VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 41 of 277
  • CVE-2023-49936HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. A NULL pointer dereference leads to denial of service. The fixed versions are 22.05.11, 23.02.7, and 23.11.1.

  • CVE-2023-48416HigDec 8, 2023
    risk 0.49cvss 7.5epss 0.00

    In multiple locations, there is a possible null dereference due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-33089HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when processing a NULL buffer while parsing WLAN vdev.

  • CVE-2023-40459HigDec 4, 2023
    risk 0.49cvss 7.5epss 0.02

    The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers…

  • CVE-2023-33056HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE.

  • CVE-2023-46345HigOct 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c.

  • CVE-2023-36709HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.03

    Microsoft AllJoyn API Denial of Service Vulnerability

  • CVE-2023-36603HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows TCP/IP Denial of Service Vulnerability

  • CVE-2023-36602HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows TCP/IP Denial of Service Vulnerability

  • CVE-2023-24847HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Modem while allocating DSM items.

  • CVE-2022-48606HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.00

    Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-36199HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in skalenetwork sgxwallet v.1.9.0 and below allows an attacker to cause a denial of service via the trustedGenerateEcdsaKey component.

  • CVE-2023-39669HigAug 18, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-880 A1_FW107WWb08 was discovered to contain a NULL pointer dereference in the function FUN_00010824.

  • CVE-2023-39397HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-32252HigJul 24, 2023
    risk 0.49cvss 7.5epss 0.04

    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_LOGOFF commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this…

  • CVE-2023-32248HigJul 24, 2023
    risk 0.49cvss 7.5epss 0.04

    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_TREE_CONNECT and SMB2_QUERY_INFO commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An…

  • CVE-2023-29984HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected…

  • CVE-2023-35338HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Peer Name Resolution Protocol Denial of Service Vulnerability

  • CVE-2023-32084HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.02

    HTTP.sys Denial of Service Vulnerability

  • CVE-2023-3354HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake…