VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 46 of 277
  • CVE-2021-44487HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer.

  • CVE-2021-44485HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in trip_gen in sr_port/emit_code.c allows attackers to crash the application by dereferencing a NULL pointer.

  • CVE-2021-44484HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to emit_trip in sr_port/emit_code.c allows attackers to crash the application by dereferencing a NULL pointer.

  • CVE-2021-42577HigMar 11, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client crash with a NULL pointer dereference.

  • CVE-2022-22510HigFeb 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack of an unauthenticated user via SNMP.

  • CVE-2022-23025HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software…

  • CVE-2022-23022HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.1.x before 16.1.2, when an HTTP profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2022-23021HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.1.x before 16.1.2, when any of the following configurations are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate: HTTP redirect rule in an LTM policy, BIG-IP APM Access Profile, and Explicit…

  • CVE-2022-23020HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.1.x before 16.1.2, when the 'Respond on Error' setting is enabled on the Request Logging profile and configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have…

  • CVE-2022-23017HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when a virtual server is configured with a DNS profile with the Rapid Response Mode setting enabled and is configured on a BIG-IP system, undisclosed requests can…

  • CVE-2022-23016HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP SSL Forward Proxy with TLS 1.3 is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of…

  • CVE-2021-38786HigJan 19, 2022
    risk 0.49cvss 7.5epss 0.02

    There is a NULL pointer dereference in media/libcedarc/vdecoder of Allwinner R818 SoC Android Q SDK V1.0, which could cause a media crash (denial of service).

  • CVE-2021-38785HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.02

    There is a NULL pointer deference in the Allwinner R818 SoC Android Q SDK V1.0 camera driver /dev/cedar_dev that could use the ioctl cmd IOCTL_GET_IOMMU_ADDR to cause a system crash.

  • CVE-2021-38784HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.02

    There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that could executable a malicious file to cause a system crash.

  • CVE-2022-23094HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.03

    Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.

  • CVE-2021-45773HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.01

    A NULL pointer dereference in CS104_IPAddress_setFromString at src/iec60870/cs104/cs104_slave.c of lib60870 commit 0d5e76e can lead to a segmentation fault or application crash.

  • CVE-2021-45769HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.01

    A NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a segmentation fault or application crash.

  • CVE-2021-45761HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.01

    ROPium v3.1 was discovered to contain an invalid memory address dereference via the find() function.

  • CVE-2021-30330HigJan 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Possible null pointer dereference due to improper validation of APE clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-40039HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.