_init_one().  Checking len…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43427 – In the Linux kernel, the following vulnerability has been resolved:

usb: class:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43427</guid>
    <pubDate>Fri, 08 May 2026 15:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43427</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  usb: class: cdc-wdm: fix reordering issue in read code path  Quoting the bug report:  Due to compiler optimization or CPU out-of-order execution, the desc->length update can be reordered before the memmove. If this happens, wdm_read() can see the new length and call copy_to_user() on uninitialized memory. This also violates LKMM…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6751 – Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6751</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6751</strong></p>
  <p>Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6749 – Information disclosure due to uninitialized memory in the Graphics: Canvas2D com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6749</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6749</strong></p>
  <p>Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6748 – Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6748</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6748</strong></p>
  <p>Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31790 – Issue summary: Applications using RSASVE key encapsulation to establish
a secret...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31790</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31790</strong></p>
  <p>Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4716 – Incorrect boundary conditions, uninitialized memory in the JavaScript Engine com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4716</guid>
    <pubDate>Tue, 24 Mar 2026 13:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4716</strong></p>
  <p>Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4715 – Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4715</guid>
    <pubDate>Tue, 24 Mar 2026 13:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4715</strong></p>
  <p>Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32829 – lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32829</guid>
    <pubDate>Fri, 20 Mar 2026 01:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32829</strong></p>
  <p>lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0,  decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from previous decompression operations. The library fails to properly validate offset values during LZ4 "match copy operations," allowing out-of-bounds reads from the output buffer. The block-…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-2806 – Uninitialized memory in the Graphics: Text component. This vulnerability was fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2806</guid>
    <pubDate>Tue, 24 Feb 2026 14:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2806</strong></p>
  <p>Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2794 – Information disclosure due to uninitialized memory in Firefox and Firefox Focus ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2794</guid>
    <pubDate>Tue, 24 Feb 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2794</strong></p>
  <p>Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 148.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2044 – GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2044</guid>
    <pubDate>Fri, 20 Feb 2026 23:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2044</strong></p>
  <p>GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.  The specific flaw exists within the parsing of PGM files. The issue results from t…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61917 – n8n is an open source workflow automation platform. From version 1.65.0 to befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61917</guid>
    <pubDate>Wed, 04 Feb 2026 17:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61917</strong></p>
  <p>n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to allocate uninitialized memory. Such uninitialized buffers could contain residual data from within the same Node.js process (for example, data from prior requests, tasks, secrets, or tokens), resulting i…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55131 – A flaw in Node.js's buffer allocation logic can expose uninitialized memory when...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55131</guid>
    <pubDate>Tue, 20 Jan 2026 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55131</strong></p>
  <p>A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like `Uint8Array` may contain leftover data from previous operations, allowing in-process secrets like tokens or passwords to leak o…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15281 – Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Lib...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15281</guid>
    <pubDate>Tue, 20 Jan 2026 14:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15281</strong></p>
  <p>Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10021 – A Use of Uninitialized Variable vulnerability exists in Open Design Alliance Dra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10021</guid>
    <pubDate>Mon, 22 Dec 2025 16:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10021</strong></p>
  <p>A Use of Uninitialized Variable vulnerability exists in Open Design Alliance Drawings SDK static versions (mt) before 2026.12. Static object `COdaMfcAppApp theApp` may access `OdString::kEmpty` before its initialization. Due to undefined initialization order of static objects across translation units (Static Initialization Order Fiasco), the application accesses uninitialized memory. This results…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-40829 – A vulnerability has been identified in Simcenter Femap (All versions &lt; V2512). T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40829</guid>
    <pubDate>Fri, 12 Dec 2025 09:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-40829</strong></p>
  <p>A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uninitialized memory vulnerability while parsing specially crafted SLDPRT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-27146)</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64181 – OpenEXR provides the specification and reference implementation of the EXR file ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64181</guid>
    <pubDate>Mon, 10 Nov 2025 22:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64181</strong></p>
  <p>OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing `openexr_exrcheck_fuzzer`, Valgrind reports a conditional branch depending on uninitialized data inside `generic_unpack`. This indicates a use of uninitialized memory. The issue can r…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-1942 – When String.toUpperCase() caused a string to get longer it was possible for unin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1942</guid>
