VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,508)

page 268 of 276
  • CVE-2020-23930MedApr 21, 2021
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function nhmldump_send_header located in write_nhml.c. It allows an attacker to cause Denial of Service.

  • CVE-2020-23914MedApr 21, 2021
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in cpp-peglib through v0.1.12. A NULL pointer dereference exists in the peg::AstOptimizer::optimize() located in peglib.h. It allows an attacker to cause Denial of Service.

  • CVE-2021-30199MedApr 19, 2021
    risk 0.00cvss 5.5epss 0.01

    In filters/reframe_latm.c in GPAC 1.0.1 there is a Null Pointer Dereference, when gf_filter_pck_get_data is called. The first arg pck may be null with a crafted mp4 file,which results in a crash.

  • CVE-2021-30015MedApr 19, 2021
    risk 0.00cvss 5.5epss 0.01

    There is a Null Pointer Dereference in function filter_core/filter_pck.c:gf_filter_pck_new_alloc_internal in GPAC 1.0.1. The pid comes from function av1dmx_parse_flush_sample, the ctx.opid maybe NULL. The result is a crash in gf_filter_pck_new_alloc_internal.

  • CVE-2021-31262MedApr 19, 2021
    risk 0.00cvss 5.5epss 0.01

    The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

  • CVE-2021-31260MedApr 19, 2021
    risk 0.00cvss 5.5epss 0.01

    The MergeTrack function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

  • CVE-2021-31259MedApr 19, 2021
    risk 0.00cvss 5.5epss 0.01

    The gf_isom_cenc_get_default_info_internal function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

  • CVE-2021-31258MedApr 19, 2021
    risk 0.00cvss 5.5epss 0.01

    The gf_isom_set_extraction_slc function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

  • CVE-2021-31257MedApr 19, 2021
    risk 0.00cvss 5.5epss 0.01

    The HintFile function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

  • CVE-2021-28855MedApr 14, 2021
    risk 0.00cvss 5.5epss 0.01

    In Deark before 1.5.8, a specially crafted input file can cause a NULL pointer dereference in the dbuf_write function (src/deark-dbuf.c).

  • CVE-2021-27815MedApr 14, 2021
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.

  • CVE-2021-30178MedApr 7, 2021
    risk 0.00cvss 5.5epss 0.00

    An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer dereference for certain accesses to the SynIC Hyper-V context, aka CID-919f4ebc5987.

  • CVE-2021-3119HigMar 25, 2021
    risk 0.00cvss 7.5epss 0.02

    Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sqlite3StrICmp in sqlite3.c. This may allow an attacker to perform a remote denial of service attack. For example, an SQL injection can be used to execute the…

  • CVE-2021-26927MedFeb 23, 2021
    risk 0.00cvss 5.5epss 0.01

    A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.

  • CVE-2021-27186HigFeb 10, 2021
    risk 0.00cvss 7.5epss 0.02

    Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metrics.c.

  • CVE-2020-35450HigDec 26, 2020
    risk 0.00cvss 7.5epss 0.01

    Gobby 0.4.11 allows a NULL pointer dereference in the D-Bus handler for certain set_language calls.

  • CVE-2020-16588MedDec 9, 2020
    risk 0.00cvss 5.5epss 0.01

    A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp that can cause a denial of service via a crafted EXR file.

  • CVE-2020-27675MedOct 22, 2020
    risk 0.00cvss 4.7epss 0.00

    An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_base.c allows event-channel removal during the event-handling loop (a race condition). This can cause a use-after-free or NULL pointer dereference, as…

  • CVE-2020-25866HigOct 6, 2020
    risk 0.00cvss 7.5epss 0.04

    In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and…

  • CVE-2020-25285MedSep 13, 2020
    risk 0.00cvss 6.4epss 0.00

    A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.