VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 90 of 277
  • CVE-2019-18635HigOct 30, 2019
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in Mooltipass Moolticute through v0.42.1 and v0.42.x-testing through v0.42.5-testing. There is a NULL pointer dereference in MPDevice_win.cpp.

  • CVE-2019-15258MedOct 16, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper validation of…

  • CVE-2019-17454MedOct 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Bento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to AP4_StsdAtom::GetSampleDescription in Core/Ap4StsdAtom.cpp, as demonstrated by mp4info.

  • CVE-2019-17453MedOct 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::WriteFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4encrypt or mp4compact.

  • CVE-2019-17452MedOct 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::InspectFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4dump.

  • CVE-2019-9372MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libskia, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132782448

  • CVE-2019-13542MedSep 17, 2019
    risk 0.42cvss 6.5epss 0.01

    3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer dereference, which may trigger a denial-of-service condition.

  • CVE-2019-16351MedSep 16, 2019
    risk 0.42cvss 6.5epss 0.01

    ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c.

  • CVE-2019-16350MedSep 16, 2019
    risk 0.42cvss 6.5epss 0.01

    ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c.

  • CVE-2019-16348MedSep 16, 2019
    risk 0.42cvss 6.5epss 0.01

    marc-q libwav through 2017-04-20 has a NULL pointer dereference in gain_file() at wav_gain.c.

  • CVE-2018-21015MedSep 16, 2019
    risk 0.42cvss 6.5epss 0.01

    AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.

  • CVE-2019-16164MedSep 9, 2019
    risk 0.42cvss 6.5epss 0.01

    MyHTML through 4.0.5 has a NULL pointer dereference in myhtml_tree_node_remove in tree.c.

  • CVE-2019-16161HigSep 9, 2019
    risk 0.42cvss 7.5epss 0.02

    Onigmo through 6.2.0 has a NULL pointer dereference in onig_error_code_to_str because of fetch_token in regparse.c.

  • CVE-2019-15757MedAug 29, 2019
    risk 0.42cvss 6.5epss 0.02

    libMirage 3.2.2 in CDemu has a NULL pointer dereference in the NRG parser in parser.c.

  • CVE-2019-13959MedJul 18, 2019
    risk 0.42cvss 6.5epss 0.01

    In Bento4 1.5.1-627, AP4_DataBuffer::SetDataSize does not handle reallocation failures, leading to a memory copy into a NULL pointer. This is different from CVE-2018-20186.

  • CVE-2019-13147MedJul 2, 2019
    risk 0.42cvss 6.5epss 0.02

    In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.

  • CVE-2019-12435MedJun 19, 2019
    risk 0.42cvss 6.5epss 0.02

    Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is related to the AD DC DNS management server (dnsserver) RPC server process.

  • CVE-2018-19802HigJun 7, 2019
    risk 0.42cvss 7.5epss 0.02

    aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference.

  • CVE-2019-12218MedMay 20, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a NULL pointer dereference in the SDL2_image function IMG_LoadPCX_RW at IMG_pcx.c.

  • CVE-2019-12217MedMay 20, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a NULL pointer dereference in the SDL stdio_read function in file/SDL_rwops.c.