    <pubDate>Tue, 04 Mar 2025 14:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-1942</strong></p>
  <p>When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20882 – Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20882</guid>
    <pubDate>Tue, 04 Feb 2025 08:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20882</strong></p>
  <p>Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-12085 – A flaw was found in rsync which could be triggered when rsync compares file chec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12085</guid>
    <pubDate>Tue, 14 Jan 2025 18:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-12085</strong></p>
  <p>A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53142 – In the Linux kernel, the following vulnerability has been resolved:

initramfs: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53142</guid>
    <pubDate>Fri, 06 Dec 2024 10:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53142</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  initramfs: avoid filename buffer overrun  The initramfs filename field is defined in Documentation/driver-api/early-userspace/buffer-format.rst as:   37 cpio_file := ALGN(4) + cpio_header + filename + "\0" + ALGN(4) + data ...  55 ============= ================== =========================  56 Field name    Field size         Mea…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49861 – In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix he...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49861</guid>
    <pubDate>Mon, 21 Oct 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49861</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix helper writes to read-only maps  Lonial found an issue that despite user- and BPF-side frozen BPF map (like in case of .rodata), it was still possible to write into it from a BPF program side through specific helpers having ARG_PTR_TO_{LONG,INT} as arguments.  In check_func_arg() when the argument is as mentioned, the m…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-48855 – In the Linux kernel, the following vulnerability has been resolved:

sctp: fix k...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48855</guid>
    <pubDate>Tue, 16 Jul 2024 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-48855</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  sctp: fix kernel-infoleak for SCTP sockets  syzbot reported a kernel infoleak [1] of 4 bytes.  After analysis, it turned out r->idiag_expires is not initialized if inet_sctp_diag_fill() calls inet_diag_msg_common_fill()  Make sure to clear idiag_timer/idiag_retrans/idiag_expires and let inet_diag_msg_sctpasoc_fill() fill them ag…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35849 – In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35849</guid>
    <pubDate>Fri, 17 May 2024 15:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35849</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix information leak in btrfs_ioctl_logical_to_ino()  Syzbot reported the following information leak for in btrfs_ioctl_logical_to_ino():    BUG: KMSAN: kernel-infoleak in instrument_copy_to_user include/linux/instrumented.h:114 [inline]   BUG: KMSAN: kernel-infoleak in _copy_to_user+0xbc/0x110 lib/usercopy.c:40    instru…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-35715 – Ashlar-Vellum Cobalt AR File Parsing Uninitialized Memory Remote Code Execution ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35715</guid>
    <pubDate>Fri, 03 May 2024 02:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-35715</strong></p>
  <p>Ashlar-Vellum Cobalt AR File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.  The specific flaw exists within the parsing of AR f…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-824</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-35713 – Ashlar-Vellum Cobalt XE File Parsing Uninitialized Memory Remote Code Execution ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35713</guid>
    <pubDate>Fri, 03 May 2024 02:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-35713</strong></p>
  <p>Ashlar-Vellum Cobalt XE File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.  The specific flaw exists within the parsing of XE f…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-824</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-35712 – Ashlar-Vellum Cobalt XE File Parsing Uninitialized Memory Remote Code Execution ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35712</guid>
    <pubDate>Fri, 03 May 2024 02:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-35712</strong></p>
  <p>Ashlar-Vellum Cobalt XE File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.  The specific flaw exists within the parsing of XE f…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-824</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-34310 – Ashlar-Vellum Cobalt Uninitialized Memory Remote Code Execution Vulnerability. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34310</guid>
    <pubDate>Fri, 03 May 2024 02:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-34310</strong></p>
  <p>Ashlar-Vellum Cobalt Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.  The specific flaw exists within the parsing of CO files. The issue…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20892 – The vCenter Server contains a heap overflow vulnerability due to the usage of un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20892</guid>
    <pubDate>Thu, 22 Jun 2023 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20892</strong></p>
  <p>The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts vCenter Server.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32846 – HyperKit is a toolkit for embedding hypervisor capabilities in an application. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32846</guid>
    <pubDate>Fri, 17 Feb 2023 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32846</strong></p>
  <p>HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vtsock_proc_tx` in `virtio-sock` can lead to to uninitialized memory use. In this situation, there is a check for the return value to be less or equal to `VTSOCK_MAXSEGS`, but that check is not sufficient because the function can return `-1` if it finds an error it cannot recover f…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2950 – Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2950</guid>
    <pubDate>Tue, 13 Dec 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2950</strong></p>
  <p>Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to increment a counter leading to memory corruption.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2949 – Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2949</guid>
    <pubDate>Tue, 13 Dec 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2949</strong></p>
  <p>Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to increment a counter leading to memory corruption.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29240 – Scylla is a real-time big data database that is API-compatible with Apache Cassa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29240</guid>
