VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,508)

page 258 of 276
  • CVE-2023-38322HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafted GET HTTP request with a missing User-Agent HTTP header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service…

  • CVE-2023-38320HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing User-Agent header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service…

  • CVE-2023-38315HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing client token query string parameter. Triggering this issue results in crashing OpenNDS (a…

  • CVE-2023-38314MedNov 17, 2023
    risk 0.00cvss 6.5epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthenticated() that can be triggered with a crafted GET HTTP request with a missing redirect query string parameter. Triggering this issue results in crashing…

  • CVE-2023-38313HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GET HTTP request with a missing client redirect query string parameter. Triggering this issue results in crashing openNDS (a…

  • CVE-2023-6176MedNov 16, 2023
    risk 0.00cvss 4.7epss 0.00

    A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functionality. This issue occurs when a user constructs a malicious packet with specific socket configuration, which could allow a local user to crash the system or…

  • CVE-2023-46728HigNov 6, 2023
    risk 0.00cvss 7.5epss 0.06

    Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1.…

  • CVE-2023-46867MedOct 30, 2023
    risk 0.00cvss 6.5epss 0.00

    In International Color Consortium DemoIccMAX 79ecb74, CIccXformMatrixTRC::GetCurve in IccCmm.cpp in libSampleICC.a has a NULL pointer dereference.

  • CVE-2023-46862MedOct 29, 2023
    risk 0.00cvss 4.7epss 0.00

    An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit, an io_uring/fdinfo.c io_uring_show_fdinfo NULL pointer dereference can occur.

  • CVE-2023-5590HigOct 15, 2023
    risk 0.00cvss 7.5epss 0.01

    NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.

  • CVE-2023-5586HigOct 15, 2023
    risk 0.00cvss 7.8epss 0.00

    NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV.

  • CVE-2023-5441MedOct 5, 2023
    risk 0.00cvss 5.5epss 0.00

    NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960.

  • CVE-2023-40032MedSep 11, 2023
    risk 0.00cvss 5.5epss 0.00

    libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when…

  • CVE-2023-4875LowSep 9, 2023
    risk 0.00cvss 2.2epss 0.01

    Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12

  • CVE-2023-4874MedSep 9, 2023
    risk 0.00cvss 4.3epss 0.01

    Null pointer dereference when viewing a specially crafted email in Mutt >1.5.2 <2.2.12

  • CVE-2023-41909HigSep 5, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.

  • CVE-2023-4683MedAug 31, 2023
    risk 0.00cvss 5.5epss 0.00

    NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.

  • CVE-2023-4681MedAug 31, 2023
    risk 0.00cvss 5.5epss 0.00

    NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.

  • CVE-2023-41358HigAug 29, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.

  • CVE-2022-28070HigAug 22, 2023
    risk 0.00cvss 7.5epss 0.01

    A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0.