CWE-457 · 237 записей
Use of Uninitialized Variable
CVE этого класса
237 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2021-40418Эксплойта нет | When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property blackmagicdesign · davinci resolve · CWE-457 | Критическая9,8 | — | 17,9 % | 22 дек. 2021 г. |
39Наблюдать | CVE-2022-21217Эксплойта нет | An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102.reolink · rlc-410w firmware · CWE-457 | Критическая9,8 | — | 1,2 % | 28 янв. 2022 г. |
39Наблюдать | CVE-2026-6748Эксплойта нет | Uninitialized memory in the Audio/Video: Web Codecs componentmozilla · firefox · CWE-457 | Критическая9,8 | — | 0,6 % | 21 апр. 2026 г. |
39Наблюдать | CVE-2022-40510Эксплойта нет | Buffer copy without checking size of input in Audio.qualcomm · apq8009 firmware · CWE-457 | Критическая9,8 | — | 0,4 % | 8 авг. 2023 г. |
38Наблюдать | CVE-2026-14405Эксплойта нет | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a cgoogle · chrome · CWE-457 | Критическая9,6 | — | 0,5 % | 1 июл. 2026 г. |
38Наблюдать | CVE-2026-78935Эксплойта нет | Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute agoogle · chrome · CWE-457 | Критическая9,6 | — | 0,5 % | 25 авг. 2026 г. |
36Наблюдать | CVE-2026-84639Эксплойта нет | Uninitialized memory in MIME parsingmozilla · thunderbird · CWE-457 | Критическая9,1 | — | 0,3 % | 1 сент. 2026 г. |
35Наблюдать | CVE-2024-6990Эксплойта нет | Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds google · chrome · CWE-457 | Высокая8,8 | — | 0,9 % | 1 авг. 2024 г. |
35Наблюдать | CVE-2023-6324Эксплойта нет | ThroughTek Kalay SDK error in handling the PSK identitythroughtek · kalay platform · CWE-457 | Высокая8,8 | — | 0,7 % | 15 мая 2024 г. |
35Наблюдать | CVE-2026-15132Эксплойта нет | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a google · chrome · CWE-457 | Высокая8,8 | — | 0,5 % | 8 июл. 2026 г. |
35Наблюдать | CVE-2026-13825Эксплойта нет | Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a cragoogle · chrome · CWE-457 | Высокая8,8 | — | 0,3 % | 30 июн. 2026 г. |
35Наблюдать | CVE-2026-92052Эксплойта нет | Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL componentmozilla · firefox · CWE-457 | Высокая8,8 | — | 0,3 % | 15 сент. 2026 г. |
35Наблюдать | CVE-2025-5749Эксплойта нет | WOLFBOX Level 2 EV Charger BLE Encryption Keys Uninitialized Variable Authentication Bypass Vulnerabilitywolfbox · level 2 ev charger firmware · CWE-457 | Высокая8,8 | — | 0,2 % | 6 июн. 2025 г. |
35Наблюдать | CVE-2026-55280Эксплойта нет | In multiple locations, there is a possible out-of-bounds write due to uninitialized data.google · android · CWE-457 | Высокая8,8 | — | — | 1 день назад |
34Наблюдать | CVE-2024-47540Эксплойта нет | GHSL-2024-197: GStreamer uses uninitialized stack memory in Matroska/WebM demuxergstreamer · gstreamer · CWE-457 | Высокая8,6 | — | 1,0 % | 11 дек. 2024 г. |
34Наблюдать | CVE-2020-27124Эксплойта нет | Cisco Adaptive Security Appliance Software SSL/TLS Denial of Service Vulnerabilitycisco · adaptive security appliance software · CWE-457 | Высокая8,6 | — | 0,9 % | 18 нояб. 2024 г. |
34Наблюдать | CVE-2025-20271Эксплойта нет | Cisco Meraki MX and Z Series AnyConnect VPN with Client Certificate Authentication Denial of Service Vulnerabilitycisco · cisco meraki mx firmware · CWE-457 | Высокая8,6 | — | 0,5 % | 18 июн. 2025 г. |
34Наблюдать | CVE-2026-66859Эксплойта нет | Apache Thrift: c_glib multiplexed processor crashes on a message it cannot routeapache software foundation · apache thrift · CWE-457 | Высокая8,7 | — | 0,4 % | 4 дня назад |
34Наблюдать | CVE-2025-58071Эксплойта нет | BIG-IP IPSec vulnerabilityf5 · big-ip access policy manager · CWE-457 | Высокая8,7 | — | 0,4 % | 15 окт. 2025 г. |
34Наблюдать | CVE-2025-2286Эксплойта нет | Local Code Execution Vulnerability in Arena®rockwellautomation · arena · CWE-457 | Высокая8,5 | — | 0,3 % | 8 апр. 2025 г. |
34Наблюдать | CVE-2025-2287Эксплойта нет | Local Code Execution Vulnerability in Arena®rockwellautomation · arena · CWE-457 | Высокая8,5 | — | 0,3 % | 8 апр. 2025 г. |
34Наблюдать | CVE-2025-2285Эксплойта нет | Local Code Execution Vulnerability in Arena®rockwellautomation · arena · CWE-457 | Высокая8,5 | — | 0,3 % | 8 апр. 2025 г. |
33Наблюдать | CVE-2026-6311Эксплойта нет | Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the rengoogle · chrome · CWE-457 | Высокая8,3 | — | 0,3 % | 15 апр. 2026 г. |
33Наблюдать | CVE-2026-9972Эксплойта нет | Uninitialized Use in Gamepad in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer procgoogle · chrome · CWE-457 | Высокая8,3 | — | 0,3 % | 28 мая 2026 г. |
33Наблюдать | CVE-2026-10960Эксплойта нет | Uninitialized Use in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to pogoogle · chrome · CWE-457 | Высокая8,3 | — | 0,3 % | 4 июн. 2026 г. |
- CVE-2021-4041844В плане
When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property
КритическаяCVSS 9,8Эксплойта нетEPSS 18 %blackmagicdesign · davinci resolve22 дек. 2021 г.
