A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which woul
Foxit PDF Reader Annotation Use of Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allow
oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attac
oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attack
oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attac
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elem
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.16.02.
Information disclosure in modem due to missing NULL check while reading packets received from local network
An information disclosure vulnerability exists in the ClientConnect() functionality of SoftEther VPN 5.01.9674. A specia
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application cra
A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an
A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_s
This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kerne
An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_2012110
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 1
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.7
In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing th
Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially e
A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of
An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 S
An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local attacker to read uninitial
When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assig
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6
vim is vulnerable to Use of Uninitialized Variable
Zydis is an x86/x86-64 disassembler library. Users of Zydis versions v3.2.0 and older that use the string functions prov
A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.
WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow
WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD exten
Frequently Asked Questions
What is CWE-457?
CWE-457 (CWE-457) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-457?
There are 248 CVE records associated with CWE-457 in our database. Of these, 12 are critical severity, 76 are high severity, and 124 are medium severity.
How can I protect against CWE-457 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-457 using AI-powered security agents.
Detect CWE-457 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-457 vulnerabilities across your infrastructure.
Get Started