VYPR

CWE-822

Untrusted Pointer Dereference

BaseIncomplete

Description

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-129

CVEs mapped to this weakness (222)

page 3 of 12
  • CVE-2024-40872HigJul 25, 2024
    risk 0.55cvss 8.4epss 0.00

    There is an elevation of privilege vulnerability in server and client components of Absolute Secure Access prior to version 13.07. Attackers with local access and valid desktop user credentials can elevate their privilege to system level by passing invalid address data to the…

  • CVE-2023-43532HigFeb 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while reading ACPI config through the user mode app.

  • CVE-2026-21250HigFeb 10, 2026
    risk 0.54cvss 7.8epss 0.01

    Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

  • CVE-2023-42772HigSep 16, 2024
    risk 0.53cvss 8.2epss 0.00

    Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-26942HigOct 19, 2023
    risk 0.53cvss 8.2epss 0.00

    The Motorola MTM5000 series firmwares lack pointer validation on arguments passed to trusted execution environment (TEE) modules. Two modules are used, one responsible for KVL key management and the other for TETRA cryptographic functionality. In both modules, an adversary with…

  • CVE-2024-37969HigJul 9, 2024
    risk 0.52cvss 8.0epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2026-68810HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-64910HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-62737HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-45198HigAug 7, 2026
    risk 0.51cvss 7.8epss 0.00

    Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory. The GPU thread of control (Firmware) uses a pointer from non-secure memory belonging to the Rich…

  • CVE-2026-7406HigAug 6, 2026
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2026-24083HigAug 4, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption while processing IOCTL device driver requests with invalid arguments.

  • CVE-2026-45645HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-45643HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-45471HigJun 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2026-40369HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.05

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-47408HigMay 4, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when another driver calls an IOCTL with invalid input/output buffer.

  • CVE-2025-47405HigMay 4, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

  • CVE-2026-32222HigApr 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

  • CVE-2026-32077HigApr 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.