VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 37 of 277
  • CVE-2024-38232HigSep 10, 2024
    risk 0.49cvss 7.5epss 0.02

    Windows Networking Denial of Service Vulnerability

  • CVE-2024-7652HigSep 6, 2024
    risk 0.49cvss 7.5epss 0.01

    An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird <…

  • CVE-2024-44992HigSep 4, 2024
    risk 0.49cvss 7.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: smb/client: avoid possible NULL dereference in cifs_free_subrequest() Clang static checker (scan-build) warning: cifsglob.h:line 890, column 3 Access to field 'ops' results in a dereference of a null…

  • CVE-2024-42058HigSep 3, 2024
    risk 0.49cvss 7.5epss 0.01

    A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V5.20 through V5.38, and USG20(W)-VPN series firmware versions from…

  • CVE-2024-45239HigAug 24, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a null eContent field. Fort dereferences the pointer without sanitizing it first. Because Fort is…

  • CVE-2024-45238HigAug 24, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that doesn't properly decode into a Subject Public Key. OpenSSL does not report this…

  • CVE-2024-45235HigAug 24, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing an Authority Key Identifier extension that lacks the keyIdentifier field. Fort references this…

  • CVE-2023-52909HigAug 21, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: nfsd: fix handling of cached open files in nfsd4_open codepath Commit fb70bf124b05 ("NFSD: Instantiate a struct file when creating a regular NFSv4 file") added the ability to cache an open fd over a compound.…

  • CVE-2024-42286HigAug 17, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: validate nvme_local_port correctly The driver load failed with error message, qla2xxx [0000:04:00.0]-ffff:0: register_localport failed: ret=ffffffef and with a kernel crash, BUG: unable to…

  • CVE-2024-43357HigAug 15, 2024
    risk 0.49cvss 8.6epss 0.01

    ECMA-262 is the language specification for the scripting language ECMAScript. A problem in the ECMAScript (JavaScript) specification of async generators, introduced by a May 2021 spec refactor, may lead to mis-implementation in a way that could present as a security…

  • CVE-2024-38146HigAug 13, 2024
    risk 0.49cvss 7.5epss 0.02

    Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability

  • CVE-2024-38145HigAug 13, 2024
    risk 0.49cvss 7.5epss 0.02

    Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability

  • CVE-2024-38126HigAug 13, 2024
    risk 0.49cvss 7.5epss 0.03

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

  • CVE-2024-7006HigAug 12, 2024
    risk 0.49cvss 7.5epss 0.02

    A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an…

  • CVE-2024-37826HigAug 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

  • CVE-2024-39948HigJul 31, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

  • CVE-2024-38536HigJul 11, 2024
    risk 0.49cvss 7.5epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A memory allocation failure due to `http.memcap` being reached leads to a NULL-ptr reference leading to a crash. Upgrade to 7.0.6.

  • CVE-2024-38072HigJul 9, 2024
    risk 0.49cvss 7.5epss 0.02

    Windows Remote Desktop Licensing Service Denial of Service Vulnerability

  • CVE-2024-36982HigJul 1, 2024
    risk 0.49cvss 7.5epss 0.00

    In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the cluster/config REST endpoint, which could result in a crash of the Splunk daemon.

  • CVE-2024-39130HigJun 27, 2024
    risk 0.49cvss 7.5epss 0.00

    A NULL Pointer Dereference discovered in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function DumpOneStream() at /src/DumpStream.cpp.