VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,667)

page 47 of 284
  • CVE-2022-30279HigMay 12, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus…

  • CVE-2021-33317HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from a null pointer dereference vulnerability. This vulnerability exists in its lldp related component. Due to fail to check if ChassisID TLV is contained in the packet, by sending a crafted lldp packet…

  • CVE-2022-29491HigMay 5, 2022
    risk 0.49cvss 7.5epss 0.01

    On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a virtual server is configured with HTTP, TCP on one side (client/server), and…

  • CVE-2021-44508HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer.

  • CVE-2021-44507HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of parameter validation in calls to memcpy in str_tok in sr_unix/ztimeoutroutines.c allows attackers to attempt to read from a NULL pointer.

  • CVE-2021-44506HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of input validation in calls to do_verify in sr_unix/do_verify.c allows attackers to attempt to jump to a NULL pointer by corrupting a function pointer.

  • CVE-2021-44505HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.

  • CVE-2021-44501HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.

  • CVE-2021-44498HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference.

  • CVE-2021-44495HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.

  • CVE-2021-44494HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.

  • CVE-2021-44492HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, attackers can cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference.

  • CVE-2021-44487HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer.

  • CVE-2021-44485HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in trip_gen in sr_port/emit_code.c allows attackers to crash the application by dereferencing a NULL pointer.

  • CVE-2021-44484HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in YottaDB through r1.32 and V7.0-000. A lack of NULL checks in calls to emit_trip in sr_port/emit_code.c allows attackers to crash the application by dereferencing a NULL pointer.

  • CVE-2021-44108HigApr 5, 2022
    risk 0.49cvss 7.5epss 0.01

    A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request to amf.

  • CVE-2021-42577HigMar 11, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client crash with a NULL pointer dereference.

  • CVE-2021-43824HigFeb 22, 2022
    risk 0.49cvss 7.5epss 0.01

    Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a CONNECT request is sent to JWT filter configured with regex match. This provides a denial of service attack vector. The only…

  • CVE-2022-22510HigFeb 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack of an unauthenticated user via SNMP.

  • CVE-2022-23025HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software…