Skip to main content

Threats Tagged 'cwe-824'

View all threats tagged with 'cwe-824'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-824

Threats Tagged 'cwe-824'

Click on any threat for detailed analysis and mitigation recommendations

An Access of Uninitialized Pointer vulnerability exists in the Apache Thrift c_glib bindings affecting versions before 0.25.0. This flaw can lead to potentially severe impacts due to improper memory handling. The issue is fixed in version 0.25.0, and users are advised to upgrade to this version to remediate the vulnerability.

Join the discussion

CVE-2026-47528 is a vulnerability in the NVIDIA GeForce GPU Display Driver firmware for Windows and Linux. It involves an access of an uninitialized pointer, which could be exploited by an attacker to achieve code execution, denial of service, privilege escalation, information disclosure, or data tampering. The vulnerability has a high severity rating with a CVSS score of 7.8. No specific affected versions or patch information is provided.

Join the discussion

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or NT_REVERSED layers in a crafted .traineddata model. During LSTMRecognizer initialization in src/lstm/lstmrecognizer.cpp, CacheXScaleFactor(XScaleFactor()) reaches Series::CacheXScaleFactor in src/lstm/series.cpp, which dereferences stack_[0] on the empty vector and invokes a virtual method through an invalid Network pointer. This causes a deterministic crash and denial of service at model load. No fixed release is available as of this review.

Join the discussion

CVE-2026-67281 is a high-severity unauthenticated file-read vulnerability in Mikrotik RouterOS WebFig 7.x branch. It arises from an uninitialized pointer used for file authorization in the /jsproxy path, allowing attackers to escape the WebFig file namespace and access root-owned files, including sensitive configuration stores with credentials. The issue was fixed in RouterOS versions 7.23.4 (Long-term) and 7.24.2 (Stable).

Join the discussion

A vulnerability in OpenEXR versions 3.4.0 through 3.4.12 allows a crafted HTJ2K-compressed EXR file to cause an unconditional process abort when exr_start_read() is called on untrusted input. This is due to an assertion failure triggered by invalid QCD marker bits passed to the OpenJPH library, resulting in a denial of service. The issue is fixed in version 3.4.13.

Join the discussion
0

Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Join the discussion
0

Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Join the discussion

These are all security issues fixed in the zcode-3.14.3-1.1 package on the GA media of openSUSE Tumbleweed.

Join the discussion

Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Join the discussion

Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3.

Join the discussion

Showing 1 to 10 of 42 results

Filters:Tag: cwe-824
Page 1 of 5
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses