CWE-457: CWE-457

41
Total CVEs
5
Critical
28
High
7.7
Avg CVSS

Yearly Trend

2026
5
2025
16
2024
8
2023
4
2022
5

Top Affected Vendors

1 Bentley 5
2 Google 4
3 Autodesk 4
4 Qualcomm 3
5 Trimble 2
6 Pdf Xchange 2
7 Ashlar 2
8 Reolink 1
9 Blackmagicdesign 1
10 Uclouvain 1

All CWE-457 CVEs (41)

CVE-2025-54874
9.8

This vulnerability in OpenJPEG allows an attacker to write data beyond allocated heap memory boundaries when processing specially crafted JPEG 2000 fi...

Aug 5, 2025
CVE-2025-53644
9.8

OpenCV versions 4.10.0 and 4.11.0 contain an uninitialized pointer vulnerability (CWE-457) that allows arbitrary heap buffer writes when processing sp...

Jul 17, 2025
CVE-2022-40510
9.8

CVE-2022-40510 is a critical memory corruption vulnerability in Qualcomm audio components that allows attackers to execute arbitrary code or cause den...

Aug 8, 2023
CVE-2022-21217
9.8

CVE-2022-21217 is a critical out-of-bounds write vulnerability in Reolink RLC-410W IP cameras that allows remote attackers to execute arbitrary code b...

Jan 28, 2022
CVE-2021-40418
9.8

CVE-2021-40418 is a critical use-after-free vulnerability in the R3D SDK's DPDecoder service that allows remote code execution when parsing malicious ...

Dec 22, 2021
CVE-2025-5749
8.8

This vulnerability allows attackers within Bluetooth range to bypass authentication on WOLFBOX Level 2 EV Chargers by exploiting uninitialized encrypt...

Jun 6, 2025
CVE-2024-6990
8.8

This critical vulnerability in Google Chrome's Dawn component on Android allows remote attackers to potentially access memory outside intended bounds ...

Aug 1, 2024
CVE-2023-31275
8.8

An uninitialized pointer vulnerability in WPS Office's Excel file parser allows remote code execution when opening malicious files. Attackers can craf...

Nov 27, 2023
CVE-2025-20271
8.6

An unauthenticated remote attacker can cause denial of service on Cisco Meraki MX and Z Series devices by sending crafted HTTPS requests to the AnyCon...

Jun 18, 2025
CVE-2023-6324
8.1

This vulnerability in ThroughTek Kalay SDK allows attackers to decrypt DTLS-encrypted communications by exploiting a predictable pre-shared key (PSK) ...

May 15, 2024
CVE-2026-1333
7.8

A Use of Uninitialized Variable vulnerability in SOLIDWORKS eDrawings allows attackers to execute arbitrary code when users open specially crafted EPR...

Feb 16, 2026
CVE-2025-47348
7.8

This vulnerability allows memory corruption in the trusted application when processing identity credential operations, potentially leading to arbitrar...

Jan 7, 2026
CVE-2025-7981
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VC6 files in Ashlar-Vellum Graphite soft...

Sep 17, 2025
CVE-2025-1649
7.8

This vulnerability allows attackers to craft malicious CATPRODUCT files that, when opened in Autodesk AutoCAD, can exploit an uninitialized variable t...

Mar 13, 2025
CVE-2025-1650
7.8

This vulnerability allows attackers to exploit an uninitialized variable in Autodesk AutoCAD when processing malicious CATPRODUCT files. Successful ex...

Mar 13, 2025
CVE-2025-1427
7.8

This vulnerability allows attackers to exploit uninitialized variables in Autodesk AutoCAD when processing malicious CATPRODUCT files. Successful expl...

Mar 13, 2025
CVE-2025-2014
7.8

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious VS...

Mar 11, 2025
CVE-2024-9717
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SKP files in Trimble SketchUp Viewer. At...

Nov 22, 2024
CVE-2024-8842
7.8

This vulnerability in PDF-XChange Editor allows remote attackers to execute arbitrary code by tricking users into opening malicious RTF files. The fla...

Nov 22, 2024
CVE-2024-37002
7.8

This vulnerability allows attackers to execute arbitrary code by tricking users into opening malicious MODEL files in affected Autodesk applications. ...