    <pubDate>Thu, 15 Sep 2022 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29240</strong></p>
  <p>Scylla is a real-time big data database that is API-compatible with Apache Cassandra and Amazon DynamoDB. When decompressing CQL frame received from user, Scylla assumes that user-provided uncompressed length is correct. If user provides fake length, that is greater than the real one, part of decompression buffer won't be overwritten, and will be left uninitialized. This can be exploited in sever…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39046 – An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39046</guid>
    <pubDate>Wed, 31 Aug 2022 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39046</strong></p>
  <p>An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43848 – h2o is an open source http server. In code prior to the `8c0eca3` commit h2o may...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43848</guid>
    <pubDate>Tue, 01 Feb 2022 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43848</strong></p>
  <p>h2o is an open source http server. In code prior to the `8c0eca3` commit h2o may attempt to access uninitialized memory. When receiving QUIC frames in certain order, HTTP/3 server-side implementation of h2o can be misguided to treat uninitialized memory as HTTP/3 frames that have been received. When h2o is used as a reverse proxy, an attacker can abuse this vulnerability to send internal state of…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45703 – An issue was discovered in the tectonic_xdv crate before 0.1.12 for Rust. XdvPar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45703</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45703</strong></p>
  <p>An issue was discovered in the tectonic_xdv crate before 0.1.12 for Rust. XdvParser::<T>::process may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45694 – An issue was discovered in the rdiff crate through 2021-02-03 for Rust. Window m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45694</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45694</strong></p>
  <p>An issue was discovered in the rdiff crate through 2021-02-03 for Rust. Window may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45693 – An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45693</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45693</strong></p>
  <p>An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string_primitive may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45692 – An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45692</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45692</strong></p>
  <p>An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_extension_others may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45691 – An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45691</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45691</strong></p>
  <p>An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45690 – An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45690</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45690</strong></p>
  <p>An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_binary may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45689 – An issue was discovered in the gfx-auxil crate through 2021-01-07 for Rust. gfx_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45689</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45689</strong></p>
  <p>An issue was discovered in the gfx-auxil crate through 2021-01-07 for Rust. gfx_auxil::read_spirv may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45688 – An issue was discovered in the ash crate before 0.33.1 for Rust. util::read_spv ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45688</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45688</strong></p>
  <p>An issue was discovered in the ash crate before 0.33.1 for Rust. util::read_spv may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45686 – An issue was discovered in the csv-sniffer crate through 2021-01-05 for Rust. pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45686</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45686</strong></p>
  <p>An issue was discovered in the csv-sniffer crate through 2021-01-05 for Rust. preamble_skipcount may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45685 – An issue was discovered in the columnar crate through 2021-01-07 for Rust. Colum...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45685</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45685</strong></p>
  <p>An issue was discovered in the columnar crate through 2021-01-07 for Rust. ColumnarReadExt::read_typed_vec may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45684 – An issue was discovered in the flumedb crate through 2021-01-07 for Rust. read_e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45684</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45684</strong></p>
  <p>An issue was discovered in the flumedb crate through 2021-01-07 for Rust. read_entry may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45683 – An issue was discovered in the binjs_io crate through 2021-01-03 for Rust. The R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45683</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45683</strong></p>
  <p>An issue was discovered in the binjs_io crate through 2021-01-03 for Rust. The Read method may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45682 – An issue was discovered in the bronzedb-protocol crate through 2021-01-03 for Ru...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45682</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45682</strong></p>
  <p>An issue was discovered in the bronzedb-protocol crate through 2021-01-03 for Rust. ReadKVExt may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-36514 – An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36514</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-36514</strong></p>
  <p>An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. fill_buf may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-36513 – An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. rea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36513</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-36513</strong></p>
  <p>An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. read_up_to may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-36512 – An issue was discovered in the buffoon crate through 2020-12-31 for Rust. InputS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36512</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-36512</strong></p>
  <p>An issue was discovered in the buffoon crate through 2020-12-31 for Rust. InputStream::read_exact may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36511 – An issue was discovered in the bite crate through 2020-12-31 for Rust. read::Bit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36511</guid>
    <pubDate>Mon, 27 Dec 2021 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36511</strong></p>
