CWE-457

High likelihood

Use of Uninitialized Variable

Parent: CWE-908 - Use of Uninitialized Resource

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

172 vulnerabilities with CWE-457
CVE-2026-2806 CRITICAL
Firefox < 148.0 - Use of Uninitialized Variable in Graphics Text Component
CVSS 9.1
CVE-2026-1333 HIGH
SOLIDWORKS Desktop <2026 - Code Injection
CVSS 7.8
CVE-2026-21690 MEDIUM
iccDEV < 2.3.1.2 - Type Confusion in CIccTagXmlTagData::ToXml()
CVSS 6.3
CVE-2026-22188 MEDIUM
Panda3D <= 1.10.16 - Denial of Service via Unbounded Stack Allocation in deploy-stub
CVSS 5.5
CVE-2025-13763 MEDIUM
Libopensc: opensc: multiple uses of uninitialized variable
CVSS 5.7
CVE-2025-58466 MEDIUM
QNAP QTS and QuTS hero - Use of Uninitialized Variable
CVSS 4.9
CVE-2025-29952 MEDIUM
AMD EPYC 9005 Series Processors - Authenticated Memory Integrity Loss via SEV Firmware Improper Initialization
CVE-2025-32467 MEDIUM
TDX Module <tdx1.5 - Info Disclosure
CVSS 4.1
CVE-2025-47348 HIGH
Qualcomm Trusted Application Firmware - Memory Corruption
CVSS 7.8
CVE-2025-20784 MEDIUM
Display < - Memory Corruption
CVSS 6.7
CVE-2025-10021 HIGH
Open Design Alliance Drawings SDK (mt) <2026.12 - Use After Free
CVE-2025-36935 HIGH
Android - Memory Corruption via Uninitialized Data in trusty_ffa_mem_reclaim
CVSS 7.8
CVE-2025-65295 HIGH
Aqara Hub <4.1.9_0027-4.3.6_0025 - RCE
CVSS 8.1
CVE-2025-20771 MEDIUM
Google Android Improper Input Validation - Privilege Escalation
CVSS 6.7
CVE-2025-20766 HIGH
Android - Local Privilege Escalation via Display Memory Corruption
CVSS 7.8
CVE-2025-64181 HIGH
OpenEXR 3.3.0-3.3.5 3.4.0-3.4.2 - Use of Uninitialized Variable in generic_unpack
CVSS 7.5
CVE-2025-58071 HIGH
F5 BIG-IP 15.1.0-15.1.10.8 - Denial of Service via IPsec Traffic
CVSS 7.5
CVE-2025-7984 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via AR File Parsing
CVSS 7.8
CVE-2025-7981 HIGH
Ashlar-Vellum Graphite - Remote Code Execution via VC6 File Parsing
CVSS 7.8
CVE-2025-7978 HIGH
Ashlar-Vellum Graphite - Remote Code Execution via VC6 File Parsing
CVSS 7.8
CVE-2025-59348 HIGH
Dragonfly < 2.1.0 - Denial of Service via Uninitialized Variable in ProcessPieceFromSource
CVSS 7.5
CVE-2025-9450 HIGH
SOLIDWORKS Desktop 2025 - Code Injection
CVSS 7.8
CVE-2025-26448 MEDIUM
Android - Local Information Disclosure via Uninitialized Data in CursorWindow.cpp
CVSS 5.5
CVE-2025-0081 HIGH
dng Lossless Decoder < - Memory Corruption
CVSS 7.5
CVE-2025-9181 MEDIUM
Firefox and Thunderbird - Use of Uninitialized Variable in JavaScript Engine
CVSS 6.5
Details
Vulnerabilities 172
Exploit Likelihood High