CWE-822
Untrusted Pointer Dereference
Description
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-129
CVEs mapped to this weakness (222)
page 2 of 12| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27060 | Hig | 0.57 | 8.8 | 0.00 | Oct 9, 2025 | Memory corruption while performing SCM call with malformed inputs. | ||
| CVE-2024-43624 | Hig | 0.57 | 8.8 | 0.02 | Nov 12, 2024 | Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability | ||
| CVE-2024-37340 | Hig | 0.57 | 8.8 | 0.02 | Sep 10, 2024 | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | ||
| CVE-2024-37339 | Hig | 0.57 | 8.8 | 0.02 | Sep 10, 2024 | Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | ||
| CVE-2024-38104 | Hig | 0.57 | 8.8 | 0.02 | Jul 9, 2024 | Windows Fax Service Remote Code Execution Vulnerability | ||
| CVE-2023-0184 | Hig | 0.57 | 8.8 | 0.00 | Apr 22, 2023 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler which may lead to denial of service, escalation of privileges, information disclosure, and data tampering. | ||
| CVE-2023-0189 | Hig | 0.57 | 8.8 | 0.00 | Apr 1, 2023 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | ||
| CVE-2022-34890 | Hig | 0.57 | 8.8 | 0.00 | Jul 18, 2022 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability.… | ||
| CVE-2020-27259 | Hig | 0.57 | 8.8 | 0.03 | Feb 9, 2021 | The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code. | ||
| CVE-2020-17392 | Hig | 0.57 | 8.8 | 0.01 | Aug 25, 2020 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw… | ||
| CVE-2026-8917 | Hig | 0.55 | — | 0.00 | Aug 11, 2026 | Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation. Refer to the ' Security Update for ASUS… | ||
| CVE-2026-40367 | Hig | 0.55 | 8.4 | 0.00 | May 12, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-20738 | Hig | 0.55 | — | 0.00 | May 12, 2026 | Untrusted pointer dereference for some Intel(R) QuickAssist Adapter 8960 software before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may… | ||
| CVE-2026-33114 | Hig | 0.55 | 8.4 | 0.00 | Apr 14, 2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-26113 | Hig | 0.55 | 8.4 | 0.01 | Mar 10, 2026 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2024-36352 | Hig | 0.55 | 8.4 | 0.00 | Sep 6, 2025 | Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary writes or denial of service. | ||
| CVE-2025-20018 | Hig | 0.55 | 8.4 | 0.00 | May 13, 2025 | Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access. | ||
| CVE-2025-24084 | Hig | 0.55 | 8.4 | 0.01 | Mar 11, 2025 | Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-21354 | Hig | 0.55 | 8.4 | 0.01 | Jan 14, 2025 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2024-34023 | Hig | 0.55 | 8.4 | 0.00 | Nov 13, 2024 | Untrusted pointer dereference in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access. |
- risk 0.57cvss 8.8epss 0.00
Memory corruption while performing SCM call with malformed inputs.
- risk 0.57cvss 8.8epss 0.02
Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Fax Service Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.00
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler which may lead to denial of service, escalation of privileges, information disclosure, and data tampering.
- risk 0.57cvss 8.8epss 0.00
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
- risk 0.57cvss 8.8epss 0.00
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability.…
- risk 0.57cvss 8.8epss 0.03
The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.
- risk 0.57cvss 8.8epss 0.01
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw…
- risk 0.55cvss —epss 0.00
Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation. Refer to the ' Security Update for ASUS…
- risk 0.55cvss 8.4epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.55cvss —epss 0.00
Untrusted pointer dereference for some Intel(R) QuickAssist Adapter 8960 software before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may…
- risk 0.55cvss 8.4epss 0.00
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.4epss 0.01
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.4epss 0.00
Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary writes or denial of service.
- risk 0.55cvss 8.4epss 0.00
Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.
- risk 0.55cvss 8.4epss 0.01
Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.4epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.55cvss 8.4epss 0.00
Untrusted pointer dereference in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.