Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-824

Access of Uninitialized Pointer

The product accesses or uses a pointer that has not been initialized.

291
Assigned CVEs
109th
Commonality Rank
7.2
Avg CVSS
0.7%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-824 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 2003
23 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

291 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-21971HIGH
Windows Runtime Remote Code Execution Vulnerability
Feb 9, 20227.887YESNO
CVE-2015-1770HIGH
Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerabil
Jun 10, 20158.880YESNO
CVE-2018-9948MEDIUM
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this v
May 17, 20186.575NOYES
CVE-2010-1818HIGH
The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Mars
Aug 31, 20109.372NOYES
CVE-2018-11803HIGH
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a rec
Feb 5, 20197.558NONO
CVE-2017-12561CRITICAL
A remote code execution vulnerability in HPE intelligent Management Center (iMC) PLAT version Plat 7.3 E0504P4 and earlier was found.
Feb 15, 20189.844NONO
CVE-2019-0853HIGH
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerabilit
Apr 9, 20198.842NONO
CVE-2026-16353CRITICAL
Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.1
Jul 21, 20269.839NONO
CVE-2020-9274HIGH
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or pri
Feb 26, 20207.537NOYES
CVE-2026-16409HIGH
Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Jul 21, 20267.534NONO
View all 291 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
16%
19%
5.0-5.9
9%
16%
6.0-6.9
55%
26%
7.0-7.9
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
2 CVEs
0.7% of CVEs· 88th percentile
Metasploit
2 CVEs
0.7% of CVEs· 85th percentile
Nuclei
1 CVE
0.3% of CVEs· 80th percentile
ExploitDB
7 CVEs
2.4% of CVEs· 90th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products