  <p>An issue was discovered in the bite crate through 2020-12-31 for Rust. read::BiteReadExpandedExt::read_framed_max may read from uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29980 – Uninitialized memory in a canvas object could have caused an incorrect free() le...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29980</guid>
    <pubDate>Tue, 17 Aug 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29980</strong></p>
  <p>Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-909</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-36452 – An issue was discovered in the array-tools crate before 0.3.2 for Rust. FixedCap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36452</guid>
    <pubDate>Sun, 08 Aug 2021 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-36452</strong></p>
  <p>An issue was discovered in the array-tools crate before 0.3.2 for Rust. FixedCapacityDequeLike::clone() has a drop of uninitialized memory.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-36432 – An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36432</guid>
    <pubDate>Sun, 08 Aug 2021 06:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-36432</strong></p>
  <p>An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matrix::new().</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11260 – An improper free of uninitialized memory can occur in DIAG services in Snapdrago...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11260</guid>
    <pubDate>Wed, 09 Jun 2021 05:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11260</strong></p>
  <p>An improper free of uninitialized memory can occur in DIAG services in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-30454 – An issue was discovered in the outer_cgi crate before 0.2.1 for Rust. A user-pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30454</guid>
    <pubDate>Wed, 07 Apr 2021 22:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-30454</strong></p>
  <p>An issue was discovered in the outer_cgi crate before 0.2.1 for Rust. A user-provided Read instance receives an uninitialized memory buffer from KeyValueReader.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-29937 – An issue was discovered in the telemetry crate through 2021-02-17 for Rust. Ther...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29937</guid>
    <pubDate>Thu, 01 Apr 2021 05:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-29937</strong></p>
  <p>An issue was discovered in the telemetry crate through 2021-02-17 for Rust. There is a drop of uninitialized memory if a value.clone() call panics within misc::vec_with_size().</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-29936 – An issue was discovered in the adtensor crate through 2021-01-11 for Rust. There...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29936</guid>
    <pubDate>Thu, 01 Apr 2021 05:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-29936</strong></p>
  <p>An issue was discovered in the adtensor crate through 2021-01-11 for Rust. There is a drop of uninitialized memory via the FromIterator implementation for Vector and Matrix.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29934 – An issue was discovered in PartialReader in the uu_od crate before 0.0.4 for Rus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29934</guid>
    <pubDate>Thu, 01 Apr 2021 05:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29934</strong></p>
  <p>An issue was discovered in PartialReader in the uu_od crate before 0.0.4 for Rust. Attackers can read the contents of uninitialized memory locations via a user-provided Read operation.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29930 – An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A dro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29930</guid>
    <pubDate>Thu, 01 Apr 2021 05:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29930</strong></p>
  <p>An issue was discovered in the arenavec crate through 2021-01-12 for Rust. A drop of uninitialized memory can sometimes occur upon a panic in T::default().</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-10196 – A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10196</guid>
    <pubDate>Fri, 19 Mar 2021 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-10196</strong></p>
  <p>A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-28035 – An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28035</guid>
    <pubDate>Fri, 05 Mar 2021 09:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-28035</strong></p>
  <p>An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a drop of uninitialized memory can occur upon a val.clone() panic.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-28033 – An issue was discovered in the byte_struct crate before 0.6.1 for Rust. There ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28033</guid>
    <pubDate>Fri, 05 Mar 2021 09:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-28033</strong></p>
  <p>An issue was discovered in the byte_struct crate before 0.6.1 for Rust. There can be a drop of uninitialized memory if a certain deserialization method panics.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-28030 – An issue was discovered in the truetype crate before 0.30.1 for Rust. Attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28030</guid>
    <pubDate>Fri, 05 Mar 2021 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-28030</strong></p>
  <p>An issue was discovered in the truetype crate before 0.30.1 for Rust. Attackers can read the contents of uninitialized memory locations via a user-provided Read operation within Tape::take_bytes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-28029 – An issue was discovered in the toodee crate before 0.3.0 for Rust. The row-inser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28029</guid>
    <pubDate>Fri, 05 Mar 2021 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-28029</strong></p>
  <p>An issue was discovered in the toodee crate before 0.3.0 for Rust. The row-insertion feature allows attackers to read the contents of uninitialized memory locations.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26953 – An issue was discovered in the postscript crate before 0.14.0 for Rust. It might...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26953</guid>
    <pubDate>Tue, 09 Feb 2021 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26953</strong></p>
  <p>An issue was discovered in the postscript crate before 0.14.0 for Rust. It might allow attackers to obtain sensitive information from uninitialized memory locations via a user-provided Read implementation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-26952 – An issue was discovered in the ms3d crate before 0.1.3 for Rust. It might allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26952</guid>
    <pubDate>Tue, 09 Feb 2021 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-26952</strong></p>
  <p>An issue was discovered in the ms3d crate before 0.1.3 for Rust. It might allow attackers to obtain sensitive information from uninitialized memory locations via IoReader::read.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-26951 – An issue was discovered in the calamine crate before 0.17.0 for Rust. It allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26951</guid>
