CWE-822
Untrusted Pointer Dereference
Description
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-129
CVEs mapped to this weakness (246)
page 13 of 13| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-50424 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50382 | Hig | 0.00 | 8.8 | 0.00 | Jul 14, 2026 | Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. | ||
| CVE-2026-50367 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-48580 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-58596 | Hig | 0.00 | 8.3 | 0.01 | Jul 12, 2026 | Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-58749 | Med | 0.00 | 5.3 | 0.00 | Sep 16, 2025 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2, when running in LLVM-JIT mode, the runtime cannot exit normally when executing WebAssembly programs containing a memory.fill instruction where the first… |
- risk 0.00cvss 7.5epss 0.01
Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 8.8epss 0.00
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 5.5epss 0.01
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 8.3epss 0.01
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
- risk 0.00cvss 5.3epss 0.00
WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2, when running in LLVM-JIT mode, the runtime cannot exit normally when executing WebAssembly programs containing a memory.fill instruction where the first…