VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 40 of 277
  • CVE-2023-52513HigMar 2, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix connection failure handling In case immediate MPA request processing fails, the newly created endpoint unlinks the listening endpoint and is ready to be dropped. This special case was not handled…

  • CVE-2024-26342HigFeb 28, 2024
    risk 0.49cvss 7.5epss 0.01

    A Null pointer dereference in usr/sbin/httpd in ASUS AC68U 3.0.0.4.384.82230 allows remote attackers to trigger DoS via network packet.

  • CVE-2021-46983HigFeb 28, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: Fix NULL deref when SEND is completed with error When running some traffic and taking down the link on peer, a retry counter exceeded error is received. This leads to nvmet_rdma_error_comp which…

  • CVE-2021-46948HigFeb 27, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: sfc: farch: fix TX queue lookup in TX event handling We're starting from a TXQ label, not a TXQ type, so efx_channel_get_tx_queue() is inappropriate (and could return NULL, leading to panics).

  • CVE-2024-25768HigFeb 26, 2024
    risk 0.49cvss 7.5epss 0.01

    OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.

  • CVE-2023-52454HigFeb 23, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length If the host sends an H2CData command with an invalid DATAL, the kernel may crash in nvmet_tcp_build_pdu_iovec(). Unable to handle kernel…

  • CVE-2023-29180HigFeb 22, 2024
    risk 0.49cvss 7.5epss 0.03

    A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 through 1.2.13, 1.1.0 through…

  • CVE-2024-24989HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC…

  • CVE-2024-24775HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2024-23308HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause the BD process to terminate. The condition results from setting the Request Body Handling option in the Header-Based Content…

  • CVE-2024-21763HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffic Management Microkernel (TMM) to terminate.  NOTE: Software versions which have reached End of Technical Support (EoTS) are…

  • CVE-2024-21404HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.03

    .NET Denial of Service Vulnerability

  • CVE-2023-43522HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.

  • CVE-2023-46838HigJan 29, 2024
    risk 0.49cvss 7.5epss 0.01

    Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be transferred data, these parts…

  • CVE-2024-21602HigJan 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS Evolved on ACX7024, ACX7100-32C and ACX7100-48L allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). If a specific IPv4 UDP packet is received and sent to the Routing Engine…

  • CVE-2024-20661HigJan 9, 2024
    risk 0.49cvss 7.5epss 0.03

    Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

  • CVE-2023-33109HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.

  • CVE-2023-38321HigDec 25, 2023
    risk 0.49cvss 7.5epss 0.01

    OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter…

  • CVE-2023-50472HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.01

    cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.

  • CVE-2023-50471HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.02

    cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.