VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 82 of 277
  • CVE-2023-32171MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Unified Automation UaGateway OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to…

  • CVE-2024-27028MedMay 1, 2024
    risk 0.42cvss 6.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: spi: spi-mt65xx: Fix NULL pointer access in interrupt handler The TX buffer in spi_transfer can be a NULL pointer, so the interrupt handler may end up writing to the invalid memory and cause crashes. Add a…

  • CVE-2024-33345MedApr 29, 2024
    risk 0.42cvss 6.5epss 0.01

    D-Link DIR-823G A1V1.0.2B05 was found to contain a Null-pointer dereference in the main function of upload_firmware.cgi, which allows remote attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-49275MedApr 19, 2024
    risk 0.42cvss 6.5epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. A NULL pointer dereference was detected during fuzzing of the analysis engine, allowing malicious clients to DoS the analysis engine. The bug occurs when `analysisd` receives a…

  • CVE-2024-27978MedApr 19, 2024
    risk 0.42cvss 6.5epss 0.02

    A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.

  • CVE-2024-24991MedApr 19, 2024
    risk 0.42cvss 6.5epss 0.02

    A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.

  • CVE-2024-30403MedApr 12, 2024
    risk 0.42cvss 6.5epss 0.00

    A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS). When Layer 2 traffic is sent through a logical interface, MAC learning happens.…

  • CVE-2024-26183MedApr 9, 2024
    risk 0.42cvss 6.5epss 0.02

    Windows Kerberos Denial of Service Vulnerability

  • CVE-2024-31420MedApr 3, 2024
    risk 0.42cvss 6.5epss 0.01

    A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --virtio and then deleting the…

  • CVE-2024-0079MedMar 27, 2024
    risk 0.42cvss 6.5epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest VM can cause a NULL-pointer dereference in the host. A successful exploit of this vulnerability may lead to denial of service.

  • CVE-2024-0078MedMar 27, 2024
    risk 0.42cvss 6.5epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest can cause a NULL-pointer dereference in the host, which may lead to denial of service.

  • CVE-2023-43279MedMar 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command.

  • CVE-2024-27660MedFeb 29, 2024
    risk 0.42cvss 6.5epss 0.01

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-6247MedFeb 29, 2024
    risk 0.42cvss 6.5epss 0.01

    The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing.

  • CVE-2023-29179MedFeb 22, 2024
    risk 0.42cvss 6.5epss 0.02

    A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 allows attacker to denial of service via specially crafted HTTP requests.

  • CVE-2024-26130HigFeb 21, 2024
    risk 0.42cvss 7.5epss 0.01

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the…

  • CVE-2024-25197MedFeb 20, 2024
    risk 0.42cvss 6.5epss 0.01

    Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp.

  • CVE-2023-6397MedFeb 20, 2024
    risk 0.42cvss 6.5epss 0.00

    A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by…

  • CVE-2024-21356MedFeb 13, 2024
    risk 0.42cvss 6.5epss 0.02

    Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

  • CVE-2023-48364MedFeb 13, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC Route Control V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime…