VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,508)

page 257 of 276
  • CVE-2024-6062LowJun 17, 2024
    risk 0.00cvss 3.3epss 0.00

    A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swf_svg_add_iso_sample of the file src/filters/load_text.c of the component MP4Box. The manipulation leads to null pointer dereference. The…

  • CVE-2024-34508MedMay 5, 2024
    risk 0.00cvss 4.3epss 0.01

    dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.

  • CVE-2024-34088HigApr 30, 2024
    risk 0.00cvss 7.5epss 0.01

    In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.

  • CVE-2024-32661HigApr 23, 2024
    risk 0.00cvss 7.5epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to a possible `NULL` access and crash. Version 3.5.1 contains a patch for the issue. No known workarounds are available.

  • CVE-2023-48183HigApr 23, 2024
    risk 0.00cvss 7.5epss 0.01

    QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.

  • CVE-2022-24810MedApr 16, 2024
    risk 0.00cvss 6.5epss 0.01

    net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users…

  • CVE-2022-24809MedApr 16, 2024
    risk 0.00cvss 6.5epss 0.01

    net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch.…

  • CVE-2022-24808MedApr 16, 2024
    risk 0.00cvss 6.5epss 0.01

    net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2…

  • CVE-2024-29489MedMar 28, 2024
    risk 0.00cvss 5.5epss 0.00

    Jerryscript 2.4.0 has SEGV at ./jerry-core/ecma/base/ecma-helpers.c:238:58 in ecma_get_object_type.

  • CVE-2023-45925Mar 27, 2024
    risk 0.00cvss epss 0.00

    GNU Midnight Commander 4.8.29-146-g299d9a2fb was discovered to contain a NULL pointer dereference via the function x_error_handler() at tty/x11conn.c. NOTE: this is disputed because it should be categorized as a usability problem (an X operation silently fails).

  • CVE-2024-23327HigFeb 9, 2024
    risk 0.00cvss 7.5epss 0.01

    Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, the Envoy instance will segfault when attempting to craft the upstream PPv2 header. This occurs when the downstream request has a command type of LOCAL and does…

  • CVE-2023-46343MedJan 23, 2024
    risk 0.00cvss 5.5epss 0.00

    In the Linux kernel before 6.5.9, there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c.

  • CVE-2021-33630MedJan 18, 2024
    risk 0.00cvss 5.5epss 0.00

    NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3.

  • CVE-2023-6915MedJan 15, 2024
    risk 0.00cvss 6.2epss 0.00

    A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attacker using this library to cause a denial of service problem due to a missing check at a function return.

  • CVE-2023-37188HigDec 25, 2023
    risk 0.00cvss 7.5epss 0.01

    C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_rate_decompress at zfp/blosc2-zfp.c.

  • CVE-2023-37187HigDec 25, 2023
    risk 0.00cvss 7.5epss 0.01

    C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the zfp/blosc2-zfp.c zfp_acc_decompress. function.

  • CVE-2023-37186HigDec 25, 2023
    risk 0.00cvss 7.5epss 0.01

    C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference in ndlz/ndlz8x8.c via a NULL pointer to memset.

  • CVE-2023-37185HigDec 25, 2023
    risk 0.00cvss 7.5epss 0.01

    C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_prec_decompress at zfp/blosc2-zfp.c.

  • CVE-2023-6622MedDec 8, 2023
    risk 0.00cvss 5.5epss 0.00

    A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.c in nf_tables in the Linux kernel. This issue may allow a local attacker with CAP_NET_ADMIN user privilege to trigger a denial of service.

  • CVE-2023-5972HigNov 23, 2023
    risk 0.00cvss 7.0epss 0.00

    A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.