VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (1,024)

page 38 of 52
  • CVE-2017-5951MedApr 3, 2017
    risk 0.36cvss 5.5epss 0.01

    The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

  • CVE-2016-10220MedApr 3, 2017
    risk 0.36cvss 5.5epss 0.01

    The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file that is mishandled in the PDF Transparency module.

  • CVE-2016-10218MedApr 3, 2017
    risk 0.36cvss 5.5epss 0.00

    The pdf14_pop_transparency_group function in base/gdevp14.c in the PDF Transparency module in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

  • CVE-2016-10209MedApr 3, 2017
    risk 0.36cvss 5.5epss 0.01

    The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file.

  • CVE-2014-9814MedMar 30, 2017
    risk 0.36cvss 5.5epss 0.00

    ImageMagick allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted wpg file.

  • CVE-2014-9812MedMar 30, 2017
    risk 0.36cvss 5.5epss 0.00

    ImageMagick allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted ps file.

  • CVE-2016-8884MedMar 28, 2017
    risk 0.36cvss 5.5epss 0.00

    The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8690.

  • CVE-2017-7274MedMar 27, 2017
    risk 0.36cvss 5.5epss 0.00

    The r_pkcs7_parse_cms function in libr/util/r_pkcs7.c in radare2 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PE file.

  • CVE-2016-8887MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.00

    The jp2_colr_destroy function in libjasper/jp2/jp2_cod.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (NULL pointer dereference).

  • CVE-2016-8885MedMar 23, 2017
    risk 0.36cvss 5.5epss 0.00

    The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.9 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image.

  • CVE-2017-7209MedMar 21, 2017
    risk 0.36cvss 5.5epss 0.00

    The dump_section_as_bytes function in readelf in GNU Binutils 2.28 accesses a NULL pointer while reading section contents in a corrupt binary, leading to a program crash.

  • CVE-2017-7207MedMar 21, 2017
    risk 0.36cvss 5.5epss 0.00

    The mem_get_bits_rectangle function in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PostScript document.

  • CVE-2017-6951MedMar 16, 2017
    risk 0.36cvss 5.5epss 0.00

    The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.

  • CVE-2015-8898MedMar 15, 2017
    risk 0.36cvss 5.5epss 0.00

    The WriteImages function in magick/constitute.c in ImageMagick before 6.9.2-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image file.

  • CVE-2017-6850MedMar 15, 2017
    risk 0.36cvss 5.5epss 0.00

    The jp2_cdef_destroy function in jp2_cod.c in JasPer before 2.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.

  • CVE-2017-6849MedMar 15, 2017
    risk 0.36cvss 5.5epss 0.00

    The PoDoFo::PdfColorGray::~PdfColorGray function in PdfColor.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

  • CVE-2017-6848MedMar 15, 2017
    risk 0.36cvss 5.5epss 0.00

    The PoDoFo::PdfXObject::PdfXObject function in PdfXObject.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

  • CVE-2017-6847MedMar 15, 2017
    risk 0.36cvss 5.5epss 0.00

    The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

  • CVE-2017-6846MedMar 15, 2017
    risk 0.36cvss 5.5epss 0.00

    The GraphicsStack::TGraphicsStackElement::SetNonStrokingColorSpace function in graphicsstack.h in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

  • CVE-2017-6845MedMar 15, 2017
    risk 0.36cvss 5.5epss 0.00

    The PoDoFo::PdfColor::operator function in PdfColor.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.