    <pubDate>Tue, 09 Feb 2021 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-26951</strong></p>
  <p>An issue was discovered in the calamine crate before 0.17.0 for Rust. It allows attackers to overwrite heap-memory locations because Vec::set_len is used without proper memory claiming, and this uninitialized memory is used for a user-provided Read operation, as demonstrated by Sectors::get.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-25905 – An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25905</guid>
    <pubDate>Tue, 26 Jan 2021 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-25905</strong></p>
  <p>An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized memory.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36210 – An issue was discovered in the autorand crate before 0.2.3 for Rust. Because of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36210</guid>
    <pubDate>Tue, 26 Jan 2021 18:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36210</strong></p>
  <p>An issue was discovered in the autorand crate before 0.2.3 for Rust. Because of impl Random on arrays, uninitialized memory can be dropped when a panic occurs, leading to memory corruption.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-28381 – A vulnerability has been identified in Solid Edge SE2020 (All Versions &lt; SE2020M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28381</guid>
    <pubDate>Tue, 12 Jan 2021 21:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-28381</strong></p>
  <p>A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could result in an out of bounds write into uninitialized memory. An attacker could leverage this vulnerability to execute code in the context of the current process.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-35893 – An issue was discovered in the simple-slab crate before 0.3.3 for Rust. remove()...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35893</guid>
    <pubDate>Thu, 31 Dec 2020 10:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-35893</strong></p>
  <p>An issue was discovered in the simple-slab crate before 0.3.3 for Rust. remove() has an off-by-one error, causing memory leakage and a drop of uninitialized memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-193</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-35888 – An issue was discovered in the arr crate through 2020-08-25 for Rust. Uninitiali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35888</guid>
    <pubDate>Thu, 31 Dec 2020 10:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-35888</strong></p>
  <p>An issue was discovered in the arr crate through 2020-08-25 for Rust. Uninitialized memory is dropped by Array::new_from_template.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-35878 – An issue was discovered in the ozone crate through 2020-07-04 for Rust. Memory s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35878</guid>
    <pubDate>Thu, 31 Dec 2020 10:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-35878</strong></p>
  <p>An issue was discovered in the ozone crate through 2020-07-04 for Rust. Memory safety is violated because of the dropping of uninitialized memory.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7925 – Incorrect validation of user input in the role name parser may lead to use of un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7925</guid>
    <pubDate>Mon, 23 Nov 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7925</strong></p>
  <p>Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-475</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26148 – md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26148</guid>
    <pubDate>Wed, 30 Sep 2020 18:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26148</strong></p>
  <p>md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial of service (e.g., assertion failure) via a malformed Markdown document.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15193 – In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15193</guid>
    <pubDate>Fri, 25 Sep 2020 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15193</strong></p>
  <p>In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_dlpack` can be made to use uninitialized memory resulting in further memory corruption. This is because the pybind11 glue code assumes that the argument is a tensor. However, there is nothing stopping users from passing in a Python object instead of a tensor. The uninitialized memory address is due to a `reinterpret_c…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-25016 – A safety violation was discovered in the rgb crate before 0.8.20 for Rust, leadi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25016</guid>
    <pubDate>Sat, 29 Aug 2020 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-25016</strong></p>
  <p>A safety violation was discovered in the rgb crate before 0.8.20 for Rust, leading to (for example) dereferencing of arbitrary pointers or disclosure of uninitialized memory. This occurs because structs can be treated as bytes for read and write operations.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-12371 – An integer overflow vulnerability in the Skia library when allocating memory for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-12371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-12371</guid>
    <pubDate>Thu, 09 Jul 2020 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-12371</strong></p>
  <p>An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-12371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-21247 – An issue was discovered in LibVNCServer before 0.9.13. There is an information l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-21247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-21247</guid>
    <pubDate>Wed, 17 Jun 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-21247</strong></p>
  <p>An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-909</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-21247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13113 – An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13113</guid>
    <pubDate>Thu, 21 May 2020 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13113</strong></p>
  <p>An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10030 – An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10030</guid>
    <pubDate>Tue, 19 May 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10030</strong></p>
  <p>An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privileges to change the system's hostname) to cause disclosure of uninitialized memory content via a stack-based out-of-bounds read. It only occurs on systems where gethostname() does not have '\0' termination of the returned string if the hostname is larger than the supplied buffer.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18675 – An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) (Exynos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18675</guid>
    <pubDate>Tue, 07 Apr 2020 16:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18675</strong></p>
