VulnSea

CWE-457

CVEs classified under CWE-457, newest first.

24 CVEsRSS

CVE-2026-58731Medium· 6.2
1w ago

In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data

In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne…

Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-58721Medium· 4.4
1w ago

In multiple locations, there is a possible information disclosure due to uninitialized memory use

In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-91963Medium· 6.5PoC⚖ disputed
1w ago

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client…

TwilightFreeRDP · FreeRDPEPSS 0.64%via NVD
CVE-2026-16141High· 8.1
1w ago

OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults

OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI se…

TwilightOpenBMC · phosphor-net-ipmidEPSS 0.39%via NVD
CVE-2026-92052High· 8.8⚖ disputed
1w ago

Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component

Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.26%via NVD
CVE-2026-84564Medium· 4.3
1w ago

An uninitialized memory issue was addressed with improved memory initialization

An uninitialized memory issue was addressed with improved memory initialization. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, wat…

Sunlitapple · ipadosEPSS 0.30%via NVD
CVE-2026-65405Medium· 5.5
1w ago

A memory initialization issue was addressed with improved memory handling

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 2…

Sunlitapple · ipadosEPSS 0.16%via NVD
CVE-2026-84391Medium· 6.5
2w ago

A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>

A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>

SunlitFortinet · FortiAnalyzerEPSS 0.24%via NVD
CVE-2026-62986Medium· 4.3
4w ago

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale he…

SunlitEPSS 0.23%via NVD
CVE-2026-76919Medium· 5.3
1mo ago

Use of Uninitialized Variable in Wireshark

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

SunlitWireshark Foundation · WiresharkEPSS 0.27%via CVEORG
CVE-2026-19212Medium· 4.3
1mo ago

A vulnerability was determined in WonderTrader up to 0.9.9

A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WTSTradeDef.hpp of the component TraderATP Cash Trade Conversion. Executing a manipulation of the argument m_offsetType…

SunlitEPSS 0.27%via NVD
CVE-2026-17668Medium· 6.5
1mo ago

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Sunlitgoogle · chromeEPSS 0.49%via NVD
CVE-2026-17667Medium· 6.5
1mo ago

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page

Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Sunlitgoogle · chromeEPSS 0.49%via NVD
CVE-2026-14405Critical· 9.6
2mo ago

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

Midnightgoogle · chromeEPSS 0.50%via NVD
CVE-2025-13763Medium· 5.7
5mo ago

Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash

Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted res…

SunlitEPSS 0.18%via NVD
CVE-2026-5888Medium· 6.5
5mo ago

Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page

Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.26%via NVD
CVE-2026-22188Medium· 5.5
8mo ago

The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due to unbounded stack allocation

The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due to unbounded stack allocation. The deploy-stub executable allocates argv_copy and argv_copy2 using alloca() based di…

Sunlitcmu · panda3dEPSS 0.20%via NVD
CVE-2025-5777High· 7.5CISA KEVPoC
1y ago

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Abyssalcitrix · netscaler_application_delivery_controllerEPSS 100%via NVD
CVE-2024-9355Medium· 6.5
1y ago

A vulnerability was found in Golang FIPS OpenSSL

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false posi…

Sunlitgolang-fips · github.com/golang-fips/opensslEPSS 0.30%via NVD
CVE-2024-45618Low· 3.9
2y ago

A vulnerability was found in pkcs15-init in OpenSC

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values …

Sunlitopensc_project · openscEPSS 0.31%via NVD
CVE-2024-45617Low· 3.9
2y ago

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient o…

Sunlitopensc_project · openscEPSS 0.30%via NVD
CVE-2024-45616Low· 3.9
2y ago

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following …

Sunlitopensc_project · openscEPSS 0.36%via NVD
CVE-2024-45615Low· 3.9
2y ago

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).

Sunlitopensc_project · openscEPSS 0.36%via NVD
CVE-2024-26882High· 7.3
2y ago

In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv() Apply the same fix than ones found in : 8d975c15c0cd ("ip6_tunnel: make sure to pull inner header in…

In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv() Apply the same fix than ones found in : 8d975c15c0cd ("ip6_tunnel: make sure to pull inner header in…

Twilightlinux · linux_kernelEPSS 0.69%via NVD
CWE-457 vulnerabilities (CVEs) · VulnSea