CWE-476
NULL Pointer Dereference
Description
The product dereferences a pointer that it expects to be valid but is NULL.
Hierarchy (View 1000)
CVEs mapped to this weakness (5,659)
page 92 of 283| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-19272 | Hig | 0.42 | 7.5 | 0.01 | Nov 26, 2019 | An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a crash when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup. | ||
| CVE-2011-1802 | Med | 0.42 | 6.5 | 0.01 | Nov 12, 2019 | WebKit in Google Chrome before Blink M11 and M12 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption). | ||
| CVE-2019-18799 | Med | 0.42 | 6.5 | 0.01 | Nov 6, 2019 | LibSass before 3.6.3 allows a NULL pointer dereference in Sass::Parser::parseCompoundSelector in parser_selectors.cpp. | ||
| CVE-2019-18680 | Hig | 0.42 | 7.5 | 0.04 | Nov 4, 2019 | An issue was discovered in the Linux kernel 4.4.x before 4.4.195. There is a NULL pointer dereference in rds_tcp_kill_sock() in net/rds/tcp.c that will cause denial of service, aka CID-91573ae4aed0. | ||
| CVE-2019-18635 | Hig | 0.42 | 7.5 | 0.02 | Oct 30, 2019 | An issue was discovered in Mooltipass Moolticute through v0.42.1 and v0.42.x-testing through v0.42.5-testing. There is a NULL pointer dereference in MPDevice_win.cpp. | ||
| CVE-2019-15258 | Med | 0.42 | 6.5 | 0.01 | Oct 16, 2019 | A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper validation of… | ||
| CVE-2019-17454 | Med | 0.42 | 6.5 | 0.01 | Oct 10, 2019 | Bento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to AP4_StsdAtom::GetSampleDescription in Core/Ap4StsdAtom.cpp, as demonstrated by mp4info. | ||
| CVE-2019-17453 | Med | 0.42 | 6.5 | 0.01 | Oct 10, 2019 | Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::WriteFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4encrypt or mp4compact. | ||
| CVE-2019-17452 | Med | 0.42 | 6.5 | 0.01 | Oct 10, 2019 | Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::InspectFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4dump. | ||
| CVE-2019-9372 | Med | 0.42 | 6.5 | 0.01 | Sep 27, 2019 | In libskia, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132782448 | ||
| CVE-2019-13542 | Med | 0.42 | 6.5 | 0.01 | Sep 17, 2019 | 3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer dereference, which may trigger a denial-of-service condition. | ||
| CVE-2019-16351 | Med | 0.42 | 6.5 | 0.01 | Sep 16, 2019 | ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c. | ||
| CVE-2019-16350 | Med | 0.42 | 6.5 | 0.01 | Sep 16, 2019 | ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c. | ||
| CVE-2019-16348 | Med | 0.42 | 6.5 | 0.01 | Sep 16, 2019 | marc-q libwav through 2017-04-20 has a NULL pointer dereference in gain_file() at wav_gain.c. | ||
| CVE-2018-21015 | Med | 0.42 | 6.5 | 0.01 | Sep 16, 2019 | AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL. | ||
| CVE-2019-16164 | Med | 0.42 | 6.5 | 0.01 | Sep 9, 2019 | MyHTML through 4.0.5 has a NULL pointer dereference in myhtml_tree_node_remove in tree.c. | ||
| CVE-2019-16161 | Hig | 0.42 | 7.5 | 0.02 | Sep 9, 2019 | Onigmo through 6.2.0 has a NULL pointer dereference in onig_error_code_to_str because of fetch_token in regparse.c. | ||
| CVE-2019-15757 | Med | 0.42 | 6.5 | 0.02 | Aug 29, 2019 | libMirage 3.2.2 in CDemu has a NULL pointer dereference in the NRG parser in parser.c. | ||
| CVE-2019-13959 | Med | 0.42 | 6.5 | 0.01 | Jul 18, 2019 | In Bento4 1.5.1-627, AP4_DataBuffer::SetDataSize does not handle reallocation failures, leading to a memory copy into a NULL pointer. This is different from CVE-2018-20186. | ||
| CVE-2019-13147 | Med | 0.42 | 6.5 | 0.02 | Jul 2, 2019 | In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file. |
- risk 0.42cvss 7.5epss 0.01
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a crash when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.
- risk 0.42cvss 6.5epss 0.01
WebKit in Google Chrome before Blink M11 and M12 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption).
- risk 0.42cvss 6.5epss 0.01
LibSass before 3.6.3 allows a NULL pointer dereference in Sass::Parser::parseCompoundSelector in parser_selectors.cpp.
- risk 0.42cvss 7.5epss 0.04
An issue was discovered in the Linux kernel 4.4.x before 4.4.195. There is a NULL pointer dereference in rds_tcp_kill_sock() in net/rds/tcp.c that will cause denial of service, aka CID-91573ae4aed0.
- risk 0.42cvss 7.5epss 0.02
An issue was discovered in Mooltipass Moolticute through v0.42.1 and v0.42.x-testing through v0.42.5-testing. There is a NULL pointer dereference in MPDevice_win.cpp.
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper validation of…
- risk 0.42cvss 6.5epss 0.01
Bento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to AP4_StsdAtom::GetSampleDescription in Core/Ap4StsdAtom.cpp, as demonstrated by mp4info.
- risk 0.42cvss 6.5epss 0.01
Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::WriteFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4encrypt or mp4compact.
- risk 0.42cvss 6.5epss 0.01
Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::InspectFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4dump.
- risk 0.42cvss 6.5epss 0.01
In libskia, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-132782448
- risk 0.42cvss 6.5epss 0.01
3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer dereference, which may trigger a denial-of-service condition.
- risk 0.42cvss 6.5epss 0.01
ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c.
- risk 0.42cvss 6.5epss 0.01
ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c.
- risk 0.42cvss 6.5epss 0.01
marc-q libwav through 2017-04-20 has a NULL pointer dereference in gain_file() at wav_gain.c.
- risk 0.42cvss 6.5epss 0.01
AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.
- risk 0.42cvss 6.5epss 0.01
MyHTML through 4.0.5 has a NULL pointer dereference in myhtml_tree_node_remove in tree.c.
- risk 0.42cvss 7.5epss 0.02
Onigmo through 6.2.0 has a NULL pointer dereference in onig_error_code_to_str because of fetch_token in regparse.c.
- risk 0.42cvss 6.5epss 0.02
libMirage 3.2.2 in CDemu has a NULL pointer dereference in the NRG parser in parser.c.
- risk 0.42cvss 6.5epss 0.01
In Bento4 1.5.1-627, AP4_DataBuffer::SetDataSize does not handle reallocation failures, leading to a memory copy into a NULL pointer. This is different from CVE-2018-20186.
- risk 0.42cvss 6.5epss 0.02
In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.