VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,553)

page 190 of 278
  • CVE-2020-19470MedJul 21, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue has been found in function DCTStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a NULL pointer dereference (invalid read of size 1) .

  • CVE-2020-19468MedJul 21, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue has been found in function EmbedStream::getChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a null pointer derefenrece (invalid read of size 8) .

  • CVE-2021-1101MedJul 21, 2021
    risk 0.36cvss 5.5epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL pointer, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

  • CVE-2021-22318MedJul 14, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS 2.0 has a Null Pointer Dereference Vulnerability. Local attackers may exploit this vulnerability to cause system denial of service.

  • CVE-2021-33715MedJul 13, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in JT Utilities (All versions < V13.0.2.0). When parsing specially crafted JT files, a race condition could cause an object to be released before being operated on, leading to NULL pointer deference condition and causing the application to…

  • CVE-2021-33714MedJul 13, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in JT Utilities (All versions < V13.0.2.0). When parsing specially crafted JT files, a missing check for the validity of an iterator leads to NULL pointer deference condition, causing the application to crash. An attacker could leverage this…

  • CVE-2021-27345MedJun 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a crafted compressed file.

  • CVE-2020-25467MedJun 10, 2021
    risk 0.36cvss 5.5epss 0.01

    A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) via a crafted compressed file.

  • CVE-2020-27830MedMay 13, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio_synth without checking whether it is NULL or not, and may lead to a NULL-ptr deref crash.

  • CVE-2021-1078MedApr 21, 2021
    risk 0.36cvss 5.5epss 0.00

    NVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel driver (nvlddmkm.sys) where a NULL pointer dereference may lead to system crash.

  • CVE-2020-23912MedApr 21, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Bento4 through v1.6.0-637. A NULL pointer dereference exists in the function AP4_StszAtom::GetSampleSize() located in Ap4StszAtom.cpp. It allows an attacker to cause Denial of Service.

  • CVE-2021-27029MedApr 19, 2021
    risk 0.36cvss 5.5epss 0.01

    The user may be tricked into opening a malicious FBX file which may exploit a Null Pointer Dereference vulnerability in FBX's Review version 1.5.0 and prior causing the application to crash leading to a denial of service.

  • CVE-2021-3467MedMar 25, 2021
    risk 0.36cvss 5.5epss 0.01

    A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.

  • CVE-2021-3443MedMar 25, 2021
    risk 0.36cvss 5.5epss 0.01

    A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.

  • CVE-2021-25674MedMar 15, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the system could cause a Denial-of-Service condition in the application when it is used to open a specially crafted file. As a consequence, a NULL pointer deference…

  • CVE-2020-27819MedFeb 23, 2021
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer dereference vulnerability exists when parsing XLS cells in libxls/xls2csv.c:199. It could allow a remote attacker to cause a denial of service via crafted XLS file.

  • CVE-2020-12364MedFeb 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Null pointer reference in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before version Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.

  • CVE-2021-27203MedFeb 16, 2021
    risk 0.36cvss 5.5epss 0.00

    In Dekart Private Disk 2.15, invalid use of the Type3 user buffer for IOCTL codes using METHOD_NEITHER results in arbitrary memory dereferencing.

  • CVE-2020-9453MedFeb 5, 2021
    risk 0.36cvss 5.5epss 0.00

    In Epson iProjection v2.30, the driver file EMP_MPAU.sys allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402406 and IOCtl 0x9C40240A. (0x9C402402 has only a NULL pointer…

  • CVE-2020-35507MedJan 4, 2021
    risk 0.36cvss 5.5epss 0.01

    There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application…