VYPR

CWE-822

Untrusted Pointer Dereference

BaseIncomplete

Description

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-129

CVEs mapped to this weakness (222)

page 1 of 12
  • CVE-2024-21338HigKEVFeb 13, 2024
    risk 0.76cvss 7.8epss 0.60

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-35250HigKEVJun 11, 2024
    risk 0.68cvss 7.8epss 0.25

    Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

  • CVE-2023-29360HigKEVJun 14, 2023
    risk 0.68cvss 8.4epss 0.22

    Microsoft Streaming Service Elevation of Privilege Vulnerability

  • CVE-2025-50165CriAug 12, 2025
    risk 0.64cvss 9.8epss 0.10

    Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

  • CVE-2023-36033HigKEVNov 14, 2023
    risk 0.64cvss 7.8epss 0.12

    Windows DWM Core Library Elevation of Privilege Vulnerability

  • CVE-2023-1437CriAug 2, 2023
    risk 0.64cvss 9.8epss 0.03

    All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the…

  • CVE-2018-12548CriJan 31, 2019
    risk 0.64cvss 9.8epss 0.01

    In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept pointer values that are dereferenced in the native code.

  • CVE-2018-17893CriOct 17, 2018
    risk 0.64cvss 9.8epss 0.06

    LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.

  • CVE-2018-14811CriSep 26, 2018
    risk 0.64cvss 9.8epss 0.04

    Fuji Electric V-Server 4.0.3.0 and prior, Multiple untrusted pointer dereference vulnerabilities have been identified, which may allow remote code execution.

  • CVE-2018-7497CriMay 15, 2018
    risk 0.64cvss 9.8epss 0.03

    In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several untrusted pointer dereference vulnerabilities…

  • CVE-2025-24990HigKEVOct 14, 2025
    risk 0.63cvss 7.8epss 0.06

    Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax…

  • CVE-2026-48137CriJun 19, 2026
    risk 0.59cvss 9.1epss 0.01

    There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution.  Successful exploitation requires an attacker  to supply a…

  • CVE-2025-4993CriSep 23, 2025
    risk 0.59cvss 9.1epss 0.00

    Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.10, from 6.1.0 before 6.1.2.27, from 6.0.0 before 6.0.1.43, from 5.3.0…

  • CVE-2025-1255CriSep 23, 2025
    risk 0.59cvss 9.1epss 0.00

    Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.2.0 before 7.3.0.9.

  • CVE-2024-36461CriAug 12, 2024
    risk 0.59cvss 9.1epss 0.01

    Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.

  • CVE-2023-21643CriAug 8, 2023
    risk 0.59cvss 9.1epss 0.00

    Memory corruption due to untrusted pointer dereference in automotive during system call.

  • CVE-2023-21768HigJan 10, 2023
    risk 0.59cvss 7.8epss 0.65

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

  • CVE-2020-26991HigJan 12, 2021
    risk 0.58cvss 8.8epss 0.04

    A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2). Affected applications lack proper validation of user-supplied data when parsing ASM files. This could lead to pointer dereferences of a value obtained…

  • CVE-2026-33120HigApr 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

  • CVE-2025-62549HigDec 9, 2025
    risk 0.57cvss 8.8epss 0.01

    Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.