CWE-822
Untrusted Pointer Dereference
Description
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-129
CVEs mapped to this weakness (246)
page 12 of 13| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-44805 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally. | ||
| CVE-2025-59959 | Med | 0.36 | 5.5 | 0.00 | Jan 15, 2026 | An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). When the command 'show route < ( receive-protocol… | ||
| CVE-2026-20819 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. | ||
| CVE-2025-20090 | Med | 0.36 | 5.5 | 0.00 | Aug 12, 2025 | Untrusted Pointer Dereference for some Intel(R) QuickAssist Technology software before version 2.5.0 may allow an authenticated user to potentially enable denial of service via local access. | ||
| CVE-2024-12576 | — | Med | 0.36 | 5.5 | 0.00 | Mar 7, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW running on the GPU freezing graphics output. | |
| CVE-2023-31023 | Med | 0.36 | 5.5 | 0.00 | Nov 2, 2023 | NVIDIA Display Driver for Windows contains a vulnerability where an attacker may cause a pointer dereference of an untrusted value, which may lead to denial of service. | ||
| CVE-2023-32040 | Med | 0.36 | 5.5 | 0.01 | Jul 11, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | ||
| CVE-2023-23394 | Med | 0.36 | 5.5 | 0.00 | Mar 14, 2023 | Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability | ||
| CVE-2020-14392 | Med | 0.36 | 5.5 | 0.01 | Sep 16, 2020 | An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability. | ||
| CVE-2025-54331 | Med | 0.34 | 5.3 | 0.00 | Nov 4, 2025 | An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the copy_ncp_header function. | ||
| CVE-2018-7525 | Med | 0.34 | 5.3 | 0.00 | Mar 21, 2018 | In Omron CX-Supervisor Versions 3.30 and prior, processing a malformed packet by a certain executable may cause an untrusted pointer dereference vulnerability. | ||
| CVE-2026-10420 | Med | 0.29 | 5.5 | 0.00 | Sep 1, 2026 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be. | ||
| CVE-2026-82927 | Med | 0.29 | 5.5 | 0.00 | Sep 1, 2026 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e. | ||
| CVE-2025-60728 | Med | 0.28 | 4.3 | 0.01 | Nov 11, 2025 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2021-20239 | Low | 0.21 | 3.3 | 0.00 | May 28, 2021 | A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentiality. | ||
| CVE-2021-26410 | Low | 0.12 | — | 0.00 | Feb 10, 2026 | Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter values from its own memory space allowing an attacker to infer the contents of the kernel memory leading to potential information disclosure. | ||
| CVE-2026-55138 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55136 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-50479 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50441 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. |
- risk 0.36cvss 5.5epss 0.00
Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.00
An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). When the command 'show route < ( receive-protocol…
- risk 0.36cvss 5.5epss 0.01
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Untrusted Pointer Dereference for some Intel(R) QuickAssist Technology software before version 2.5.0 may allow an authenticated user to potentially enable denial of service via local access.
- risk 0.36cvss 5.5epss 0.00
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW running on the GPU freezing graphics output.
- risk 0.36cvss 5.5epss 0.00
NVIDIA Display Driver for Windows contains a vulnerability where an attacker may cause a pointer dereference of an untrusted value, which may lead to denial of service.
- risk 0.36cvss 5.5epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the copy_ncp_header function.
- risk 0.34cvss 5.3epss 0.00
In Omron CX-Supervisor Versions 3.30 and prior, processing a malformed packet by a certain executable may cause an untrusted pointer dereference vulnerability.
- risk 0.29cvss 5.5epss 0.00
Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.
- risk 0.29cvss 5.5epss 0.00
Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.
- risk 0.28cvss 4.3epss 0.01
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- risk 0.21cvss 3.3epss 0.00
A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentiality.
- risk 0.12cvss —epss 0.00
Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter values from its own memory space allowing an attacker to infer the contents of the kernel memory leading to potential information disclosure.
- risk 0.00cvss 5.5epss 0.01
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.