VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,508)

page 21 of 276
  • CVE-2023-52574HigMar 2, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: team: fix null-ptr-deref when team device type is changed Get a null-ptr-deref bug as follows with reproducer [1]. BUG: kernel NULL pointer dereference, address: 0000000000000228 ... RIP:…

  • CVE-2023-52523HigMar 2, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Reject sk_msg egress redirects to non-TCP sockets With a SOCKMAP/SOCKHASH map and an sk_msg program user can steer messages sent from one TCP socket (s1) to actually egress from another TCP…

  • CVE-2021-46933HigFeb 27, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear. ffs_data_clear is indirectly called from both ffs_fs_kill_sb and ffs_ep0_release, so it ends up being called twice when userland closes ep0 and then…

  • CVE-2024-0035HigFeb 16, 2024
    risk 0.51cvss 7.8epss 0.00

    In onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-0209HigJan 3, 2024
    risk 0.51cvss 7.8epss 0.01

    IEEE 1609.2 dissector crash in Wireshark 4.2.0, 4.0.0 to 4.0.11, and 3.6.0 to 3.6.19 allows denial of service via packet injection or crafted capture file

  • CVE-2023-32008HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

  • CVE-2022-42335HigApr 25, 2023
    risk 0.51cvss 7.8epss 0.00

    x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Due to too lax a check in one of the hypervisor routines used for…

  • CVE-2023-24910HigMar 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Graphics Component Elevation of Privilege Vulnerability

  • CVE-2022-47094HigJan 5, 2023
    risk 0.51cvss 7.8epss 0.00

    GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Null pointer dereference via filters/dmx_m2ts.c:343 in m2tsdmx_declare_pid

  • CVE-2022-38928HigSep 21, 2022
    risk 0.51cvss 7.8epss 0.00

    XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.

  • CVE-2022-24577HigMar 14, 2022
    risk 0.51cvss 7.8epss 0.01

    GPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8_wcslen is a renamed Unicode utf8_wcslen function.)

  • CVE-2021-26948HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file.

  • CVE-2018-4302HigDec 23, 2021
    risk 0.51cvss 7.8epss 0.01

    A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or…

  • CVE-2021-40826HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.01

    Clementine Music Player through 1.3.1 is vulnerable to a User Mode Write Access Violation, affecting the MP3 file parsing functionality at clementine+0x3aa207. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled…

  • CVE-2021-41524HigOct 5, 2021
    risk 0.51cvss 7.5epss 0.25

    While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is…

  • CVE-2021-32284HigSep 20, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function ircode_register_pop_context_protect() located in gravity_ircode.c. It allows an attacker to cause Denial of Service.

  • CVE-2021-39251HigSep 7, 2021
    risk 0.51cvss 7.8epss 0.00

    A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.

  • CVE-2019-14584HigJun 3, 2021
    risk 0.51cvss 7.8epss 0.00

    Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-26235HigMar 18, 2021
    risk 0.51cvss 7.8epss 0.01

    FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfc9, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to…

  • CVE-2021-25176HigJan 18, 2021
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A NULL pointer dereference exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart).