VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,667)

page 281 of 284
  • CVE-2022-0908HigMar 11, 2022
    risk 0.00cvss 7.7epss 0.01

    Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.

  • CVE-2022-0433MedMar 10, 2022
    risk 0.00cvss 5.5epss 0.00

    A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_next_key function of the BPF bloom filter. This flaw allows a local user to crash the system. This flaw affects Linux kernel versions prior to 5.17-rc1.

  • CVE-2022-0890MedMar 10, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2.

  • CVE-2022-0712MedFeb 22, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.

  • CVE-2022-0696MedFeb 21, 2022
    risk 0.00cvss 5.5epss 0.02

    NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.

  • CVE-2022-0632MedFeb 19, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in Homebrew mruby prior to 3.2.

  • CVE-2022-25258MedFeb 16, 2022
    risk 0.00cvss 4.6epss 0.01

    An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory…

  • CVE-2022-0617MedFeb 16, 2022
    risk 0.00cvss 5.5epss 0.01

    A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.

  • CVE-2022-0562MedFeb 11, 2022
    risk 0.00cvss 5.5epss 0.01

    Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit…

  • CVE-2022-0561MedFeb 11, 2022
    risk 0.00cvss 5.5epss 0.01

    Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, the fix is available with…

  • CVE-2022-0481HigFeb 4, 2022
    risk 0.00cvss 7.5epss 0.01

    NULL Pointer Dereference in Homebrew mruby prior to 3.2.

  • CVE-2022-0419MedFeb 1, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.

  • CVE-2022-0286MedJan 31, 2022
    risk 0.00cvss 5.5epss 0.01

    A flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_add_sa() may lead to local denial of service.

  • CVE-2022-0326MedJan 21, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in Homebrew mruby prior to 3.2.

  • CVE-2022-0240HigJan 17, 2022
    risk 0.00cvss 7.5epss 0.01

    mruby is vulnerable to NULL Pointer Dereference

  • CVE-2021-46019MedJan 14, 2022
    risk 0.00cvss 5.5epss 0.01

    An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.

  • CVE-2022-23222HigJan 14, 2022
    risk 0.00cvss 7.8epss 0.02

    kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.

  • CVE-2015-4444Jul 15, 2015
    risk 0.00cvss —epss 0.03

    Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to cause a denial of service (NULL pointer…

  • CVE-2015-4443Jul 15, 2015
    risk 0.00cvss —epss 0.03

    Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to cause a denial of service (NULL pointer…

  • CVE-2014-9708Mar 31, 2015
    risk 0.00cvss —epss 0.56

    Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".