- CVE-2022-2121739Наблюдать
An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %reolink · rlc-410w firmware28 янв. 2022 г.
- CVE-2026-674839Наблюдать
Uninitialized memory in the Audio/Video: Web Codecs component
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mozilla · firefox21 апр. 2026 г.
- CVE-2022-4051039Наблюдать
Buffer copy without checking size of input in Audio.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %qualcomm · apq8009 firmware8 авг. 2023 г.
- CVE-2026-1440538Наблюдать
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a c
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %google · chrome1 июл. 2026 г.
- CVE-2026-7893538Наблюдать
Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute a
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %google · chrome25 авг. 2026 г.
- CVE-2026-8463936Наблюдать
Uninitialized memory in MIME parsing
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %mozilla · thunderbird1 сент. 2026 г.
- CVE-2024-699035Наблюдать
Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %google · chrome1 авг. 2024 г.
- CVE-2023-632435Наблюдать
ThroughTek Kalay SDK error in handling the PSK identity
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %throughtek · kalay platform15 мая 2024 г.
- CVE-2026-1513235Наблюдать
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %google · chrome8 июл. 2026 г.
- CVE-2026-1382535Наблюдать
Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a cra
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %google · chrome30 июн. 2026 г.
- CVE-2026-9205235Наблюдать
Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mozilla · firefox15 сент. 2026 г.
- CVE-2025-574935Наблюдать
WOLFBOX Level 2 EV Charger BLE Encryption Keys Uninitialized Variable Authentication Bypass Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wolfbox · level 2 ev charger firmware6 июн. 2025 г.
- CVE-2026-5528035Наблюдать
In multiple locations, there is a possible out-of-bounds write due to uninitialized data.
ВысокаяCVSS 8,8Эксплойта нетgoogle · android1 день назад
- CVE-2024-4754034Наблюдать
GHSL-2024-197: GStreamer uses uninitialized stack memory in Matroska/WebM demuxer
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %gstreamer · gstreamer11 дек. 2024 г.
- CVE-2020-2712434Наблюдать
Cisco Adaptive Security Appliance Software SSL/TLS Denial of Service Vulnerability
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %cisco · adaptive security appliance software18 нояб. 2024 г.
- CVE-2025-2027134Наблюдать
Cisco Meraki MX and Z Series AnyConnect VPN with Client Certificate Authentication Denial of Service Vulnerability
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %cisco · cisco meraki mx firmware18 июн. 2025 г.
- CVE-2026-6685934Наблюдать
Apache Thrift: c_glib multiplexed processor crashes on a message it cannot route
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %apache software foundation · apache thrift4 дня назад
- CVE-2025-5807134Наблюдать
BIG-IP IPSec vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %f5 · big-ip access policy manager15 окт. 2025 г.
- CVE-2025-228634Наблюдать
Local Code Execution Vulnerability in Arena®
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %rockwellautomation · arena8 апр. 2025 г.
- CVE-2025-228734Наблюдать
Local Code Execution Vulnerability in Arena®
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %rockwellautomation · arena8 апр. 2025 г.
- CVE-2025-228534Наблюдать
Local Code Execution Vulnerability in Arena®
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %rockwellautomation · arena8 апр. 2025 г.
- CVE-2026-631133Наблюдать
Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the ren
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %google · chrome15 апр. 2026 г.
- CVE-2026-997233Наблюдать
Uninitialized Use in Gamepad in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer proc
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %google · chrome28 мая 2026 г.
- CVE-2026-1096033Наблюдать
Uninitialized Use in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to po
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %google · chrome4 июн. 2026 г.