VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,669)

page 98 of 284
  • CVE-2018-19797MedDec 3, 2018
    risk 0.42cvss 6.5epss 0.02

    In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (used by ast.cpp and ast_selectors.cpp) may cause a Denial of Service (application crash) via a crafted sass input file.

  • CVE-2018-19757MedNov 30, 2018
    risk 0.42cvss 6.5epss 0.01

    There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that will cause a denial of service.

  • CVE-2018-16852MedNov 28, 2018
    risk 0.42cvss 6.5epss 0.02

    Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of an DNS zone in the DNS management DCE/RPC server, the internal DNS server or the Samba DLZ plugin for BIND9, if the DSPROPERTY_ZONE_MASTER_SERVERS property or…

  • CVE-2018-19607MedNov 27, 2018
    risk 0.42cvss 6.5epss 0.03

    Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

  • CVE-2018-19542MedNov 26, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.

  • CVE-2018-19432MedNov 22, 2018
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service.

  • CVE-2018-7361MedNov 16, 2018
    risk 0.42cvss 6.5epss 0.01

    All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by null pointer dereference vulnerability, which may allows an attacker to cause a denial of service via appviahttp service.

  • CVE-2018-19217MedNov 12, 2018
    risk 0.42cvss 6.5epss 0.01

    In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a…

  • CVE-2018-19208MedNov 12, 2018
    risk 0.42cvss 6.5epss 0.01

    In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.

  • CVE-2018-19184HigNov 12, 2018
    risk 0.42cvss 7.5epss 0.01

    cmd/evm/runner.go in Go Ethereum (aka geth) 1.8.17 allows attackers to cause a denial of service (SEGV) via crafted bytecode.

  • CVE-2018-19129MedNov 9, 2018
    risk 0.42cvss 6.5epss 0.01

    In Libav 12.3, a NULL pointer dereference (RIP points to zero) issue in ff_mpa_synth_filter_float in libavcodec/mpegaudiodsp_template.c can cause a segmentation fault (application crash) via a crafted mov file.

  • CVE-2018-19060MedNov 7, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating a filename of an embedded file before constructing a save path.

  • CVE-2018-18829MedOct 30, 2018
    risk 0.42cvss 6.5epss 0.01

    There exists a NULL pointer dereference in ff_vc1_parse_frame_header_adv in vc1.c in Libav 12.3, which allows attackers to cause a denial-of-service through a crafted aac file.

  • CVE-2018-18661MedOct 26, 2018
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c.

  • CVE-2018-18192MedOct 9, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in libgig 4.1.0. There is a NULL pointer dereference in the function DLS::File::GetFirstSample() in DLS.cpp.

  • CVE-2018-18088MedOct 9, 2018
    risk 0.42cvss 6.5epss 0.02

    OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c

  • CVE-2018-17794MedSep 30, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.

  • CVE-2018-17432MedSep 24, 2018
    risk 0.42cvss 6.5epss 0.01

    A NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file.

  • CVE-2018-17282MedSep 20, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.

  • CVE-2018-17075HigSep 16, 2018
    risk 0.42cvss 7.5epss 0.03

    The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of , , or . This is related to HTMLTreeBuilder.cpp in WebKit.