VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,669)

page 202 of 284
  • CVE-2019-10545MedDec 12, 2019
    risk 0.36cvss 5.5epss 0.00

    Null pointer dereference issue in kernel due to missing check related to LLC support in GPU in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in QCS605, SDM670, SDM710, SM6150, SM7150, SM8150

  • CVE-2019-19462MedNov 30, 2019
    risk 0.36cvss 5.5epss 0.00

    relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result.

  • CVE-2019-19308MedNov 27, 2019
    risk 0.36cvss 5.5epss 0.01

    In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns NULL).

  • CVE-2012-5640MedNov 25, 2019
    risk 0.36cvss 5.5epss 0.00

    thttpd has a local DoS vulnerability via specially-crafted .htpasswd files

  • CVE-2019-10207MedNov 25, 2019
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call…

  • CVE-2019-19227MedNov 22, 2019
    risk 0.36cvss 5.5epss 0.01

    In the AppleTalk subsystem in the Linux kernel before 5.1, there is a potential NULL pointer dereference because register_snap_client may return NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c, as demonstrated by unregister_snap_client,…

  • CVE-2019-19037MedNov 21, 2019
    risk 0.36cvss 5.5epss 0.02

    ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE) can be zero.

  • CVE-2019-19036MedNov 21, 2019
    risk 0.36cvss 5.5epss 0.02

    btrfs_root_node in fs/btrfs/ctree.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because rcu_dereference(root->node) can be zero.

  • CVE-2010-0206MedOct 30, 2019
    risk 0.36cvss 5.5epss 0.01

    xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.

  • CVE-2019-17064MedOct 1, 2019
    risk 0.36cvss 5.5epss 0.01

    Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.

  • CVE-2019-16349MedSep 16, 2019
    risk 0.36cvss 5.5epss 0.01

    Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from the AP4_TrunAtom class.

  • CVE-2019-15924MedSep 4, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in the Linux kernel before 5.0.11. fm10k_init_module in drivers/net/ethernet/intel/fm10k/fm10k_main.c has a NULL pointer dereference because there is no -ENOMEM upon an alloc_workqueue failure.

  • CVE-2019-15923MedSep 4, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in the Linux kernel before 5.0.9. There is a NULL pointer dereference for a cd data structure if alloc_disk fails in drivers/block/paride/pf.c.

  • CVE-2019-15922MedSep 4, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in the Linux kernel before 5.0.9. There is a NULL pointer dereference for a pf data structure if alloc_disk fails in drivers/block/paride/pf.c.

  • CVE-2019-15860MedSep 3, 2019
    risk 0.36cvss 5.5epss 0.01

    Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.

  • CVE-2019-14534MedAug 29, 2019
    risk 0.36cvss 5.5epss 0.01

    In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.

  • CVE-2019-13219MedAug 15, 2019
    risk 0.36cvss 5.5epss 0.01

    A NULL pointer dereference in the get_window function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file.

  • CVE-2019-10140MedAug 15, 2019
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers…

  • CVE-2019-2236MedJul 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Null pointer dereference during secure application termination using specific application ids. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2019-14248MedJul 24, 2019
    risk 0.36cvss 5.5epss 0.01

    In libnasm.a in Netwide Assembler (NASM) 2.14.xx, asm/pragma.c allows a NULL pointer dereference in process_pragma, search_pragma_list, and nasm_set_limit when "%pragma limit" is mishandled.