CWE-476
NULL Pointer Dereference
Description
The product dereferences a pointer that it expects to be valid but is NULL.
Hierarchy (View 1000)
CVEs mapped to this weakness (5,508)
page 265 of 276| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1035 | Med | 0.00 | 5.5 | 0.01 | Mar 21, 2022 | Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV. | ||
| CVE-2022-0908 | Hig | 0.00 | 7.7 | 0.01 | Mar 11, 2022 | Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file. | ||
| CVE-2022-0433 | Med | 0.00 | 5.5 | 0.00 | Mar 10, 2022 | A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_next_key function of the BPF bloom filter. This flaw allows a local user to crash the system. This flaw affects Linux kernel versions prior to 5.17-rc1. | ||
| CVE-2021-3739 | Hig | 0.00 | 7.1 | 0.01 | Mar 10, 2022 | A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. The highest… | ||
| CVE-2021-34122 | Med | 0.00 | 5.5 | 0.01 | Mar 10, 2022 | The function bitstr_tell at bitstr.c in ffjpeg commit 4ab404e has a NULL pointer dereference. | ||
| CVE-2022-0890 | Med | 0.00 | 5.5 | 0.01 | Mar 10, 2022 | NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2. | ||
| CVE-2021-23191 | Hig | 0.00 | 7.8 | 0.01 | Mar 2, 2022 | A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service. | ||
| CVE-2021-23180 | Hig | 0.00 | 7.8 | 0.01 | Mar 2, 2022 | A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service. | ||
| CVE-2021-43824 | Hig | 0.00 | 7.5 | 0.01 | Feb 22, 2022 | Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a CONNECT request is sent to JWT filter configured with regex match. This provides a denial of service attack vector. The only… | ||
| CVE-2022-0712 | Med | 0.00 | 5.5 | 0.01 | Feb 22, 2022 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4. | ||
| CVE-2022-0696 | Med | 0.00 | 5.5 | 0.02 | Feb 21, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428. | ||
| CVE-2022-0632 | Med | 0.00 | 5.5 | 0.01 | Feb 19, 2022 | NULL Pointer Dereference in Homebrew mruby prior to 3.2. | ||
| CVE-2022-25258 | Med | 0.00 | 4.6 | 0.01 | Feb 16, 2022 | An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory… | ||
| CVE-2022-0617 | Med | 0.00 | 5.5 | 0.01 | Feb 16, 2022 | A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2. | ||
| CVE-2021-44879 | Med | 0.00 | 5.5 | 0.01 | Feb 14, 2022 | In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. | ||
| CVE-2022-0562 | Med | 0.00 | 5.5 | 0.01 | Feb 11, 2022 | Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit… | ||
| CVE-2022-0561 | Med | 0.00 | 5.5 | 0.01 | Feb 11, 2022 | Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, the fix is available with… | ||
| CVE-2021-45385 | Med | 0.00 | 6.5 | 0.01 | Feb 11, 2022 | A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information in metadata of the bmp is out of range, it returns without assign memory buffer to `pb->pdata` and did not exit the program. So the program crashes when it… | ||
| CVE-2022-0481 | Hig | 0.00 | 7.5 | 0.01 | Feb 4, 2022 | NULL Pointer Dereference in Homebrew mruby prior to 3.2. | ||
| CVE-2021-4043 | Med | 0.00 | 5.5 | 0.05 | Feb 4, 2022 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0. |
- risk 0.00cvss 5.5epss 0.01
Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV.
- risk 0.00cvss 7.7epss 0.01
Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.
- risk 0.00cvss 5.5epss 0.00
A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_next_key function of the BPF bloom filter. This flaw allows a local user to crash the system. This flaw affects Linux kernel versions prior to 5.17-rc1.
- risk 0.00cvss 7.1epss 0.01
A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. The highest…
- risk 0.00cvss 5.5epss 0.01
The function bitstr_tell at bitstr.c in ffjpeg commit 4ab404e has a NULL pointer dereference.
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2.
- risk 0.00cvss 7.8epss 0.01
A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service.
- risk 0.00cvss 7.8epss 0.01
A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service.
- risk 0.00cvss 7.5epss 0.01
Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a CONNECT request is sent to JWT filter configured with regex match. This provides a denial of service attack vector. The only…
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.
- risk 0.00cvss 5.5epss 0.02
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in Homebrew mruby prior to 3.2.
- risk 0.00cvss 4.6epss 0.01
An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory…
- risk 0.00cvss 5.5epss 0.01
A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.
- risk 0.00cvss 5.5epss 0.01
In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference.
- risk 0.00cvss 5.5epss 0.01
Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit…
- risk 0.00cvss 5.5epss 0.01
Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, the fix is available with…
- risk 0.00cvss 6.5epss 0.01
A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information in metadata of the bmp is out of range, it returns without assign memory buffer to `pb->pdata` and did not exit the program. So the program crashes when it…
- risk 0.00cvss 7.5epss 0.01
NULL Pointer Dereference in Homebrew mruby prior to 3.2.
- risk 0.00cvss 5.5epss 0.05
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.