VulnSea

CWE-824

CVEs classified under CWE-824, newest first.

32 CVEsRSS

CVE-2026-90021Medium· 5.5
6d ago

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: initialize work in f_midi_alloc() f_midi_alloc initializes free_ref to 1 and it can only be incremented when a sound card is registered via f_midi…

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: initialize work in f_midi_alloc() f_midi_alloc initializes free_ref to 1 and it can only be incremented when a sound card is registered via f_midi…

SunlitLinux · LinuxEPSS 0.20%via NVD
CVE-2026-91946Medium· 6.5PoC
1w ago

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format

FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitiali…

TwilightFreeRDP · FreeRDPEPSS 0.43%via NVD
CVE-2026-91963Medium· 6.5PoC⚖ disputed
1w ago

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client…

TwilightFreeRDP · FreeRDPEPSS 0.64%via NVD
CVE-2026-92052High· 8.8⚖ disputed
1w ago

Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component

Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.26%via NVD
CVE-2026-89758High· 7.0⚖ disputed
1w ago

kernel: mm/mempolicy: skip non-present PMDs when queueing folios (CVE-2026-89758)

A flaw was found in the Linux kernel's memory management subsystem. When an HMM-based Graphics Processing Unit (GPU) driver migrates a Transparent Huge Page (THP) to device memory, it can leave a device-private Page Middle Directory (PMD) …

TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.14%via CSAF
CVE-2026-80952High· 7.0
1w ago

kernel: i3c: master: Fix info leak and UAF in device unregister path (CVE-2026-80952)

A flaw was found in the Linux kernel's i3c master component. During device unregistration, a race condition can occur where the device descriptor is prematurely cleared. This can lead to an information leak, exposing kernel stack contents …

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.13%via CSAF
CVE-2026-89458High· 7.0
1w ago

kernel: s390/dasd: Do not complete a failed ESE read as successful (CVE-2026-89458)

A flaw was found in the Linux kernel's s390/dasd component. The `dasd_int_handler()` function incorrectly marks failed Extended Sense Data (ESE) read operations as successful when processing unallocated ESE tracks. This leads to the block …

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89515Medium· 5.5
1w ago

kernel: scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() (CVE-2026-89515)

A flaw was found in the Linux kernel's SCSI core component. When processing data transfers using scatter-gather lists, the system does not properly initialize padding bytes for unaligned data elements. This can result in the exposure of un…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.18%via CSAF
CVE-2026-89483Medium· 5.5⚖ disputed
1w ago

kernel: nvme: zero the discard fallback page (CVE-2026-89483)

A flaw was found in the Linux kernel's Non-Volatile Memory Express (NVMe) subsystem. Under specific memory pressure conditions, a local user could trigger a scenario where uninitialized kernel memory is used and potentially exposed. This c…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.56%via CSAF
CVE-2026-89554Medium· 5.5⚖ disputed
1w ago

kernel: mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction (CVE-2026-89554)

A flaw was found in the Linux kernel's Multipath TCP (MPTCP) implementation. When reconstructing a Multipath TCP (MPTCP) join request under SYN cookies, the `local_id` field is not properly initialized. An off-path attacker can influence t…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.61%via CSAF
CVE-2026-89684High· 7.0
1w ago

kernel: nfsd: fix cpntf publish race in nfs4_init_cp_state (CVE-2026-89684)

A flaw was found in the Linux kernel's nfsd component. A remote attacker, by sending a specially crafted OFFLOAD_CANCEL request, could exploit a race condition during the initialization of copy state notifications. This could lead to a den…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.51%via CSAF
CVE-2026-89618Medium· 5.5
1w ago

kernel: eventfs: Initialize ei->children and ei->list in init_ei() (CVE-2026-89618)

A flaw was found in the Linux kernel's eventfs component. When the `eventfs_create_dir()` function fails due to memory pressure, an uninitialized internal data structure can cause the system to issue a misleading warning during the cleanup…

SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.18%via CSAF
CVE-2026-89505Medium· 5.5
1w ago

kernel: RDMA/uverbs: Guard legacy bundles without method_elm (CVE-2026-89505)

A flaw was found in the Linux kernel's RDMA/uverbs component. Malformed input from a provider in the legacy write path can cause the `uverbs_get_handler_fn()` function to dereference an uninitialized pointer. This can lead to a system cras…

SunlitRed Hat · Red Hat Enterprise Linux 6EPSS 0.16%via CSAF
CVE-2026-80956Medium· 5.5
1w ago

kernel: dm-pcache: only hand out initialized cache segments (CVE-2026-80956)

A flaw was found in the Linux kernel's `dm-pcache` component. A crafted image can cause the `get_cache_segment()` function to return an uninitialized cache segment. This uninitialized segment, containing a null data pointer, is then used b…

SunlitRed Hat · LinuxEPSS 0.20%via CSAF
CVE-2026-88054Medium· 5.5PoC
1w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or NT_REVERSED laye…

Twilighttesseract-ocr · tesseract_ocrEPSS 0.15%via NVD
CVE-2026-67281High· 8.7PoC
2w ago

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare…

MidnightMikrotik · RouterOSEPSS 0.45%via NVD
CVE-2026-54920None· 0.0
4w ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the HTJ2K decode path allows a crafted HTJ…

SunlitEPSS 0.21%via NVD
CVE-2022-42885High· 7.8
2mo ago

Open Babel has uninitialized pointer dereference in GRO residue parser

Open Babel has uninitialized pointer dereference in GRO residue parser

Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-44451High· 7.8
2mo ago

Open Babel has uninitialized pointer dereference in MSI atom parser

Open Babel has uninitialized pointer dereference in MSI atom parser

Twilightopenbabel · openbabelEPSS 0.80%via GHSA
CVE-2022-46280High· 7.8
2mo ago

Open Babel has uninitialized pointer dereference in PQS pFormat

Open Babel has uninitialized pointer dereference in PQS pFormat

Twilightopenbabel · openbabelEPSS 0.83%via GHSA
CVE-2026-42959High· 7.5
4mo ago

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, t…

Twilightnlnetlabs · unboundEPSS 0.78%via NVD
CVE-2026-45736Medium· 4.4PoC
4mo ago

ws is an open source WebSocket client and server for Node.js

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability i…

Twilightws_project · wsEPSS 0.74%via NVD
CVE-2026-39458High· 7.5
4mo ago

When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support…

When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support…

TwilightEPSS 0.26%via NVD
CVE-2026-44411High· 7.8
4mo ago

A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5)

A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected application is vulnerable to uninitialized pointer access while parsing specially crafted PAR files. An attacker could leverage this …

TwilightEPSS 0.10%via NVD
CVE-2026-27300Medium· 5.5
5mo ago

Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could lead to memory exposure

Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information. Exploitati…

Sunlitadobe · framemakerEPSS 0.15%via NVD
CVE-2026-31790High· 7.5
5mo ago

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive da…

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive da…

Twilightopenssl · opensslEPSS 1.0%via NVD
CVE-2026-2100Medium· 5.3
6mo ago

A flaw was found in p11-kit

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-…

SunlitEPSS 1.2%via NVD
CVE-2026-21276High· 7.8
8mo ago

InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user

InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires use…

Twilightadobe · indesignEPSS 0.25%via NVD
CVE-2026-21275High· 7.8
8mo ago

InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user

InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires use…

Twilightadobe · indesignEPSS 0.25%via NVD
CVE-2025-39729Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix dereferencing uninitialized error pointer Fix below smatch warnings: drivers/crypto/ccp/sev-dev.c:1312 __sev_platform_init_locked() error: we previou…

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix dereferencing uninitialized error pointer Fix below smatch warnings: drivers/crypto/ccp/sev-dev.c:1312 __sev_platform_init_locked() error: we previou…

Sunlitlinux · linux_kernelEPSS 0.14%via NVD
CWE-824 vulnerabilities (CVEs) · VulnSea