VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,667)

page 45 of 284
  • CVE-2022-33299HigJan 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data.

  • CVE-2022-33290HigJan 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Bluetooth HOST due to null pointer dereference when a mismatched argument is passed.

  • CVE-2021-44758HigDec 26, 2022
    risk 0.49cvss 7.5epss 0.01

    Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_response value to send_accept.

  • CVE-2022-41999HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2. A specially-crafted .dds can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2022-42527HigDec 16, 2022
    risk 0.49cvss 7.5epss 0.01

    In cd_SsParseMsg of cd_SsCodec.c, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid…

  • CVE-2022-25741HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Denial of service in WLAN due to potential null pointer dereference while accessing the memory location in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2022-25710HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Denial of service due to null pointer dereference when GATT is disconnected in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2022-41787HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when DNS profile is configured on a virtual server with DNS Express enabled, undisclosed DNS queries with DNSSEC can cause TMM to…

  • CVE-2022-22232HigOct 18, 2022
    risk 0.49cvss 7.5epss 0.01

    A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On SRX Series If Unified Threat Management (UTM) Enhanced Content Filtering…

  • CVE-2022-40759HigSep 16, 2022
    risk 0.49cvss 7.5epss 0.01

    A NULL pointer dereference issue in the TEE_MACCompareFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_MACCompareFinal with a NULL pointer for the parameter operation.

  • CVE-2022-37797HigSep 12, 2022
    risk 0.49cvss 7.5epss 0.03

    In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service…

  • CVE-2022-39829HigSep 5, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_new.

  • CVE-2022-36622HigSep 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1.

  • CVE-2022-36621HigSep 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_AllocateTransientObject.

  • CVE-2020-35525HigSep 1, 2022
    risk 0.49cvss 7.5epss 0.01

    In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.

  • CVE-2022-39028HigAug 30, 2022
    risk 0.49cvss 7.5epss 0.02

    telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However,…

  • CVE-2022-1199HigAug 29, 2022
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.

  • CVE-2021-42521HigAug 25, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that…

  • CVE-2022-2547HigAug 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A crafted HTTP packet without a content-type header can create a denial-of-service condition in Softing Secure Integration Server V1.22.

  • CVE-2022-2337HigAug 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A crafted HTTP packet with a missing HTTP URI can create a denial-of-service condition in Softing Secure Integration Server V1.22.