VYPR

CWE-822

Untrusted Pointer Dereference

BaseIncomplete

Description

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-129

CVEs mapped to this weakness (222)

page 2 of 12
  • CVE-2025-27060HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.00

    Memory corruption while performing SCM call with malformed inputs.

  • CVE-2024-43624HigNov 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability

  • CVE-2024-37340HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

  • CVE-2024-37339HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

  • CVE-2024-38104HigJul 9, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Fax Service Remote Code Execution Vulnerability

  • CVE-2023-0184HigApr 22, 2023
    risk 0.57cvss 8.8epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler which may lead to denial of service, escalation of privileges, information disclosure, and data tampering.

  • CVE-2023-0189HigApr 1, 2023
    risk 0.57cvss 8.8epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

  • CVE-2022-34890HigJul 18, 2022
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability.…

  • CVE-2020-27259HigFeb 9, 2021
    risk 0.57cvss 8.8epss 0.03

    The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2020-17392HigAug 25, 2020
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw…

  • CVE-2026-8917HigAug 11, 2026
    risk 0.55cvss epss 0.00

    Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation. Refer to the '  Security Update for ASUS…

  • CVE-2026-40367HigMay 12, 2026
    risk 0.55cvss 8.4epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-20738HigMay 12, 2026
    risk 0.55cvss epss 0.00

    Untrusted pointer dereference for some Intel(R) QuickAssist Adapter 8960 software before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may…

  • CVE-2026-33114HigApr 14, 2026
    risk 0.55cvss 8.4epss 0.00

    Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-26113HigMar 10, 2026
    risk 0.55cvss 8.4epss 0.01

    Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2024-36352HigSep 6, 2025
    risk 0.55cvss 8.4epss 0.00

    Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary writes or denial of service.

  • CVE-2025-20018HigMay 13, 2025
    risk 0.55cvss 8.4epss 0.00

    Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-24084HigMar 11, 2025
    risk 0.55cvss 8.4epss 0.01

    Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.

  • CVE-2025-21354HigJan 14, 2025
    risk 0.55cvss 8.4epss 0.01

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2024-34023HigNov 13, 2024
    risk 0.55cvss 8.4epss 0.00

    Untrusted pointer dereference in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.