VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,667)

page 44 of 284
  • CVE-2020-23259HigApr 4, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function in the src/jsiChar.c file.

  • CVE-2022-3116HigMar 27, 2023
    risk 0.49cvss 7.5epss 0.01

    The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can cause the application to crash.

  • CVE-2023-1444HigMar 17, 2023
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Filseclab Twister Antivirus 8. It has been rated as critical. This issue affects the function 0x8011206B in the library fildds.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack may be initiated…

  • CVE-2023-27787HigMar 16, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint.

  • CVE-2023-27785HigMar 16, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function.

  • CVE-2023-27784HigMar 16, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint.

  • CVE-2023-24859HigMar 14, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability

  • CVE-2023-21700HigFeb 14, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows iSCSI Discovery Service Denial of Service Vulnerability

  • CVE-2022-25735HigFeb 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Denial of service in modem due to missing null check while processing TCP or UDP packets from server

  • CVE-2022-25733HigFeb 12, 2023
    risk 0.49cvss 7.5epss 0.00

    Denial of service in modem due to null pointer dereference while processing DNS packets

  • CVE-2023-0401HigFeb 8, 2023
    risk 0.49cvss 7.5epss 0.02

    A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest…

  • CVE-2023-0217HigFeb 8, 2023
    risk 0.49cvss 7.5epss 0.02

    An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. This will most likely lead to an application crash. This function can be called on public keys supplied from untrusted…

  • CVE-2023-0216HigFeb 8, 2023
    risk 0.49cvss 7.5epss 0.02

    An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service…

  • CVE-2022-32663HigFeb 6, 2023
    risk 0.49cvss 7.5epss 0.02

    In Wi-Fi driver, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220720014; Issue ID: GN20220720014.

  • CVE-2023-22839HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled,…

  • CVE-2023-22341HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed requests may cause the Traffic Management Microkernel (TMM) to terminate: * An OAuth Server that references an OAuth Provider …

  • CVE-2023-22340HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have…

  • CVE-2022-44018HigJan 26, 2023
    risk 0.49cvss 7.5epss 0.01

    In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer dereference or out-of-bounds memory access in the subscriber application.

  • CVE-2023-21757HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability

  • CVE-2023-21683HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability