CWE-457: CWE-457
Yearly Trend
Top Affected Vendors
All CWE-457 CVEs (41)
This vulnerability in OpenJPEG allows an attacker to write data beyond allocated heap memory boundaries when processing specially crafted JPEG 2000 fi...
Aug 5, 2025OpenCV versions 4.10.0 and 4.11.0 contain an uninitialized pointer vulnerability (CWE-457) that allows arbitrary heap buffer writes when processing sp...
Jul 17, 2025CVE-2022-40510 is a critical memory corruption vulnerability in Qualcomm audio components that allows attackers to execute arbitrary code or cause den...
Aug 8, 2023CVE-2022-21217 is a critical out-of-bounds write vulnerability in Reolink RLC-410W IP cameras that allows remote attackers to execute arbitrary code b...
Jan 28, 2022CVE-2021-40418 is a critical use-after-free vulnerability in the R3D SDK's DPDecoder service that allows remote code execution when parsing malicious ...
Dec 22, 2021This vulnerability allows attackers within Bluetooth range to bypass authentication on WOLFBOX Level 2 EV Chargers by exploiting uninitialized encrypt...
Jun 6, 2025This critical vulnerability in Google Chrome's Dawn component on Android allows remote attackers to potentially access memory outside intended bounds ...
Aug 1, 2024An uninitialized pointer vulnerability in WPS Office's Excel file parser allows remote code execution when opening malicious files. Attackers can craf...
Nov 27, 2023An unauthenticated remote attacker can cause denial of service on Cisco Meraki MX and Z Series devices by sending crafted HTTPS requests to the AnyCon...
Jun 18, 2025This vulnerability in ThroughTek Kalay SDK allows attackers to decrypt DTLS-encrypted communications by exploiting a predictable pre-shared key (PSK) ...
May 15, 2024A Use of Uninitialized Variable vulnerability in SOLIDWORKS eDrawings allows attackers to execute arbitrary code when users open specially crafted EPR...
Feb 16, 2026This vulnerability allows memory corruption in the trusted application when processing identity credential operations, potentially leading to arbitrar...
Jan 7, 2026This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VC6 files in Ashlar-Vellum Graphite soft...
Sep 17, 2025This vulnerability allows attackers to craft malicious CATPRODUCT files that, when opened in Autodesk AutoCAD, can exploit an uninitialized variable t...
Mar 13, 2025This vulnerability allows attackers to exploit an uninitialized variable in Autodesk AutoCAD when processing malicious CATPRODUCT files. Successful ex...
Mar 13, 2025This vulnerability allows attackers to exploit uninitialized variables in Autodesk AutoCAD when processing malicious CATPRODUCT files. Successful expl...
Mar 13, 2025This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious VS...
Mar 11, 2025This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SKP files in Trimble SketchUp Viewer. At...
Nov 22, 2024This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious RTF files. The fla...
Nov 22, 2024This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious MODEL files in affected Autodesk applications. ...
Jun 25, 2024This vulnerability allows remote attackers to execute arbitrary code on affected Trimble SketchUp Viewer installations by tricking users into opening ...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious 3DM files in Bentley View. Attackers can...
Mar 29, 2023This vulnerability allows remote attackers to execute arbitrary code on Bentley MicroStation CONNECT installations by tricking users into opening mali...
Feb 18, 2022CVE-2021-46631 is a memory initialization vulnerability in Bentley View's TIF image parser that allows remote code execution when users open malicious...
Feb 18, 2022This vulnerability in Bentley View allows remote attackers to disclose sensitive information by exploiting improper memory initialization when parsing...
Feb 18, 2022This vulnerability allows remote attackers to execute arbitrary code on Bentley MicroStation CONNECT installations by tricking users into opening mali...
Feb 18, 2022CVE-2021-3928 is a use-after-free vulnerability in Vim's undo functionality that occurs when handling specially crafted files. This vulnerability coul...
Nov 5, 2021This vulnerability allows remote attackers to execute arbitrary code on Foxit Studio Photo installations by tricking users into opening malicious CMP ...
Apr 29, 2021An authenticated attacker with VPN credentials can cause a denial of service on Cisco Meraki MX/Z Series devices by exploiting an uninitialized variab...
Apr 2, 2025OpenEXR versions 3.3.0-3.3.5 and 3.4.0-3.4.2 contain a use of uninitialized memory vulnerability in the generic_unpack function. This can cause undefi...
Nov 10, 2025A denial-of-service vulnerability in Dragonfly's P2P file distribution system allows attackers to bypass rate limiting by exploiting an uninitialized ...
Sep 17, 2025CVE-2024-21502 is a use of uninitialized variable vulnerability in fastecdsa's curvemath_mul function that allows attackers to control stack memory. T...
Feb 24, 2024CVE-2022-25737 is an information disclosure vulnerability in Qualcomm modems where missing NULL pointer checks allow attackers to read sensitive data ...
Apr 13, 2023This CVE describes a memory corruption vulnerability in display components due to uninitialized data. It allows local privilege escalation if an attac...
Jan 6, 2026This vulnerability involves uninitialized memory in the JavaScript Engine component of Mozilla products, which could allow an attacker to execute arbi...
Aug 19, 2025Panda3D versions up to 1.10.16 contain a denial of service vulnerability in the deploy-stub component. Attackers can crash the application by supplyin...
Jan 7, 2026This vulnerability in Android's CursorWindow component allows unauthenticated local attackers to read uninitialized memory, potentially exposing sensi...
Sep 4, 2025CVE-2023-42046 is an information disclosure vulnerability in PDF-XChange Editor's J2K file parser caused by uninitialized memory access. Attackers can...
May 3, 2024A use of uninitialized variable vulnerability in QNAP operating systems allows attackers with administrator access to cause denial of service or manip...
Feb 11, 2026This CVE describes an uninitialized heap data read vulnerability in DA (likely a MediaTek component) that could allow local information disclosure. At...
Feb 3, 2025A Use of Uninitialized Variable vulnerability in Open Design Alliance Drawings SDK allows applications to access uninitialized memory during startup d...
Dec 22, 2025About CWE-457 (CWE-457)
Our database tracks 41 CVEs classified as CWE-457, with 5 rated critical and 28 rated high severity. The average CVSS score for CWE-457 vulnerabilities is 7.7.
External reference: View CWE-457 on MITRE CWE →
Monitor CWE-457 Vulnerabilities
Get alerted when new CWE-457 CVEs affect your infrastructure.
Start Monitoring Free