VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,508)

page 264 of 276
  • CVE-2022-29224MedJun 9, 2022
    risk 0.00cvss 5.9epss 0.01

    Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in the GrpcHealthCheckerImpl. Envoy can perform various types of upstream health checking. One of them uses gRPC. Envoy also has a feature which can “hold”…

  • CVE-2022-32202MedJun 2, 2022
    risk 0.00cvss 5.5epss 0.01

    In libjpeg 1.63, there is a NULL pointer dereference in LineBuffer::FetchRegion in linebuffer.cpp.

  • CVE-2022-32201MedJun 2, 2022
    risk 0.00cvss 5.5epss 0.01

    In libjpeg 1.63, there is a NULL pointer dereference in Component::SubXOf in component.hpp.

  • CVE-2022-29788MedJun 2, 2022
    risk 0.00cvss 6.5epss 0.01

    libmobi before v0.10 contains a NULL pointer dereference via the component mobi_buffer_getpointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mobi file.

  • CVE-2022-29694HigJun 2, 2022
    risk 0.00cvss 7.5epss 0.02

    Unicorn Engine v2.0.0-rc7 and below was discovered to contain a NULL pointer dereference via qemu_ram_free.

  • CVE-2022-1674MedMay 12, 2022
    risk 0.00cvss 5.5epss 0.02

    NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input.

  • CVE-2022-30592CriMay 11, 2022
    risk 0.00cvss 9.8epss 0.03

    liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.

  • CVE-2022-1649MedMay 10, 2022
    risk 0.00cvss 5.5epss 0.01

    Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 prior to 5.7.0. It is likely to be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/476.html).

  • CVE-2022-1620HigMay 8, 2022
    risk 0.00cvss 7.5epss 0.02

    NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in GitHub repository vim/vim prior to 8.2.4901. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 allows attackers to cause a denial of service (application crash) via a crafted input.

  • CVE-2022-1516MedMay 5, 2022
    risk 0.00cvss 5.5epss 0.00

    A NULL pointer dereference flaw was found in the Linux kernel’s X.25 set of standardized network protocols functionality in the way a user terminates their session using a simulated Ethernet card and continued usage of this connection. This flaw allows a local user to crash…

  • CVE-2022-29340HigMay 5, 2022
    risk 0.00cvss 7.5epss 0.01

    GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal due to improper return value handling of GF_SKIP_BOX, which causes a Denial of Service. This vulnerability was fixed in commit 37592ad.

  • CVE-2022-24736LowApr 27, 2022
    risk 0.00cvss 3.3epss 0.01

    Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis…

  • CVE-2022-1507MedApr 27, 2022
    risk 0.00cvss 5.5epss 0.01

    chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. in GitHub repository hpjansson/chafa prior to 1.10.2. chafa: NULL Pointer Dereference in function…

  • CVE-2022-1341HigApr 18, 2022
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in in bwm-ng v0.6.2. An arbitrary null write exists in get_cmdln_options() function in src/options.c.

  • CVE-2022-1382MedApr 18, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making the radare2 crash, thus affecting the availability of the system.

  • CVE-2022-28049MedApr 15, 2022
    risk 0.00cvss 5.5epss 0.01

    NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njs_vmcode_array at /src/njs_vmcode.c.

  • CVE-2022-1283MedApr 8, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to cause a denial of service (application crash).

  • CVE-2021-44108HigApr 5, 2022
    risk 0.00cvss 7.5epss 0.01

    A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request to amf.

  • CVE-2022-1201MedApr 2, 2022
    risk 0.00cvss 6.5epss 0.00

    NULL Pointer Dereference in mrb_vm_exec with super in GitHub repository mruby/mruby prior to 3.2. This vulnerability is capable of making the mruby interpreter crash, thus affecting the availability of the system.

  • CVE-2022-1172MedMar 30, 2022
    risk 0.00cvss 5.0epss 0.01

    Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.