CWE-824: CWE-824

67
Total CVEs
5
Critical
52
High
7.7
Avg CVSS

Yearly Trend

2026
4
2025
18
2024
13
2023
11
2022
4

Top Affected Vendors

1 Adobe 10
2 Google 8
3 Linux 8
4 Hornerautomation 2
5 F5 2
6 Fujielectric 2
7 Qualcomm 2
8 Luxion 2
9 Siemens 2
10 Wireshark 2

All CWE-824 CVEs (67)

CVE-2025-66588
9.8

An uninitialized pointer vulnerability in AzeoTech DAQFactory allows attackers to execute arbitrary code on affected systems. This affects DAQFactory ...

Dec 11, 2025
CVE-2022-44451
9.8

This vulnerability allows arbitrary code execution through a use of uninitialized pointer in Open Babel's MSI format atom functionality. Attackers can...

Jul 21, 2023
CVE-2021-36219
9.8

CVE-2021-36219 is a critical memory corruption vulnerability in SKALE sgxwallet that allows an attacker to free uninitialized stack pointers, potentia...

Sep 27, 2021
CVE-2021-1619
9.8

An uninitialized variable in Cisco IOS XE Software's AAA function allows unauthenticated remote attackers to bypass NETCONF/RESTCONF authentication. T...

Sep 23, 2021
CVE-2020-11138
9.8

This vulnerability allows attackers to exploit uninitialized pointers during music playback in Qualcomm Snapdragon chipsets, potentially leading to re...

Jan 21, 2021
CVE-2025-32451
8.8

A memory corruption vulnerability in Foxit Reader allows arbitrary code execution when users open malicious PDF files containing specially crafted Jav...

Aug 13, 2025
CVE-2023-43531
8.4

This vulnerability allows memory corruption during cryptographic key pair generation when verifying serialized headers. It affects systems using Qualc...

May 6, 2024
CVE-2023-30847
8.2

CVE-2023-30847 is a memory corruption vulnerability in H2O HTTP server's reverse proxy handler that occurs when processing certain invalid HTTP reques...

Apr 27, 2023
CVE-2026-21275
7.8

Adobe InDesign versions 21.0, 19.5.5 and earlier contain an uninitialized pointer access vulnerability that allows arbitrary code execution when a use...

Jan 13, 2026
CVE-2026-21276
7.8

Adobe InDesign has an uninitialized pointer access vulnerability that allows arbitrary code execution when a user opens a malicious file. This affects...

Jan 13, 2026
CVE-2025-13499
7.8

A vulnerability in Wireshark's Kafka dissector causes a crash when parsing malicious network packets, leading to denial of service. This affects Wires...

Nov 21, 2025
CVE-2025-58777
7.8

CVE-2025-58777 is an access of uninitialized pointer vulnerability in VT Studio versions 8.53 and prior that allows arbitrary code execution when proc...

Oct 2, 2025
CVE-2025-9274
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Oxford Instruments Imaris Viewer. Attac...

Sep 2, 2025
CVE-2025-47121
7.8

Adobe Framemaker versions 2020.8, 2022.6 and earlier contain an uninitialized pointer access vulnerability that could allow arbitrary code execution w...

Jul 8, 2025
CVE-2025-47098
7.8

CVE-2025-47098 is an uninitialized pointer access vulnerability in Adobe InCopy that could allow arbitrary code execution when a user opens a maliciou...

Jul 8, 2025
CVE-2025-43557
7.8

Adobe Animate versions 24.0.8, 23.0.11 and earlier contain an uninitialized pointer access vulnerability that could allow arbitrary code execution whe...

May 13, 2025
CVE-2025-1047
7.8

This vulnerability allows remote attackers to execute arbitrary code on Luxion KeyShot installations by tricking users into opening malicious PVS file...

Apr 23, 2025
CVE-2025-2530
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious DAE files in Luxion KeyShot. Attackers c...

Mar 25, 2025
CVE-2025-26599
7.8

This CVE describes an uninitialized pointer vulnerability in X.Org and Xwayland display servers. When compCheckRedirect() fails to allocate a backing ...

Feb 25, 2025
CVE-2024-57943
7.8

This CVE-2024-57943 is a Linux kernel vulnerability in the exFAT filesystem driver where newly allocated buffer data isn't properly zeroed before bein...

Jan 21, 2025
CVE-2024-45155
7.8

Adobe Animate versions 23.0.8, 24.0.5 and earlier contain an uninitialized pointer access vulnerability that could allow arbitrary code execution when...

Dec 10, 2024
CVE-2024-9258
7.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SID files in IrfanView. Attackers can ga...

Nov 22, 2024
CVE-2024-50088
7.8

This CVE describes an uninitialized pointer vulnerability in the Linux kernel's btrfs filesystem add_inode_ref() function. If exploited, it could lead...

Oct 29, 2024
CVE-2024-46844
7.8

This CVE addresses an uninitialized pointer vulnerability in the Linux kernel's UML (User-Mode Linux) line driver. Attackers could potentially exploit...

Sep 27, 2024
CVE-2023-35712
7.8

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious XE...

May 3, 2024
CVE-2024-24925
7.8

This vulnerability in Simcenter Femap allows attackers to execute arbitrary code by exploiting uninitialized pointer access when parsing malicious Cat...

