CWE-822
Untrusted Pointer Dereference
Description
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-129
CVEs mapped to this weakness (222)
page 10 of 12| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-60708 | Med | 0.42 | 6.5 | 0.00 | Nov 11, 2025 | Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally. | ||
| CVE-2025-32446 | Med | 0.42 | 6.5 | 0.00 | Nov 11, 2025 | Untrusted pointer dereference for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data… | ||
| CVE-2025-27710 | Med | 0.42 | 6.5 | 0.00 | Nov 11, 2025 | Untrusted pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable data exposure.… | ||
| CVE-2024-20680 | Med | 0.42 | 6.5 | 0.02 | Jan 9, 2024 | Windows Message Queuing Client (MSMQC) Information Disclosure | ||
| CVE-2024-20664 | Med | 0.42 | 6.5 | 0.02 | Jan 9, 2024 | Microsoft Message Queuing Information Disclosure Vulnerability | ||
| CVE-2024-20663 | Med | 0.42 | 6.5 | 0.02 | Jan 9, 2024 | Windows Message Queuing Client (MSMQC) Information Disclosure | ||
| CVE-2022-20796 | Med | 0.42 | 6.5 | 0.00 | May 4, 2022 | On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2 could allow an authenticated, local attacker… | ||
| CVE-2026-20935 | Med | 0.40 | 6.2 | 0.00 | Jan 13, 2026 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-52516 | Med | 0.40 | 6.2 | 0.00 | Jan 5, 2026 | An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. An invalid kernel address dereference in the issimian device driver leads to a denial of service. | ||
| CVE-2025-22464 | Med | 0.40 | 6.1 | 0.00 | Apr 8, 2025 | An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition. | ||
| CVE-2023-32277 | Med | 0.40 | 6.1 | 0.00 | Feb 12, 2025 | Untrusted Pointer Dereference in I/O subsystem for some Intel(R) QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access. | ||
| CVE-2022-40533 | Med | 0.40 | 6.2 | 0.00 | Jun 6, 2023 | Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request. | ||
| CVE-2026-23670 | Med | 0.37 | 5.7 | 0.00 | Apr 14, 2026 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-62798 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-61360 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. | ||
| CVE-2026-44805 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally. | ||
| CVE-2025-59959 | Med | 0.36 | 5.5 | 0.00 | Jan 15, 2026 | An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). When the command 'show route < ( receive-protocol… | ||
| CVE-2026-20819 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. | ||
| CVE-2025-20090 | Med | 0.36 | 5.5 | 0.00 | Aug 12, 2025 | Untrusted Pointer Dereference for some Intel(R) QuickAssist Technology software before version 2.5.0 may allow an authenticated user to potentially enable denial of service via local access. | ||
| CVE-2024-12576 | — | Med | 0.36 | 5.5 | 0.00 | Mar 7, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW running on the GPU freezing graphics output. |
- risk 0.42cvss 6.5epss 0.00
Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.
- risk 0.42cvss 6.5epss 0.00
Untrusted pointer dereference for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data…
- risk 0.42cvss 6.5epss 0.00
Untrusted pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable data exposure.…
- risk 0.42cvss 6.5epss 0.02
Windows Message Queuing Client (MSMQC) Information Disclosure
- risk 0.42cvss 6.5epss 0.02
Microsoft Message Queuing Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Message Queuing Client (MSMQC) Information Disclosure
- risk 0.42cvss 6.5epss 0.00
On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2 could allow an authenticated, local attacker…
- risk 0.40cvss 6.2epss 0.00
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.
- risk 0.40cvss 6.2epss 0.00
An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. An invalid kernel address dereference in the issimian device driver leads to a denial of service.
- risk 0.40cvss 6.1epss 0.00
An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition.
- risk 0.40cvss 6.1epss 0.00
Untrusted Pointer Dereference in I/O subsystem for some Intel(R) QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access.
- risk 0.40cvss 6.2epss 0.00
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.
- risk 0.37cvss 5.7epss 0.00
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
- risk 0.36cvss 5.5epss 0.00
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.00
An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). When the command 'show route < ( receive-protocol…
- risk 0.36cvss 5.5epss 0.01
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Untrusted Pointer Dereference for some Intel(R) QuickAssist Technology software before version 2.5.0 may allow an authenticated user to potentially enable denial of service via local access.
- risk 0.36cvss 5.5epss 0.00
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW running on the GPU freezing graphics output.