VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 48 of 277
  • CVE-2021-32987HigSep 23, 2021
    risk 0.49cvss 7.5epss 0.01

    Null pointer dereference in SuiteLink server while processing command 0x0b

  • CVE-2021-32979HigSep 23, 2021
    risk 0.49cvss 7.5epss 0.01

    Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a

  • CVE-2021-32971HigSep 23, 2021
    risk 0.49cvss 7.5epss 0.01

    Null pointer dereference in SuiteLink server while processing command 0x07

  • CVE-2021-32963HigSep 23, 2021
    risk 0.49cvss 7.5epss 0.01

    Null pointer dereference in SuiteLink server while processing commands 0x03/0x10

  • CVE-2021-38177HigSep 14, 2021
    risk 0.49cvss 7.5epss 0.03

    SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted malicious data in the HTTP requests over the network, this causes the SAP application to crash and has high impact on the…

  • CVE-2021-30698HigSep 8, 2021
    risk 0.49cvss 7.5epss 0.02

    A null pointer dereference was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, Safari 14.1.1, iOS 14.6 and iPadOS 14.6. A remote attacker may be able to cause a denial of service.

  • CVE-2020-19752HigSep 7, 2021
    risk 0.49cvss 7.5epss 0.02

    The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.

  • CVE-2021-22792HigSep 2, 2021
    risk 0.49cvss 7.5epss 0.01

    A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all…

  • CVE-2020-18731HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A segmentation violation in the Iec104_Deal_FirmUpdate function of IEC104 v1.0 allows attackers to cause a denial of service (DOS).

  • CVE-2020-18730HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A segmentation violation in the Iec104_Deal_I function of IEC104 v1.0 allows attackers to cause a denial of service (DOS).

  • CVE-2020-23331HigAug 17, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_DescriptorListWriter::Action component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).

  • CVE-2020-23330HigAug 17, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_Stz2Atom::GetSampleSize component located in /Core/Ap4Stz2Atom.cpp. It allows an attacker to cause a denial of service (DOS).

  • CVE-2021-38604HigAug 12, 2021
    risk 0.49cvss 7.5epss 0.03

    In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.

  • CVE-2021-38567HigAug 11, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Foxit PDF Editor before 11.0.1 and PDF Reader before 11.0.1 on macOS. It mishandles missing dictionary entries, leading to a NULL pointer dereference, aka CNVD-C-2021-95204.

  • CVE-2021-29296HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Null Pointer Dereference vulnerability in D-Link DIR-825 2.10b02, which could let a remote malicious user cause a denial of service. The vulnerability could be triggered by sending an HTTP request with URL /vct_wan; the sbin/httpd would invoke the strchr function and take NULL…

  • CVE-2021-29295HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Null Pointer Dereference vulnerability exists in D-Link DSP-W215 1.10, which could let a remote malicious user cause a denial of servie via usr/bin/lighttpd. It could be triggered by sending an HTTP request without URL in the start line directly to the device. NOTE: The DSP-W215…

  • CVE-2021-29294HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Null Pointer Dereference vulnerability exists in D-Link DSL-2740R UK_1.01, which could let a remove malicious user cause a denial of service via the send_hnap_unauthorized function. It could be triggered by sending crafted POST request to /HNAP1/. NOTE: The DSL-2740R and all…

  • CVE-2021-28845HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending the POST request to apply_cgi via the lang action…

  • CVE-2021-28844HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to apply_cgi via a do_graph_auth action without a session_id key.

  • CVE-2021-28843HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Null Pointer Dereference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03 by sending the POST request to apply_cgi with an unknown action name.