VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,669)

page 203 of 284
  • CVE-2019-1010162MedJul 23, 2019
    risk 0.36cvss 5.5epss 0.01

    jsish 2.4.74 2.0474 is affected by: CWE-476: NULL Pointer Dereference. The impact is: denial of service. The component is: function Jsi_StrcmpDict (jsiChar.c:121). The attack vector is: The victim must execute crafted javascript code. The fixed version is: 2.4.77.

  • CVE-2019-13590MedJul 14, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in libsox.a in SoX 14.4.2. In sox-fmt.h (startread function), there is an integer overflow on the result of integer addition (wraparound to 0) fed into the lsx_calloc macro that wraps malloc. When a NULL pointer is returned, it is used without a prior…

  • CVE-2019-12984MedJun 26, 2019
    risk 0.36cvss 5.5epss 0.02

    A NULL pointer dereference vulnerability in the function nfc_genl_deactivate_target() in net/nfc/netlink.c in the Linux kernel before 5.1.13 can be triggered by a malicious user-mode program that omits certain NFC attributes, leading to denial of service.

  • CVE-2019-12974MedJun 26, 2019
    risk 0.36cvss 5.5epss 0.02

    A NULL pointer dereference in the function ReadPANGOImage in coders/pango.c and the function ReadVIDImage in coders/vid.c in ImageMagick 7.0.8-34 allows remote attackers to cause a denial of service via a crafted image.

  • CVE-2018-15733MedJun 21, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a NULL Pointer Dereference vulnerability due to not validating the size of the output buffer value from IOCtl 0x80002028.

  • CVE-2019-12481MedMay 30, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.

  • CVE-2019-12455MedMay 30, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in sunxi_divs_clk_setup in drivers/clk/sunxi/clk-sunxi.c in the Linux kernel through 5.1.5. There is an unchecked kstrndup of derived_name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: This…

  • CVE-2019-12382MedMay 28, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in drm_load_edid_firmware in drivers/gpu/drm/drm_edid_load.c in the Linux kernel through 5.1.5. There is an unchecked kstrdup of fwstr, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: The…

  • CVE-2019-12381MedMay 28, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in ip_ra_control in net/ipv4/ip_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: this is disputed because…

  • CVE-2019-12378MedMay 28, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in ip6_ra_control in net/ipv6/ipv6_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: This has been disputed…

  • CVE-2018-7191MedMay 17, 2019
    risk 0.36cvss 5.5epss 0.01

    In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is not called before register_netdevice. This allows local users to cause a denial of service (NULL pointer dereference and panic) via an ioctl(TUNSETIFF) call with a dev name containing a / character.…

  • CVE-2019-10022MedMar 25, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Xpdf 4.01.01. There is a NULL pointer dereference in the function Gfx::opSetExtGState in Gfx.cc.

  • CVE-2019-9704MedMar 12, 2019
    risk 0.36cvss 5.5epss 0.00

    Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.

  • CVE-2019-8413MedFeb 17, 2019
    risk 0.36cvss 5.5epss 0.00

    On Xiaomi MIX 2 devices with the 4.4.78 kernel, a NULL pointer dereference in the ioctl interface of the device file /dev/elliptic1 or /dev/elliptic0 causes a system crash via IOCTL 0x4008c575 (aka decimal 1074316661).

  • CVE-2019-8357MedFeb 15, 2019
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c allows a NULL pointer dereference.

  • CVE-2018-9190MedFeb 8, 2019
    risk 0.36cvss 5.5epss 0.00

    A null pointer dereference vulnerability in Fortinet FortiClientWindows 6.0.2 and earlier allows attacker to cause a denial of service via the NDIS miniport driver.

  • CVE-2019-5006MedJan 3, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is a NULL pointer dereference during PDF parsing.

  • CVE-2018-20651MedJan 1, 2019
    risk 0.36cvss 5.5epss 0.02

    A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31.1. This occurs for a crafted ET_DYN with no program headers. A specially crafted ELF file allows…

  • CVE-2018-20362MedDec 22, 2018
    risk 0.36cvss 5.5epss 0.01

    A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash because adding to windowed output is mishandled in the EIGHT_SHORT_SEQUENCE…

  • CVE-2018-20357MedDec 22, 2018
    risk 0.36cvss 5.5epss 0.01

    A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash.