The product accesses or uses a pointer that has not been initialized.
Volume of CVEs assigned to CWE-824 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
291 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-21971HIGH Windows Runtime Remote Code Execution Vulnerability | Feb 9, 2022 | 7.8 | 87 | YES | NO |
CVE-2015-1770HIGH Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerabil | Jun 10, 2015 | 8.8 | 80 | YES | NO |
CVE-2018-9948MEDIUM This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this v | May 17, 2018 | 6.5 | 75 | NO | YES |
CVE-2010-1818HIGH The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Mars | Aug 31, 2010 | 9.3 | 72 | NO | YES |
CVE-2018-11803HIGH Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a rec | Feb 5, 2019 | 7.5 | 58 | NO | NO |
CVE-2017-12561CRITICAL A remote code execution vulnerability in HPE intelligent Management Center (iMC) PLAT version Plat 7.3 E0504P4 and earlier was found. | Feb 15, 2018 | 9.8 | 44 | NO | NO |
CVE-2019-0853HIGH A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerabilit | Apr 9, 2019 | 8.8 | 42 | NO | NO |
CVE-2026-16353CRITICAL Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.1 | Jul 21, 2026 | 9.8 | 39 | NO | NO |
CVE-2020-9274HIGH An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or pri | Feb 26, 2020 | 7.5 | 37 | NO | YES |
CVE-2026-16409HIGH Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | Jul 21, 2026 | 7.5 | 34 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.