CWE-822
Untrusted Pointer Dereference
Description
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-129
CVEs mapped to this weakness (246)
page 11 of 13| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-72956 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-72938 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-47325 | Med | 0.42 | 6.5 | 0.00 | Dec 18, 2025 | Information disclosure while processing system calls with invalid parameters. | ||
| CVE-2025-60708 | Med | 0.42 | 6.5 | 0.00 | Nov 11, 2025 | Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally. | ||
| CVE-2025-32446 | Med | 0.42 | 6.5 | 0.00 | Nov 11, 2025 | Untrusted pointer dereference for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data… | ||
| CVE-2025-27710 | Med | 0.42 | 6.5 | 0.00 | Nov 11, 2025 | Untrusted pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable data exposure.… | ||
| CVE-2024-20680 | Med | 0.42 | 6.5 | 0.02 | Jan 9, 2024 | Windows Message Queuing Client (MSMQC) Information Disclosure | ||
| CVE-2024-20664 | Med | 0.42 | 6.5 | 0.02 | Jan 9, 2024 | Microsoft Message Queuing Information Disclosure Vulnerability | ||
| CVE-2024-20663 | Med | 0.42 | 6.5 | 0.02 | Jan 9, 2024 | Windows Message Queuing Client (MSMQC) Information Disclosure | ||
| CVE-2022-20796 | Med | 0.42 | 6.5 | 0.00 | May 4, 2022 | On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2 could allow an authenticated, local attacker… | ||
| CVE-2026-20935 | Med | 0.40 | 6.2 | 0.00 | Jan 13, 2026 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-52516 | Med | 0.40 | 6.2 | 0.00 | Jan 5, 2026 | An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. An invalid kernel address dereference in the issimian device driver leads to a denial of service. | ||
| CVE-2025-22464 | Med | 0.40 | 6.1 | 0.00 | Apr 8, 2025 | An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition. | ||
| CVE-2023-32277 | Med | 0.40 | 6.1 | 0.00 | Feb 12, 2025 | Untrusted Pointer Dereference in I/O subsystem for some Intel(R) QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access. | ||
| CVE-2022-40533 | Med | 0.40 | 6.2 | 0.00 | Jun 6, 2023 | Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request. | ||
| CVE-2026-69569 | Med | 0.37 | 5.7 | 0.01 | Sep 8, 2026 | Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network. | ||
| CVE-2026-23670 | Med | 0.37 | 5.7 | 0.00 | Apr 14, 2026 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-90890 | Med | 0.36 | 5.5 | 0.00 | Sep 14, 2026 | ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating… | ||
| CVE-2026-62798 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-61360 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. |
- risk 0.42cvss 6.5epss 0.01
Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while processing system calls with invalid parameters.
- risk 0.42cvss 6.5epss 0.00
Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.
- risk 0.42cvss 6.5epss 0.00
Untrusted pointer dereference for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable data…
- risk 0.42cvss 6.5epss 0.00
Untrusted pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable data exposure.…
- risk 0.42cvss 6.5epss 0.02
Windows Message Queuing Client (MSMQC) Information Disclosure
- risk 0.42cvss 6.5epss 0.02
Microsoft Message Queuing Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Message Queuing Client (MSMQC) Information Disclosure
- risk 0.42cvss 6.5epss 0.00
On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2 could allow an authenticated, local attacker…
- risk 0.40cvss 6.2epss 0.00
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.
- risk 0.40cvss 6.2epss 0.00
An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. An invalid kernel address dereference in the issimian device driver leads to a denial of service.
- risk 0.40cvss 6.1epss 0.00
An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition.
- risk 0.40cvss 6.1epss 0.00
Untrusted Pointer Dereference in I/O subsystem for some Intel(R) QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access.
- risk 0.40cvss 6.2epss 0.00
Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.
- risk 0.37cvss 5.7epss 0.01
Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network.
- risk 0.37cvss 5.7epss 0.00
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
- risk 0.36cvss 5.5epss 0.00
ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating…
- risk 0.36cvss 5.5epss 0.00
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.