VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 43 of 277
  • CVE-2022-25733HigFeb 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Denial of service in modem due to null pointer dereference while processing DNS packets

  • CVE-2023-0401HigFeb 8, 2023
    risk 0.49cvss 7.5epss 0.02

    A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest…

  • CVE-2023-0217HigFeb 8, 2023
    risk 0.49cvss 7.5epss 0.02

    An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. This will most likely lead to an application crash. This function can be called on public keys supplied from untrusted…

  • CVE-2023-0216HigFeb 8, 2023
    risk 0.49cvss 7.5epss 0.02

    An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service…

  • CVE-2022-32663HigFeb 6, 2023
    risk 0.49cvss 7.5epss 0.02

    In Wi-Fi driver, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220720014; Issue ID: GN20220720014.

  • CVE-2023-22839HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled,…

  • CVE-2023-22341HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed requests may cause the Traffic Management Microkernel (TMM) to terminate: * An OAuth Server that references an OAuth Provider …

  • CVE-2023-22340HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have…

  • CVE-2022-44018HigJan 26, 2023
    risk 0.49cvss 7.5epss 0.01

    In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer dereference or out-of-bounds memory access in the subscriber application.

  • CVE-2023-21757HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability

  • CVE-2023-21683HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability

  • CVE-2022-33299HigJan 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data.

  • CVE-2022-33290HigJan 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Bluetooth HOST due to null pointer dereference when a mismatched argument is passed.

  • CVE-2022-41999HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2. A specially-crafted .dds can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2022-42527HigDec 16, 2022
    risk 0.49cvss 7.5epss 0.01

    In cd_SsParseMsg of cd_SsCodec.c, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid…

  • CVE-2022-25741HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Denial of service in WLAN due to potential null pointer dereference while accessing the memory location in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2022-25710HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Denial of service due to null pointer dereference when GATT is disconnected in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2022-41787HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when DNS profile is configured on a virtual server with DNS Express enabled, undisclosed DNS queries with DNSSEC can cause TMM to…

  • CVE-2022-22232HigOct 18, 2022
    risk 0.49cvss 7.5epss 0.01

    A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On SRX Series If Unified Threat Management (UTM) Enhanced Content Filtering…

  • CVE-2022-40759HigSep 16, 2022
    risk 0.49cvss 7.5epss 0.01

    A NULL pointer dereference issue in the TEE_MACCompareFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_MACCompareFinal with a NULL pointer for the parameter operation.