VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 50 of 277
  • CVE-2021-25693HigMay 13, 2021
    risk 0.49cvss 7.5epss 0.01

    An attacker may cause a Denial of Service (DoS) in multiple versions of Teradici PCoIP Agent via a null pointer dereference.

  • CVE-2021-32611HigMay 12, 2021
    risk 0.49cvss 7.5epss 0.01

    A NULL pointer dereference vulnerability exists in eXcall_api.c in Antisip eXosip2 through 5.2.0 when handling certain 3xx redirect responses.

  • CVE-2021-25845HigMay 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a NULL pointer dereference via a crafted lldp packet.

  • CVE-2020-11273HigMay 7, 2021
    risk 0.49cvss 7.5epss 0.01

    Histogram type KPI was teardown with the assumption of the existence of histogram binning info and will lead to null pointer access when histogram binning info is missing due to lack of null check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2021-29241HigMay 3, 2021
    risk 0.49cvss 7.5epss 0.01

    CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).

  • CVE-2021-31826HigApr 27, 2021
    risk 0.49cvss 7.5epss 0.02

    Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.

  • CVE-2020-23539HigApr 8, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Realtek rtl8723de BLE Stack <= 4.1 that allows remote attackers to cause a Denial of Service via the interval field to the CONNECT_REQ message.

  • CVE-2021-20213HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Dereference of a NULL-pointer that could result in a crash if accept-intercepted-requests was enabled, Privoxy failed to get the request destination from the Host header and a memory allocation failed.

  • CVE-2021-28361HigMar 13, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI target with a zero length (but data is expected), the iSCSI target can crash with a NULL pointer dereference.

  • CVE-2021-28307HigMar 12, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the fltk crate before 0.15.3 for Rust. There is a NULL pointer dereference during attempted use of a non-raster image for a window icon.

  • CVE-2021-28306HigMar 12, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the fltk crate before 0.15.3 for Rust. There is a NULL pointer dereference during attempted use of a multi label type if the image is nonexistent.

  • CVE-2021-20274HigMar 9, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbehaves.

  • CVE-2021-25690HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.01

    A null pointer dereference in Teradici PCoIP Soft Client versions prior to 20.07.3 could allow an attacker to crash the software.

  • CVE-2020-13583HigFeb 10, 2021
    risk 0.49cvss 7.5epss 0.02

    A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2020-13578HigFeb 10, 2021
    risk 0.49cvss 7.5epss 0.03

    A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2020-13577HigFeb 10, 2021
    risk 0.49cvss 7.5epss 0.03

    A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2020-13575HigFeb 10, 2021
    risk 0.49cvss 7.5epss 0.02

    A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2020-13574HigFeb 10, 2021
    risk 0.49cvss 7.5epss 0.03

    A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2020-13582HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.03

    A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-25904HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the av-data crate before 0.3.0 for Rust. A raw pointer is dereferenced, leading to a read of an arbitrary memory address, sometimes causing a segfault.