Jun 25, 2024
CVE-2023-50188
7.8

This vulnerability allows remote attackers to execute arbitrary code on affected Trimble SketchUp Viewer installations by tricking users into opening ...

May 3, 2024
CVE-2022-28320
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious 3DM files in Bentley View. Attackers can...

Mar 29, 2023
CVE-2021-46617
7.8

This vulnerability allows remote attackers to execute arbitrary code on Bentley MicroStation CONNECT installations by tricking users into opening mali...

Feb 18, 2022
CVE-2021-46631
7.8

CVE-2021-46631 is a memory initialization vulnerability in Bentley View's TIF image parser that allows remote code execution when users open malicious...

Feb 18, 2022
CVE-2021-46570
7.8

This vulnerability in Bentley View allows remote attackers to disclose sensitive information by exploiting improper memory initialization when parsing...

Feb 18, 2022
CVE-2021-46566
7.8

This vulnerability allows remote attackers to execute arbitrary code on Bentley MicroStation CONNECT installations by tricking users into opening mali...

Feb 18, 2022
CVE-2021-3928
7.8

CVE-2021-3928 is a use-after-free vulnerability in Vim's undo functionality that occurs when handling specially crafted files. This vulnerability coul...

Nov 5, 2021
CVE-2021-31435
7.8

This vulnerability allows remote attackers to execute arbitrary code on Foxit Studio Photo installations by tricking users into opening malicious CMP ...

Apr 29, 2021
CVE-2025-20212
7.7

An authenticated attacker with VPN credentials can cause a denial of service on Cisco Meraki MX/Z Series devices by exploiting an uninitialized variab...

Apr 2, 2025
CVE-2025-64181
7.5

OpenEXR versions 3.3.0-3.3.5 and 3.4.0-3.4.2 contain a use of uninitialized memory vulnerability in the generic_unpack function. This can cause undefi...

Nov 10, 2025
CVE-2025-59348
7.5

A denial-of-service vulnerability in Dragonfly's P2P file distribution system allows attackers to bypass rate limiting by exploiting an uninitialized ...

Sep 17, 2025
CVE-2024-21502
7.5

CVE-2024-21502 is a use of uninitialized variable vulnerability in fastecdsa's curvemath_mul function that allows attackers to control stack memory. T...

Feb 24, 2024
CVE-2022-25737
7.5

CVE-2022-25737 is an information disclosure vulnerability in Qualcomm modems where missing NULL pointer checks allow attackers to read sensitive data ...

Apr 13, 2023
CVE-2025-20784
6.7

This CVE describes a memory corruption vulnerability in display components due to uninitialized data. It allows local privilege escalation if an attac...

Jan 6, 2026
CVE-2025-9181
6.5

This vulnerability involves uninitialized memory in the JavaScript Engine component of Mozilla products, which could allow an attacker to execute arbi...

Aug 19, 2025
CVE-2026-22188
5.5

Panda3D versions up to 1.10.16 contain a denial of service vulnerability in the deploy-stub component. Attackers can crash the application by supplyin...

Jan 7, 2026
CVE-2025-26448
5.5

This vulnerability in Android's CursorWindow component allows unauthenticated local attackers to read uninitialized memory, potentially exposing sensi...

Sep 4, 2025
CVE-2023-42046
5.5

CVE-2023-42046 is an information disclosure vulnerability in PDF-XChange Editor's J2K file parser caused by uninitialized memory access. Attackers can...

May 3, 2024
CVE-2025-58466
4.9

A use of uninitialized variable vulnerability in QNAP operating systems allows attackers with administrator access to cause denial of service or manip...

Feb 11, 2026
CVE-2025-20638
4.3

This CVE describes an uninitialized heap data read vulnerability in DA (likely a MediaTek component) that could allow local information disclosure. At...

Feb 3, 2025
CVE-2025-10021
N/A

A Use of Uninitialized Variable vulnerability in Open Design Alliance Drawings SDK allows applications to access uninitialized memory during startup d...

Dec 22, 2025

About CWE-457 (CWE-457)

Our database tracks 41 CVEs classified as CWE-457, with 5 rated critical and 28 rated high severity. The average CVSS score for CWE-457 vulnerabilities is 7.7.

External reference: View CWE-457 on MITRE CWE →

Monitor CWE-457 Vulnerabilities

Get alerted when new CWE-457 CVEs affect your infrastructure.

Start Monitoring Free