VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 57 of 277
  • CVE-2018-19939HigDec 7, 2018
    risk 0.49cvss 7.5epss 0.01

    The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfree after a kmalloc failure in gtp_read_Color in…

  • CVE-2018-19935HigDec 7, 2018
    risk 0.49cvss 7.5epss 0.06

    ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty string in the message argument to the imap_mail function.

  • CVE-2018-14747HigNov 28, 2018
    risk 0.49cvss 7.5epss 0.01

    NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to crash the NAS media server.

  • CVE-2018-19395HigNov 20, 2018
    risk 0.49cvss 7.5epss 0.04

    ext/standard/var.c in PHP 5.x through 7.1.24 on Windows allows attackers to cause a denial of service (NULL pointer dereference and application crash) because com and com_safearray_proxy return NULL in com_properties_get in ext/com_dotnet/com_handlers.c, as demonstrated by a…

  • CVE-2018-18937HigNov 5, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in ClientDataSet_getValues in client/ied_connection.c.

  • CVE-2018-2914HigOct 17, 2018
    risk 0.49cvss 7.5epss 0.04

    Vulnerability in the Oracle GoldenGate component of Oracle GoldenGate (subcomponent: Manager). Supported versions that are affected are 12.1.2.1.0, 12.2.0.2.0 and 12.3.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to…

  • CVE-2018-2912HigOct 17, 2018
    risk 0.49cvss 7.5epss 0.04

    Vulnerability in the Oracle GoldenGate component of Oracle GoldenGate (subcomponent: Manager). Supported versions that are affected are 12.1.2.1.0, 12.2.0.2.0 and 12.3.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to…

  • CVE-2018-18318HigOct 15, 2018
    risk 0.49cvss 7.5epss 0.01

    The /dev/block/mmcblk0rpmb driver kernel module on Qiku 360 Phone N6 Pro 1801-A01 devices allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted 0xc0d8b300 ioctl call.

  • CVE-2018-12469HigOct 12, 2018
    risk 0.49cvss 7.5epss 0.01

    Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Update 2 and earlier, 3.0 before Patch Update 12, and 4.0 before Patch Update 2…

  • CVE-2018-18227HigOct 12, 2018
    risk 0.49cvss 7.5epss 0.03

    In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was addressed in epan/dissectors/packet-mswsp.c by properly handling NULL return values.

  • CVE-2018-0049HigOct 10, 2018
    risk 0.49cvss 7.5epss 0.02

    A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to cause the Junos OS kernel to crash. Continued receipt of this specifically crafted malicious MPLS packet will cause a sustained Denial of Service condition. This issue require it to be…

  • CVE-2018-18066HigOct 8, 2018
    risk 0.49cvss 7.5epss 0.04

    snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.

  • CVE-2018-17142HigSep 17, 2018
    risk 0.49cvss 7.5epss 0.03

    The html package (aka x/net/html) through 2018-09-17 in Go mishandles , leading to a "panic: runtime error" in parseCurrentToken in parse.go during an html.Parse call.

  • CVE-2018-17127HigSep 17, 2018
    risk 0.49cvss 7.5epss 0.01

    blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (NULL pointer dereference and device crash) via a request that lacks a timestap parameter.

  • CVE-2018-17073HigSep 16, 2018
    risk 0.49cvss 7.5epss 0.01

    wernsey/bitmap before 2018-08-18 allows a NULL pointer dereference via a 4-bit image.

  • CVE-2018-14737HigJul 30, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A NULL pointer dereference can occur in pbc_wmessage_string in wmessage.c.

  • CVE-2018-14588HigJul 24, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in Bento4 1.5.1-624. A NULL pointer dereference can occur in AP4_DataBuffer::SetData in Core/Ap4DataBuffer.cpp.

  • CVE-2018-3841HigJun 26, 2018
    risk 0.49cvss 7.5epss 0.02

    A denial-of-service vulnerability exists in the Pixar Renderman IT Display Service 21.6 (0x69). The vulnerability is present in the parsing of a network packet without proper validation of the packet. The data read-in is not validated, and its use can lead to a null pointer…

  • CVE-2018-3840HigJun 26, 2018
    risk 0.49cvss 7.5epss 0.02

    A denial-of-service vulnerability exists in the Pixar Renderman IT Display Service 21.6 (0x67). The vulnerability is present in the parsing of a network packet without proper validation of the packet. The data read by the application is not validated, and its use can lead to a…

  • CVE-2018-12697HigJun 23, 2018
    risk 0.49cvss 7.5epss 0.05

    A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump.