CWE-824

Access of Uninitialized Pointer

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product accesses or uses a pointer that has not been initialized.

283 vulnerabilities with CWE-824
CVE-2018-9981 HIGH
Foxit Reader and PhantomPDF < 9.0.1.1049 - Remote Code Execution via U3D File Parsing
CVSS 8.8
CVE-2018-9948 MEDIUM
Foxit PDF Reader Pointer Overwrite UAF
CVSS 6.5
CVE-2018-10484 HIGH
Foxit Reader and PhantomPDF < 9.0.1.1049 - Remote Code Execution via U3D Node Object Parsing
CVSS 8.8
CVE-2018-3842 HIGH
Foxit Reader 9.0.1.1049 - Use-After-Free via JavaScript Engine
CVSS 8.8
CVE-2018-7515 MEDIUM
Omron CX-Supervisor <3.30 - Memory Corruption
CVSS 5.3
CVE-2018-0894 MEDIUM
Windows Kernel - Information Disclosure via Memory Address Handling
CVSS 4.7
CVE-2018-1000099 HIGH
Teluu PJSIP <2.7.1 - Memory Corruption
CVSS 7.5
CVE-2017-12561 CRITICAL
HPE Intelligent Management Center PLAT < 7.3 E0504P4 - Remote Code Execution via Uninitialized Pointer Access
CVSS 9.8
CVE-2017-16378 HIGH
Adobe Acrobat and Reader <2017.012.20098 - Memory Corruption
CVSS 8.8
CVE-2017-16377 HIGH
Adobe Acrobat <2017.012.20098 - Info Disclosure
CVSS 8.8
CVE-2017-9670 HIGH
gnuplot 5.2.rc1 - Denial of Service via Crafted File in load_tic_series()
CVSS 7.8
CVE-2016-10447 HIGH
Android - Uninitialized Link List Entry
CVSS 7.5
CVE-2016-4343 HIGH
PHP < 5.5.36 - Use-After-Free in phar_make_dirstream
CVSS 8.8
CVE-2016-1005 HIGH
Adobe Flash Player < 18.0.0.333, 19.x-21.x < 21.0.0.182, < 11.2.202.577 - Remote Code Execution via MPEG-4 Data
CVSS 8.8
CVE-2015-1770 HIGH KEV
Microsoft Office <2013 SP1-2013 RT SP1 - RCE
CVSS 8.8
CVE-2014-1564
Mozilla Firefox <32 - Info Disclosure
CVE-2011-1814
Google Chrome <12.0.742.91 - Memory Corruption
CVE-2011-0479
Google Chrome < 8.0.552.237 and Chrome OS < 8.0.552.344 - DoS via Uninitialized Pointer
CVE-2010-1818
Apple QuickTime - Remote Code Execution via Untrusted Pointer Unmarshalling
CVE-2009-2768 HIGH
Linux Kernel < 2.6.31 - Denial of Service via Flat Binary Execution
CVSS 7.8
CVE-2009-1721
OpenEXR 1.2.2 and 1.6.1 - Use-After-Free in Imf::hufUncompress
CVE-2009-1415
GnuTLS < 2.6.6 - Denial of Service via Invalid DSA Signature Handling
CVE-2009-0846
MIT Kerberos 5 < 1.6.4 - Denial of Service via ASN.1 GeneralizedTime Decoder
CVE-2009-0040
libpng <1.0.43, <1.2.35 - DoS/Code Injection
CVE-2007-4682
Mac OS X 10.4-10.4.10 - Denial of Service and Possible Remote Code Execution via Uninitialized Pointer in CoreText
Details
Vulnerabilities 283