CWE-476
NULL Pointer Dereference
Description
The product dereferences a pointer that it expects to be valid but is NULL.
Hierarchy (View 1000)
CVEs mapped to this weakness (5,508)
page 258 of 276| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-38322 | Hig | 0.00 | 7.5 | 0.01 | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafted GET HTTP request with a missing User-Agent HTTP header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service… | ||
| CVE-2023-38320 | Hig | 0.00 | 7.5 | 0.01 | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing User-Agent header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service… | ||
| CVE-2023-38315 | Hig | 0.00 | 7.5 | 0.01 | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing client token query string parameter. Triggering this issue results in crashing OpenNDS (a… | ||
| CVE-2023-38314 | Med | 0.00 | 6.5 | 0.01 | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthenticated() that can be triggered with a crafted GET HTTP request with a missing redirect query string parameter. Triggering this issue results in crashing… | ||
| CVE-2023-38313 | Hig | 0.00 | 7.5 | 0.01 | Nov 17, 2023 | An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GET HTTP request with a missing client redirect query string parameter. Triggering this issue results in crashing openNDS (a… | ||
| CVE-2023-6176 | Med | 0.00 | 4.7 | 0.00 | Nov 16, 2023 | A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functionality. This issue occurs when a user constructs a malicious packet with specific socket configuration, which could allow a local user to crash the system or… | ||
| CVE-2023-46728 | Hig | 0.00 | 7.5 | 0.06 | Nov 6, 2023 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1.… | ||
| CVE-2023-46867 | Med | 0.00 | 6.5 | 0.00 | Oct 30, 2023 | In International Color Consortium DemoIccMAX 79ecb74, CIccXformMatrixTRC::GetCurve in IccCmm.cpp in libSampleICC.a has a NULL pointer dereference. | ||
| CVE-2023-46862 | Med | 0.00 | 4.7 | 0.00 | Oct 29, 2023 | An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit, an io_uring/fdinfo.c io_uring_show_fdinfo NULL pointer dereference can occur. | ||
| CVE-2023-5590 | Hig | 0.00 | 7.5 | 0.01 | Oct 15, 2023 | NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0. | ||
| CVE-2023-5586 | Hig | 0.00 | 7.8 | 0.00 | Oct 15, 2023 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV. | ||
| CVE-2023-5441 | Med | 0.00 | 5.5 | 0.00 | Oct 5, 2023 | NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960. | ||
| CVE-2023-40032 | Med | 0.00 | 5.5 | 0.00 | Sep 11, 2023 | libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when… | ||
| CVE-2023-4875 | Low | 0.00 | 2.2 | 0.01 | Sep 9, 2023 | Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12 | ||
| CVE-2023-4874 | Med | 0.00 | 4.3 | 0.01 | Sep 9, 2023 | Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12 | ||
| CVE-2023-41909 | Hig | 0.00 | 7.5 | 0.01 | Sep 5, 2023 | An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference. | ||
| CVE-2023-4683 | Med | 0.00 | 5.5 | 0.00 | Aug 31, 2023 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV. | ||
| CVE-2023-4681 | Med | 0.00 | 5.5 | 0.00 | Aug 31, 2023 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV. | ||
| CVE-2023-41358 | Hig | 0.00 | 7.5 | 0.01 | Aug 29, 2023 | An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero. | ||
| CVE-2022-28070 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0. |
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafted GET HTTP request with a missing User-Agent HTTP header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service…
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing User-Agent header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service…
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing client token query string parameter. Triggering this issue results in crashing OpenNDS (a…
- risk 0.00cvss 6.5epss 0.01
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthenticated() that can be triggered with a crafted GET HTTP request with a missing redirect query string parameter. Triggering this issue results in crashing…
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GET HTTP request with a missing client redirect query string parameter. Triggering this issue results in crashing openNDS (a…
- risk 0.00cvss 4.7epss 0.00
A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functionality. This issue occurs when a user constructs a malicious packet with specific socket configuration, which could allow a local user to crash the system or…
- risk 0.00cvss 7.5epss 0.06
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1.…
- risk 0.00cvss 6.5epss 0.00
In International Color Consortium DemoIccMAX 79ecb74, CIccXformMatrixTRC::GetCurve in IccCmm.cpp in libSampleICC.a has a NULL pointer dereference.
- risk 0.00cvss 4.7epss 0.00
An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit, an io_uring/fdinfo.c io_uring_show_fdinfo NULL pointer dereference can occur.
- risk 0.00cvss 7.5epss 0.01
NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.
- risk 0.00cvss 7.8epss 0.00
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV.
- risk 0.00cvss 5.5epss 0.00
NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960.
- risk 0.00cvss 5.5epss 0.00
libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when…
- risk 0.00cvss 2.2epss 0.01
Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12
- risk 0.00cvss 4.3epss 0.01
Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
- risk 0.00cvss 5.5epss 0.00
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.
- risk 0.00cvss 5.5epss 0.00
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
- risk 0.00cvss 7.5epss 0.01
A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0.