CWE-824: Access of Uninitialized Pointer
The product accesses or uses a pointer that has not been initialized.
185 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-39458 — BIG-IP DNS Cache vulnerability
- CVE-2025-32451 — A memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A sp
- CVE-2025-59478 — BIG-IP AFM DoS protection profile vulnerability
- CVE-2025-9274 — Oxford Instruments Imaris Viewer IMS File Parsing Uninitialized Pointer Remote Code Execution Vulnerability
- CVE-2025-58777 — VT Studio versions 8.53 and prior contain an access of uninitialized pointer vulnerability. If the product uses a specia
- CVE-2025-54207 — InDesign Desktop | Access of Uninitialized Pointer (CWE-824)
- CVE-2025-49529 — Illustrator | Access of Uninitialized Pointer (CWE-824)
- CVE-2025-47121 — Adobe Framemaker | Access of Uninitialized Pointer (CWE-824)
- CVE-2025-47098 — InCopy | Access of Uninitialized Pointer (CWE-824)
- CVE-2025-43592 — InDesign Desktop | Access of Uninitialized Pointer (CWE-824)
- CVE-2025-43557 — Animate | Access of Uninitialized Pointer (CWE-824)
- CVE-2025-43545 — Bridge | Access of Uninitialized Pointer (CWE-824)
- CVE-2025-30326 — Photoshop Desktop | Access of Uninitialized Pointer (CWE-824)
- CVE-2025-27162 — Acrobat Reader | Access of Uninitialized Pointer (CWE-824)
- CVE-2025-27158 — Acrobat Reader | Access of Uninitialized Pointer (CWE-824)
- CVE-2025-2530 — Luxion KeyShot DAE File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability
- CVE-2025-23352 — NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause uninitiali
- CVE-2025-13499 — Access of Uninitialized Pointer in Wireshark
- CVE-2025-1047 — Luxion KeyShot PVS File Parsing Access of Uninitialized Pointer Remote Code Execution Vulnerability
- CVE-2024-9258 — IrfanView SID File Parsing Uninitialized Pointer Remote Code Execution Vulnerability
Recently published
- CVE-2026-88054 — Tesseract: Denial of service via empty-stack dereference in Plumbing/Series at model load
- CVE-2026-67281 — Unauthenticated file read in Mikrotik RouterOS
- CVE-2026-54920 — OpenEXR: Integer overflow and uninitialized pointer cause invalid delete in OpenEXRUtil image resize
- CVE-2026-47908 — Dreamweaver Desktop | Access of Uninitialized Pointer (CWE-824)
- CVE-2026-47320 — Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Mani
- CVE-2026-42959 — Crash during DNSSEC validation of malicious content
- CVE-2026-39458 — BIG-IP DNS Cache vulnerability
- CVE-2026-44411 — A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected application is v
- CVE-2026-6524 — Access of Uninitialized Pointer in Wireshark
- CVE-2026-6870 — Access of Uninitialized Pointer in Wireshark
- CVE-2026-27300 — Adobe Framemaker | Access of Uninitialized Pointer (CWE-824)
- CVE-2026-28691 — ImageMagick has an uninitialized pointer dereference in JBIG decoder
- CVE-2026-28547 — Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerabil
- CVE-2026-1200 — Remote code execution via segmentation fault in increasebufferto function
- CVE-2026-23761 — VB-Audio Voicemeeter & Matrix Drivers DoS via Improper FILE_OBJECT FsContext Initialization
- CVE-2026-21275 — InDesign Desktop | Access of Uninitialized Pointer (CWE-824)
- CVE-2026-21276 — InDesign Desktop | Access of Uninitialized Pointer (CWE-824)
- CVE-2025-14739 — Uninitialized Pointer Vulnerability in TP-Link WR940N and WR941ND
- CVE-2025-66588 — Access of Uninitialized Pointer vulnerability in AzeoTech DAQFactory
- CVE-2025-13674 — Access of Uninitialized Pointer in Wireshark