VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 91 of 277
  • CVE-2019-11638MedMay 1, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec.a, leading to a crash.

  • CVE-2019-11637MedMay 1, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leading to a crash.

  • CVE-2019-10873MedApr 5, 2019
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.

  • CVE-2018-17419HigMar 7, 2019
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in setTA in scan_rr.go in the Miek Gieben DNS library before 1.0.10 for Go. A dns.ParseZone() parsing error causes a segmentation violation, leading to denial of service.

  • CVE-2019-6460MedJan 16, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_field_set_name() in the file rec-field.c in librec.a.

  • CVE-2019-6456MedJan 16, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_fex_size() in the file rec-fex.c of librec.a.

  • CVE-2018-20537MedDec 28, 2018
    risk 0.42cvss 6.5epss 0.01

    There is a NULL pointer dereference at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of service.

  • CVE-2018-20431MedDec 24, 2018
    risk 0.42cvss 6.5epss 0.02

    GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.

  • CVE-2018-20364MedDec 22, 2018
    risk 0.42cvss 6.5epss 0.03

    LibRaw::copy_bayer in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.

  • CVE-2018-20363MedDec 22, 2018
    risk 0.42cvss 6.5epss 0.03

    LibRaw::raw2image in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.

  • CVE-2018-20349MedDec 22, 2018
    risk 0.42cvss 6.5epss 0.02

    The igraph_i_strdiff function in igraph_trie.c in igraph through 0.7.1 has an NULL pointer dereference that allows attackers to cause a denial of service (application crash) via a crafted object.

  • CVE-2018-20024HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.03

    LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS.

  • CVE-2018-20190MedDec 17, 2018
    risk 0.42cvss 6.5epss 0.03

    In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Eval::operator()(Sass::Supports_Operator*) in eval.cpp may cause a Denial of Service (application crash) via a crafted sass input file.

  • CVE-2018-6116MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.01

    A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2018-19797MedDec 3, 2018
    risk 0.42cvss 6.5epss 0.02

    In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (used by ast.cpp and ast_selectors.cpp) may cause a Denial of Service (application crash) via a crafted sass input file.

  • CVE-2018-19757MedNov 30, 2018
    risk 0.42cvss 6.5epss 0.01

    There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that will cause a denial of service.

  • CVE-2018-16852MedNov 28, 2018
    risk 0.42cvss 6.5epss 0.02

    Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of an DNS zone in the DNS management DCE/RPC server, the internal DNS server or the Samba DLZ plugin for BIND9, if the DSPROPERTY_ZONE_MASTER_SERVERS property or…

  • CVE-2018-19607MedNov 27, 2018
    risk 0.42cvss 6.5epss 0.03

    Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

  • CVE-2018-19542MedNov 26, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.

  • CVE-2018-19432MedNov 22, 2018
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service.