VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,508)

page 265 of 276
  • CVE-2022-1035MedMar 21, 2022
    risk 0.00cvss 5.5epss 0.01

    Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV.

  • CVE-2022-0908HigMar 11, 2022
    risk 0.00cvss 7.7epss 0.01

    Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.

  • CVE-2022-0433MedMar 10, 2022
    risk 0.00cvss 5.5epss 0.00

    A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_next_key function of the BPF bloom filter. This flaw allows a local user to crash the system. This flaw affects Linux kernel versions prior to 5.17-rc1.

  • CVE-2021-3739HigMar 10, 2022
    risk 0.00cvss 7.1epss 0.01

    A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. The highest…

  • CVE-2021-34122MedMar 10, 2022
    risk 0.00cvss 5.5epss 0.01

    The function bitstr_tell at bitstr.c in ffjpeg commit 4ab404e has a NULL pointer dereference.

  • CVE-2022-0890MedMar 10, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2.

  • CVE-2021-23191HigMar 2, 2022
    risk 0.00cvss 7.8epss 0.01

    A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service.

  • CVE-2021-23180HigMar 2, 2022
    risk 0.00cvss 7.8epss 0.01

    A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service.

  • CVE-2021-43824HigFeb 22, 2022
    risk 0.00cvss 7.5epss 0.01

    Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a CONNECT request is sent to JWT filter configured with regex match. This provides a denial of service attack vector. The only…

  • CVE-2022-0712MedFeb 22, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.

  • CVE-2022-0696MedFeb 21, 2022
    risk 0.00cvss 5.5epss 0.02

    NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.

  • CVE-2022-0632MedFeb 19, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in Homebrew mruby prior to 3.2.

  • CVE-2022-25258MedFeb 16, 2022
    risk 0.00cvss 4.6epss 0.01

    An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory…

  • CVE-2022-0617MedFeb 16, 2022
    risk 0.00cvss 5.5epss 0.01

    A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.

  • CVE-2021-44879MedFeb 14, 2022
    risk 0.00cvss 5.5epss 0.01

    In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference.

  • CVE-2022-0562MedFeb 11, 2022
    risk 0.00cvss 5.5epss 0.01

    Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit…

  • CVE-2022-0561MedFeb 11, 2022
    risk 0.00cvss 5.5epss 0.01

    Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, the fix is available with…

  • CVE-2021-45385MedFeb 11, 2022
    risk 0.00cvss 6.5epss 0.01

    A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information in metadata of the bmp is out of range, it returns without assign memory buffer to `pb->pdata` and did not exit the program. So the program crashes when it…

  • CVE-2022-0481HigFeb 4, 2022
    risk 0.00cvss 7.5epss 0.01

    NULL Pointer Dereference in Homebrew mruby prior to 3.2.

  • CVE-2021-4043MedFeb 4, 2022
    risk 0.00cvss 5.5epss 0.05

    NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.