Feb 13, 2024
CVE-2023-44365
7.8

Adobe Acrobat Reader has an uninitialized pointer vulnerability that allows arbitrary code execution when a user opens a malicious PDF file. This affe...

Nov 16, 2023
CVE-2023-47582
7.8

This vulnerability in TELLUS and TELLUS Lite software allows attackers to execute arbitrary code or disclose sensitive information by tricking a user ...

Nov 15, 2023
CVE-2023-26370
7.8

CVE-2023-26370 is an access of uninitialized pointer vulnerability in Adobe Photoshop that could allow arbitrary code execution when a user opens a ma...

Oct 11, 2023
CVE-2023-31244
7.8

This vulnerability allows arbitrary code execution when a user opens a malicious CSP file. Attackers can exploit uninitialized pointer access to run c...

Jun 6, 2023
CVE-2023-25007
7.8

This vulnerability allows remote code execution through a malicious USD (Universal Scene Description) file. Attackers can craft a file that triggers a...

May 12, 2023
CVE-2023-29278
7.8

CVE-2023-29278 is an access of uninitialized pointer vulnerability in Adobe Substance 3D Painter that could allow arbitrary code execution when a user...

May 11, 2023
CVE-2022-43609
7.8

This vulnerability allows remote attackers to execute arbitrary code on IronCAD installations by tricking users into opening malicious STP files. The ...

Mar 29, 2023
CVE-2023-24562
7.8

This vulnerability in Solid Edge CAD software allows attackers to execute arbitrary code by exploiting uninitialized pointer access when processing ma...

Feb 14, 2023
CVE-2022-34228
7.8

This vulnerability in Adobe Acrobat Reader allows attackers to execute arbitrary code on a victim's system by exploiting an uninitialized pointer when...

Jul 15, 2022
CVE-2022-29925
7.8

This vulnerability allows attackers to execute arbitrary code or leak sensitive information by tricking users into opening malicious image files in V-...

Jun 14, 2022
CVE-2022-1809
7.8

CVE-2022-1809 is an uninitialized pointer access vulnerability in radare2 reverse engineering framework versions before 5.7.0. This allows attackers t...

May 21, 2022
CVE-2022-21971
7.8

CVE-2022-21971 is a remote code execution vulnerability in Windows Runtime that allows attackers to execute arbitrary code on affected systems. It aff...

Feb 9, 2022
CVE-2021-41219
7.8

This vulnerability in TensorFlow's sparse matrix multiplication allows attackers to trigger undefined behavior and potential heap out-of-bounds access...

Nov 5, 2021
CVE-2021-41201
7.8

This CVE describes an uninitialized variable access vulnerability in TensorFlow's EinsumHelper::ParseEquation() function. The bug occurs when the func...

Nov 5, 2021
CVE-2021-33015
7.8

CVE-2021-33015 is a memory corruption vulnerability in Cscape software where improper validation of project files allows an attacker to write beyond a...

Aug 25, 2021
CVE-2021-37666
7.8

This vulnerability in TensorFlow allows an attacker to cause undefined behavior by triggering a null pointer dereference in the RaggedTensorToVariant ...

Aug 12, 2021
CVE-2021-37671
7.8

This vulnerability in TensorFlow allows attackers to cause undefined behavior by triggering null pointer dereferences in Map* and OrderedMap* operatio...

Aug 12, 2021
CVE-2021-37676
7.8

This vulnerability in TensorFlow allows attackers to cause undefined behavior by passing empty tensors to the SparseFillEmptyRows operation, potential...

Aug 12, 2021
CVE-2021-32931
7.8

CVE-2021-32931 is an uninitialized pointer vulnerability in FATEK Automation FvDesigner software that allows arbitrary code execution when processing ...

Aug 11, 2021
CVE-2021-31503
7.8

CVE-2021-31503 is a remote code execution vulnerability in OpenText Brava! Desktop that allows attackers to execute arbitrary code by tricking users i...

Aug 3, 2021
CVE-2021-33542
7.8

This vulnerability allows remote code execution on Phoenix Contact Classic Automation Worx Software Suite programming workstations. Attackers can mani...

Jun 25, 2021
CVE-2021-22758
7.8

This vulnerability in Schneider Electric IGSS Definition software allows attackers to execute arbitrary code or cause data loss by importing a malicio...

Jun 11, 2021
CVE-2021-34280
7.8

CVE-2021-34280 is an uninitialized pointer vulnerability in Polaris Office that allows remote code execution when a user opens a malicious PDF file. T...

Jun 8, 2021
CVE-2025-59478
7.5

A vulnerability in BIG-IP AFM DoS protection profiles allows specially crafted requests to crash the TMM process, causing denial of service. This affe...

Oct 15, 2025

About CWE-824 (CWE-824)

Our database tracks 67 CVEs classified as CWE-824, with 5 rated critical and 52 rated high severity. The average CVSS score for CWE-824 vulnerabilities is 7.7.

External reference: View CWE-824 on MITRE CWE →

Monitor CWE-824 Vulnerabilities

Get alerted when new CWE-824 CVEs affect your infrastructure.

Start Monitoring Free