CWE-476
NULL Pointer Dereference
Description
The product dereferences a pointer that it expects to be valid but is NULL.
Hierarchy (View 1000)
CVEs mapped to this weakness (5,667)
page 44 of 284| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-23259 | Hig | 0.49 | 7.5 | 0.01 | Apr 4, 2023 | An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function in the src/jsiChar.c file. | ||
| CVE-2022-3116 | Hig | 0.49 | 7.5 | 0.01 | Mar 27, 2023 | The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can cause the application to crash. | ||
| CVE-2023-1444 | Hig | 0.49 | 7.5 | 0.01 | Mar 17, 2023 | A vulnerability was found in Filseclab Twister Antivirus 8. It has been rated as critical. This issue affects the function 0x8011206B in the library fildds.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack may be initiated… | ||
| CVE-2023-27787 | Hig | 0.49 | 7.5 | 0.01 | Mar 16, 2023 | An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint. | ||
| CVE-2023-27785 | Hig | 0.49 | 7.5 | 0.01 | Mar 16, 2023 | An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function. | ||
| CVE-2023-27784 | Hig | 0.49 | 7.5 | 0.01 | Mar 16, 2023 | An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint. | ||
| CVE-2023-24859 | Hig | 0.49 | 7.5 | 0.02 | Mar 14, 2023 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | ||
| CVE-2023-21700 | Hig | 0.49 | 7.5 | 0.02 | Feb 14, 2023 | Windows iSCSI Discovery Service Denial of Service Vulnerability | ||
| CVE-2022-25735 | Hig | 0.49 | 7.5 | 0.00 | Feb 12, 2023 | Denial of service in modem due to missing null check while processing TCP or UDP packets from server | ||
| CVE-2022-25733 | Hig | 0.49 | 7.5 | 0.00 | Feb 12, 2023 | Denial of service in modem due to null pointer dereference while processing DNS packets | ||
| CVE-2023-0401 | Hig | 0.49 | 7.5 | 0.02 | Feb 8, 2023 | A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest… | ||
| CVE-2023-0217 | Hig | 0.49 | 7.5 | 0.02 | Feb 8, 2023 | An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. This will most likely lead to an application crash. This function can be called on public keys supplied from untrusted… | ||
| CVE-2023-0216 | Hig | 0.49 | 7.5 | 0.02 | Feb 8, 2023 | An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service… | ||
| CVE-2022-32663 | Hig | 0.49 | 7.5 | 0.02 | Feb 6, 2023 | In Wi-Fi driver, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220720014; Issue ID: GN20220720014. | ||
| CVE-2023-22839 | Hig | 0.49 | 7.5 | 0.01 | Feb 1, 2023 | On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled,… | ||
| CVE-2023-22341 | Hig | 0.49 | 7.5 | 0.01 | Feb 1, 2023 | On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed requests may cause the Traffic Management Microkernel (TMM) to terminate: * An OAuth Server that references an OAuth Provider … | ||
| CVE-2023-22340 | Hig | 0.49 | 7.5 | 0.01 | Feb 1, 2023 | On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have… | ||
| CVE-2022-44018 | Hig | 0.49 | 7.5 | 0.01 | Jan 26, 2023 | In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer dereference or out-of-bounds memory access in the subscriber application. | ||
| CVE-2023-21757 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2023 | Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability | ||
| CVE-2023-21683 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2023 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability |
- risk 0.49cvss 7.5epss 0.01
An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function in the src/jsiChar.c file.
- risk 0.49cvss 7.5epss 0.01
The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can cause the application to crash.
- risk 0.49cvss 7.5epss 0.01
A vulnerability was found in Filseclab Twister Antivirus 8. It has been rated as critical. This issue affects the function 0x8011206B in the library fildds.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack may be initiated…
- risk 0.49cvss 7.5epss 0.01
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint.
- risk 0.49cvss 7.5epss 0.01
An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function.
- risk 0.49cvss 7.5epss 0.01
An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint.
- risk 0.49cvss 7.5epss 0.02
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows iSCSI Discovery Service Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.00
Denial of service in modem due to missing null check while processing TCP or UDP packets from server
- risk 0.49cvss 7.5epss 0.00
Denial of service in modem due to null pointer dereference while processing DNS packets
- risk 0.49cvss 7.5epss 0.02
A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not available the digest…
- risk 0.49cvss 7.5epss 0.02
An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. This will most likely lead to an application crash. This function can be called on public keys supplied from untrusted…
- risk 0.49cvss 7.5epss 0.02
An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service…
- risk 0.49cvss 7.5epss 0.02
In Wi-Fi driver, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220720014; Issue ID: GN20220720014.
- risk 0.49cvss 7.5epss 0.01
On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all version of 13.1.x, when a DNS profile with the Rapid Response Mode setting enabled is configured on a virtual server with hardware SYN cookies enabled,…
- risk 0.49cvss 7.5epss 0.01
On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the following elements, undisclosed requests may cause the Traffic Management Microkernel (TMM) to terminate: * An OAuth Server that references an OAuth Provider …
- risk 0.49cvss 7.5epss 0.01
On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have…
- risk 0.49cvss 7.5epss 0.01
In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer dereference or out-of-bounds memory access in the subscriber application.
- risk 0.49cvss 7.5epss 0.02
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability