VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,667)

page 46 of 284
  • CVE-2022-1748HigAug 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affected by a NULL pointer dereference vulnerability.

  • CVE-2022-36186HigAug 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in commit b43f9d1.

  • CVE-2022-2832HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may lead to loss of confidentiality and integrity.

  • CVE-2022-26979HigAug 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.

  • CVE-2022-27944HigAug 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference.

  • CVE-2022-35245HigAug 4, 2022
    risk 0.49cvss 7.5epss 0.01

    In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5.1, when a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which…

  • CVE-2022-34651HigAug 4, 2022
    risk 0.49cvss 7.5epss 0.01

    In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, when an LTM Client or Server SSL profile with TLS 1.3 enabled is configured on a virtual server, along with an iRule that calls HTTP::respond, undisclosed requests can cause the Traffic Management Microkernel…

  • CVE-2022-34969HigAug 3, 2022
    risk 0.49cvss 7.5epss 0.01

    PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.

  • CVE-2022-31213HigJul 17, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in dbus-broker before 31. Multiple NULL pointer dereferences can be found when supplying a malformed XML config file.

  • CVE-2022-32298HigJul 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Toybox v0.8.7 was discovered to contain a NULL pointer dereference via the component httpd.c. This vulnerability can lead to a Denial of Service (DoS) via unspecified vectors.

  • CVE-2022-34761HigJul 13, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-476: NULL Pointer Dereference vulnerability exists that could cause a denial of service of the webserver when parsing JSON content type. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module…

  • CVE-2022-34736HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.

  • CVE-2022-34735HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.

  • CVE-2021-41689HigJun 28, 2022
    risk 0.49cvss 7.5epss 0.02

    DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can use it to launch a DoS attack.

  • CVE-2022-2121HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    OFFIS DCMTK's (All versions prior to 3.6.7) has a NULL pointer dereference vulnerability while processing DICOM files, which may result in a denial-of-service condition.

  • CVE-2022-32230HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.08

    Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the April, 2022 patch set. By sending a malformed FileNormalizedNameInformation SMBv3 request over a named pipe, an attacker can cause a Blue Screen of Death (BSOD) crash of the…

  • CVE-2021-35087HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Possible null pointer access due to improper validation of system information message to be processed in Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-35076HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Possible null pointer dereference due to improper validation of RRC connection reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-33254HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri function.

  • CVE-2022-29795HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.