VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,659)

page 88 of 283
  • CVE-2022-22638MedMar 18, 2022
    risk 0.42cvss 6.5epss 0.02

    A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An attacker in a privileged position may be able to perform a…

  • CVE-2021-20299HigMar 16, 2022
    risk 0.42cvss 7.5epss 0.02

    A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerability is to system availability.

  • CVE-2021-3596MedFeb 24, 2022
    risk 0.42cvss 6.5epss 0.02

    A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and…

  • CVE-2021-44960MedFeb 15, 2022
    risk 0.42cvss 6.5epss 0.01

    In SVGPP SVG++ library 1.3.0, the XMLDocument::getRoot function in the renderDocument function handled the XMLDocument object improperly, returning a null pointer in advance at the second if, resulting in a null pointer reference behind the renderDocument function.

  • CVE-2021-33068MedFeb 9, 2022
    risk 0.42cvss 6.5epss 0.01

    Null pointer dereference in subsystem for Intel(R) AMT before versions 15.0.35 may allow an authenticated user to potentially enable denial of service via network access.

  • CVE-2022-21736HigFeb 3, 2022
    risk 0.42cvss 7.6epss 0.01

    Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseTensorSliceDataset` has an undefined behavior: under certain condition it can be made to dereference a `nullptr` value. The 3 input arguments to `SparseTensorSliceDataset` represent a sparse…

  • CVE-2021-45340MedJan 25, 2022
    risk 0.42cvss 6.5epss 0.01

    In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.

  • CVE-2021-46243MedJan 21, 2022
    risk 0.42cvss 6.5epss 0.01

    An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at hdf5/src/H5Odtype.c. This vulnerability can lead to a Denial of Service (DoS).

  • CVE-2020-36135MedDec 2, 2021
    risk 0.42cvss 6.5epss 0.01

    AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c.

  • CVE-2020-36130MedDec 2, 2021
    risk 0.42cvss 6.5epss 0.01

    AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component av1/av1_dx_iface.c.

  • CVE-2021-27836MedNov 3, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial of service, via a crafted XLS file.

  • CVE-2021-1115MedOct 27, 2021
    risk 0.42cvss 6.5epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs, where an attacker with local unprivileged system access may cause a NULL pointer dereference, which may lead to denial of service in a component…

  • CVE-2021-3322MedOct 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Unexpected Pointer Aliasing in IEEE 802154 Fragment Reassembly in Zephyr. Zephyr versions >= >=2.4.0 contain NULL Pointer Dereference (CWE-476). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-p86r-gc4r-4mq3

  • CVE-2021-3319MedOct 5, 2021
    risk 0.42cvss 6.5epss 0.01

    DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresses. Zephyr versions >= > v2.4.0 contain NULL Pointer Dereference (CWE-476), Attempt to Access Child of a Non-structure Pointer (CWE-588). For more information, see https://github.com/zephyrproject-rtos/zephyr…

  • CVE-2021-39535MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libxsmm through v1.16.1-93. A NULL pointer dereference exists in JIT code. It allows an attacker to cause Denial of Service.

  • CVE-2021-39532MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libslax through v0.22.1. A NULL pointer dereference exists in the function slaxLexer() located in slaxlexer.c. It allows an attacker to cause Denial of Service.

  • CVE-2021-39523MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function check_POLYLINE_handles() located in decode.c. It allows an attacker to cause Denial of Service.

  • CVE-2021-39521MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in bits.c. It allows an attacker to cause Denial of Service.

  • CVE-2021-39520MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PushReconstructedData() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service.

  • CVE-2021-39519MedSep 20, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PullQData() located in blockbitmaprequester.cpp It allows an attacker to cause Denial of Service.