VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,534)

page 179 of 277
  • CVE-2022-47465MedApr 11, 2023
    risk 0.36cvss 5.5epss 0.00

    In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.

  • CVE-2023-0197MedApr 1, 2023
    risk 0.36cvss 5.5epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious user in a guest VM can cause a NULL-pointer dereference, which may lead to denial of service.

  • CVE-2022-44369MedMar 29, 2023
    risk 0.36cvss 5.5epss 0.00

    NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.

  • CVE-2022-44368MedMar 29, 2023
    risk 0.36cvss 5.5epss 0.00

    NASM v2.16 was discovered to contain a null pointer deference in the NASM component

  • CVE-2023-1631MedMar 25, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability, which was classified as problematic, was found in JiangMin Antivirus 16.2.2022.418. This affects the function 0x222010 in the library kvcore.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Attacking locally is a…

  • CVE-2023-1628MedMar 25, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability classified as problematic has been found in Jianming Antivirus 16.2.2022.418. Affected is an unknown function in the library kvcore.sys of the component IoControlCode Handler. The manipulation leads to null pointer dereference. The attack needs to be approached…

  • CVE-2023-1446MedMar 17, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability classified as problematic was found in Watchdog Anti-Virus 1.4.214.0. Affected by this vulnerability is the function 0x80002004/0x80002008 in the library wsdk-driver.sys of the component IoControlCode Handler. The manipulation leads to denial of service. An…

  • CVE-2023-24465MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause the current application to crash.

  • CVE-2023-24758MedMar 1, 2023
    risk 0.36cvss 5.5epss 0.00

    libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.

  • CVE-2023-24757MedMar 1, 2023
    risk 0.36cvss 5.5epss 0.00

    libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.

  • CVE-2023-24756MedMar 1, 2023
    risk 0.36cvss 5.5epss 0.00

    libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.

  • CVE-2023-24755MedMar 1, 2023
    risk 0.36cvss 5.5epss 0.00

    libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.

  • CVE-2023-24754MedMar 1, 2023
    risk 0.36cvss 5.5epss 0.00

    libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.

  • CVE-2023-24752MedMar 1, 2023
    risk 0.36cvss 5.5epss 0.00

    libde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input file.

  • CVE-2023-21593MedFeb 17, 2023
    risk 0.36cvss 5.5epss 0.00

    Adobe InDesign versions ID18.1 (and earlier) and ID17.4 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user.…

  • CVE-2022-47360MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In log service, there is a missing permission check. This could lead to local denial of service in log service.

  • CVE-2022-47359MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In log service, there is a missing permission check. This could lead to local denial of service in log service.

  • CVE-2022-44447MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible null pointer dereference issue due to a missing bounds check. This could lead to local denial of service in wlan services.

  • CVE-2022-4285MedJan 27, 2023
    risk 0.36cvss 5.5epss 0.00

    An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.

  • CVE-2022-4842MedJan 12, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw NULL Pointer Dereference in the Linux kernel NTFS3 driver function attr_punch_hole() was found. A local user could use this flaw to crash the system.