VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,659)

page 93 of 283
  • CVE-2019-12435MedJun 19, 2019
    risk 0.42cvss 6.5epss 0.02

    Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is related to the AD DC DNS management server (dnsserver) RPC server process.

  • CVE-2018-19802HigJun 7, 2019
    risk 0.42cvss 7.5epss 0.02

    aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference.

  • CVE-2019-12218MedMay 20, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a NULL pointer dereference in the SDL2_image function IMG_LoadPCX_RW at IMG_pcx.c.

  • CVE-2019-12217MedMay 20, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a NULL pointer dereference in the SDL stdio_read function in file/SDL_rwops.c.

  • CVE-2019-11638MedMay 1, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec.a, leading to a crash.

  • CVE-2019-11637MedMay 1, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leading to a crash.

  • CVE-2019-10873MedApr 5, 2019
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.

  • CVE-2018-17419HigMar 7, 2019
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in setTA in scan_rr.go in the Miek Gieben DNS library before 1.0.10 for Go. A dns.ParseZone() parsing error causes a segmentation violation, leading to denial of service.

  • CVE-2019-6460MedJan 16, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_field_set_name() in the file rec-field.c in librec.a.

  • CVE-2019-6456MedJan 16, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_fex_size() in the file rec-fex.c of librec.a.

  • CVE-2018-20537MedDec 28, 2018
    risk 0.42cvss 6.5epss 0.01

    There is a NULL pointer dereference at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of service.

  • CVE-2018-20431MedDec 24, 2018
    risk 0.42cvss 6.5epss 0.02

    GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.

  • CVE-2018-20364MedDec 22, 2018
    risk 0.42cvss 6.5epss 0.03

    LibRaw::copy_bayer in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.

  • CVE-2018-20363MedDec 22, 2018
    risk 0.42cvss 6.5epss 0.03

    LibRaw::raw2image in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.

  • CVE-2018-20349MedDec 22, 2018
    risk 0.42cvss 6.5epss 0.02

    The igraph_i_strdiff function in igraph_trie.c in igraph through 0.7.1 has an NULL pointer dereference that allows attackers to cause a denial of service (application crash) via a crafted object.

  • CVE-2018-20024HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.03

    LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS.

  • CVE-2018-20190MedDec 17, 2018
    risk 0.42cvss 6.5epss 0.03

    In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Eval::operator()(Sass::Supports_Operator*) in eval.cpp may cause a Denial of Service (application crash) via a crafted sass input file.

  • CVE-2018-6116MedDec 4, 2018
    risk 0.42cvss 6.5epss 0.02

    A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2018-19797MedDec 3, 2018
    risk 0.42cvss 6.5epss 0.02

    In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (used by ast.cpp and ast_selectors.cpp) may cause a Denial of Service (application crash) via a crafted sass input file.

  • CVE-2018-19757MedNov 30, 2018
    risk 0.42cvss 6.5epss 0.01

    There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that will cause a denial of service.