  <p>An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) (Exynos7420 or Exynox8890 chipsets) software. The Camera application can leak uninitialized memory via ion. The Samsung ID is SVE-2016-6989 (April 2017).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14044 – Out of bound access due to access of uninitialized memory segment in an array of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14044</guid>
    <pubDate>Fri, 07 Feb 2020 05:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14044</strong></p>
  <p>Out of bound access due to access of uninitialized memory segment in an array of pointers while normal camera open close in Snapdragon Consumer IOT, Snapdragon Mobile in QCS605, SDM439, SDM630, SDM636, SDM660, SDX24</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12410 – While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12410</guid>
    <pubDate>Fri, 08 Nov 2019 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12410</strong></p>
  <p>While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.12.0 to 0.14.1, left memory Array data uninitialized when reading RLE null data from parquet. This affected the C++, Python, Ruby and R implementations. The uninitialized memory could potentially be shared if are transmitted over the wire (for instance with Flight) or persisted…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-909</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12408 – It was discovered that the C++ implementation (which underlies the R, Python and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12408</guid>
    <pubDate>Fri, 08 Nov 2019 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12408</strong></p>
  <p>It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0.14.0 to 0.14.1 had a uninitialized memory bug when building arrays with null values in some cases. This can lead to uninitialized memory being unintentionally shared if Arrow Arrays are transmitted over the wire (for instance with Flight) or persisted in the streaming IPC and f…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-909</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17533 – Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17533</guid>
    <pubDate>Sun, 13 Oct 2019 02:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17533</strong></p>
  <p>Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16866 – Unbound before 1.9.4 accesses uninitialized memory, which allows remote attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16866</guid>
    <pubDate>Thu, 03 Oct 2019 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16866</strong></p>
  <p>Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5067 – An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5067</guid>
    <pubDate>Wed, 18 Sep 2019 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5067</strong></p>
  <p>An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write from uninitialized memory, resulting in memory corruption and possibly arbitrary code execution. To trigger this vulnerability, a specifically crafted PDF document needs to be processed by the target application.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16144 – An issue was discovered in the generator crate before 0.6.18 for Rust. Uninitial...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16144</guid>
    <pubDate>Mon, 09 Sep 2019 12:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16144</strong></p>
  <p>An issue was discovered in the generator crate before 0.6.18 for Rust. Uninitialized memory is used by Scope, done, and yield_ during API calls.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15553 – An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15553</guid>
    <pubDate>Mon, 26 Aug 2019 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15553</strong></p>
  <p>An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninitialized memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-9805 – A latent vulnerability exists in the Prio library where data may be read from un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9805</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9805</guid>
    <pubDate>Fri, 26 Apr 2019 17:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-9805</strong></p>
  <p>A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9805">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7777 – Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7777</guid>
    <pubDate>Mon, 15 Apr 2019 12:31:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7777</strong></p>
  <p>Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-13376 – An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-13376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-13376</guid>
    <pubDate>Tue, 27 Nov 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-13376</strong></p>
  <p>An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing sensitive data to be displayed in the HTTP response.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-13376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-15911 – In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15911</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15911</guid>
    <pubDate>Tue, 28 Aug 2018 04:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-15911</strong></p>
  <p>In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15911">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-7166 – In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-7166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-7166</guid>
    <pubDate>Tue, 21 Aug 2018 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-7166</strong></p>
  <p>In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory. This method is intended to be safe and only return initialized, or cleared, memory. The third argument specifying `encoding` can be passed as a number, this is misinterpreted by `Buffer's` internal "fill" method as the `start` to a fill operation. This flaw may be…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-226</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-7166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000224 – Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000224</guid>
    <pubDate>Mon, 20 Aug 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000224</strong></p>
  <p>Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)Serialization functions (core/io/marshalls.cpp) that can result in DoS (packet of death), possible leak of uninitialized memory. This attack appear to be exploitable via A malforme…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14678 – An issue was discovered in the Linux kernel through 4.17.11, as used in Xen thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14678</guid>
    <pubDate>Sat, 28 Jul 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14678</strong></p>
  <p>An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized memory usage and system crash). Within Xen, 64-bit x86 PV Linux guest OS users can trigger a guest OS crash or possibly gain privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14678">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
