VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,508)

page 9 of 276
  • CVE-2017-17224HigNov 12, 2019
    risk 0.57cvss 8.8epss 0.00

    Some Huawei smart phones with versions earlier than Harry-AL00C 9.1.0.206(C00E205R3P1) have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the…

  • CVE-2019-17539CriOct 14, 2019
    risk 0.57cvss 9.8epss 0.02

    In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no valid close function pointer.

  • CVE-2019-9656HigMar 11, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump.

  • CVE-2019-9113HigFeb 25, 2019
    risk 0.57cvss 8.8epss 0.01

    Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a.

  • CVE-2019-8382HigFeb 17, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in the function AP4_List:Find located in Core/Ap4List.h when called from Core/Ap4Movie.cpp. It can be triggered by sending a crafted file to the mp4dump binary. It allows an attacker to cause a Denial…

  • CVE-2019-8380HigFeb 17, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in AP4_Track::GetSampleIndexForTimeStampMs() located in Core/Ap4Track.cpp. It can triggered by sending a crafted file to the mp4audioclip binary. It allows an attacker to cause a Denial of Service…

  • CVE-2018-20751HigFeb 4, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the function GetObject() being called for the pPage NULL pointer object. The value of pPage at this…

  • CVE-2019-7233HigJan 30, 2019
    risk 0.57cvss 8.8epss 0.01

    In libdoc through 2019-01-28, doc2text in catdoc.c has a NULL pointer dereference.

  • CVE-2018-20429HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.01

    libming 0.4.8 has a NULL pointer dereference in the getName function of the decompile.c file, a different vulnerability than CVE-2018-7872 and CVE-2018-9165.

  • CVE-2018-20428HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.01

    libming 0.4.8 has a NULL pointer dereference in the strlenext function of the decompile.c file, a different vulnerability than CVE-2018-7874.

  • CVE-2018-20427HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.01

    libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file, a different vulnerability than CVE-2018-9132.

  • CVE-2018-20426HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.01

    libming 0.4.8 has a NULL pointer dereference in the newVar3 function of the decompile.c file, a different vulnerability than CVE-2018-7866.

  • CVE-2018-20425HigDec 24, 2018
    risk 0.57cvss 8.8epss 0.01

    libming 0.4.8 has a NULL pointer dereference in the pushdup function of the decompile.c file.

  • CVE-2018-19532HigNov 26, 2018
    risk 0.57cvss 8.8epss 0.02

    A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by podofoimpose. It allows an attacker to cause Denial of Service.

  • CVE-2018-18883HigNov 1, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, allowing x86 HVM and PVH guests to cause a host OS denial of service (NULL pointer dereference) or possibly have unspecified other impact because nested VT-x is not properly restricted.

  • CVE-2018-16428CriSep 4, 2018
    risk 0.57cvss 9.8epss 0.05

    In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.

  • CVE-2018-11696HigJun 4, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Inspect::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.

  • CVE-2018-11694HigJun 4, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Functions::selector_append which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.

  • CVE-2018-6250HigApr 2, 2018
    risk 0.57cvss 8.8epss 0.00

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a NULL pointer dereference occurs which may lead to denial of service or possible escalation of privileges.

  • CVE-2018-6249HigApr 2, 2018
    risk 0.57cvss 8.8epss 0.00

    NVIDIA GPU Display Driver contains a vulnerability in kernel mode layer handler where a NULL pointer dereference may lead to denial of service or potential escalation of privileges.