VYPR

CWE-822

Untrusted Pointer Dereference

BaseIncomplete

Description

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-129

CVEs mapped to this weakness (222)

page 11 of 12
  • CVE-2023-31023MedNov 2, 2023
    risk 0.36cvss 5.5epss 0.00

    NVIDIA Display Driver for Windows contains a vulnerability where an attacker may cause a pointer dereference of an untrusted value, which may lead to denial of service.

  • CVE-2023-32040MedJul 11, 2023
    risk 0.36cvss 5.5epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

  • CVE-2023-23394MedMar 14, 2023
    risk 0.36cvss 5.5epss 0.00

    Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability

  • CVE-2020-14392MedSep 16, 2020
    risk 0.36cvss 5.5epss 0.01

    An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.

  • CVE-2025-54331MedNov 4, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the copy_ncp_header function.

  • CVE-2018-7525MedMar 21, 2018
    risk 0.34cvss 5.3epss 0.00

    In Omron CX-Supervisor Versions 3.30 and prior, processing a malformed packet by a certain executable may cause an untrusted pointer dereference vulnerability.

  • CVE-2025-60728MedNov 11, 2025
    risk 0.28cvss 4.3epss 0.01

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

  • CVE-2021-20239LowMay 28, 2021
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentiality.

  • CVE-2021-26410LowFeb 10, 2026
    risk 0.12cvss epss 0.00

    Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter values from its own memory space allowing an attacker to infer the contents of the kernel memory leading to potential information disclosure.

  • CVE-2026-15029HigJul 15, 2026
    risk 0.00cvss epss 0.00

    Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced…

  • CVE-2026-48340HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-55138MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-55136HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-50479HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50441HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50424HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50382HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.

  • CVE-2026-50367HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-48580MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-58596HigJul 12, 2026
    risk 0.00cvss 8.3epss 0.00

    Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.