VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 45 of 277
  • CVE-2022-34736HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.

  • CVE-2022-34735HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.

  • CVE-2022-2121HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    OFFIS DCMTK's (All versions prior to 3.6.7) has a NULL pointer dereference vulnerability while processing DICOM files, which may result in a denial-of-service condition.

  • CVE-2022-32230HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.07

    Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the April, 2022 patch set. By sending a malformed FileNormalizedNameInformation SMBv3 request over a named pipe, an attacker can cause a Blue Screen of Death (BSOD) crash of the…

  • CVE-2021-35087HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Possible null pointer access due to improper validation of system information message to be processed in Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-35076HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Possible null pointer dereference due to improper validation of RRC connection reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-33254HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri function.

  • CVE-2022-29795HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.

  • CVE-2022-30279HigMay 12, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus…

  • CVE-2021-33317HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from a null pointer dereference vulnerability. This vulnerability exists in its lldp related component. Due to fail to check if ChassisID TLV is contained in the packet, by sending a crafted lldp packet…

  • CVE-2022-29491HigMay 5, 2022
    risk 0.49cvss 7.5epss 0.01

    On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a virtual server is configured with HTTP, TCP on one side (client/server), and…

  • CVE-2021-44508HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer.

  • CVE-2021-44507HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of parameter validation in calls to memcpy in str_tok in sr_unix/ztimeoutroutines.c allows attackers to attempt to read from a NULL pointer.

  • CVE-2021-44506HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer.

  • CVE-2021-44505HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.

  • CVE-2021-44501HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.

  • CVE-2021-44498HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference.

  • CVE-2021-44495HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.

  • CVE-2021-44494HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.

  • CVE-2021-44492HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, attackers can cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference.