CWE-822
Untrusted Pointer Dereference
Description
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-129
CVEs mapped to this weakness (222)
page 6 of 12| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-53034 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag reset. | ||
| CVE-2024-53033 | Hig | 0.51 | 7.8 | 0.00 | Mar 3, 2025 | Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address. | ||
| CVE-2025-21381 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2025-21358 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Windows Core Messaging Elevation of Privileges Vulnerability | ||
| CVE-2024-45584 | Hig | 0.51 | 7.8 | 0.00 | Feb 3, 2025 | Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace. | ||
| CVE-2025-21363 | Hig | 0.51 | 7.8 | 0.01 | Jan 14, 2025 | Microsoft Word Remote Code Execution Vulnerability | ||
| CVE-2024-49090 | Hig | 0.51 | 7.8 | 0.01 | Dec 12, 2024 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-43636 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2024-43629 | Hig | 0.51 | 7.8 | 0.04 | Nov 12, 2024 | Windows DWM Core Library Elevation of Privilege Vulnerability | ||
| CVE-2024-43516 | Hig | 0.51 | 7.8 | 0.01 | Oct 8, 2024 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability | ||
| CVE-2024-21455 | Hig | 0.51 | 7.8 | 0.00 | Oct 7, 2024 | Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver. | ||
| CVE-2024-33038 | Hig | 0.51 | 7.8 | 0.00 | Sep 2, 2024 | Memory corruption while passing untrusted/corrupted pointers from DSP to EVA. | ||
| CVE-2024-38187 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-38185 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-0091 | Hig | 0.51 | 7.8 | 0.00 | Jun 13, 2024 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering. | ||
| CVE-2023-40472 | Hig | 0.51 | 7.8 | 0.00 | May 3, 2024 | PDF-XChange Editor JavaScript String Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this… | ||
| CVE-2023-40471 | Hig | 0.51 | 7.8 | 0.00 | May 3, 2024 | PDF-XChange Editor App Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the… | ||
| CVE-2023-39501 | Hig | 0.51 | 7.8 | 0.00 | May 3, 2024 | PDF-XChange Editor OXPS File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this… | ||
| CVE-2023-35711 | Hig | 0.51 | 7.8 | 0.00 | May 3, 2024 | Ashlar-Vellum Cobalt XE File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this… | ||
| CVE-2023-34311 | Hig | 0.51 | 7.8 | 0.00 | May 3, 2024 | Ashlar-Vellum Cobalt Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the… |
- risk 0.51cvss 7.8epss 0.00
Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag reset.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address.
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Core Messaging Elevation of Privileges Vulnerability
- risk 0.51cvss 7.8epss 0.00
Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
- risk 0.51cvss 7.8epss 0.01
Microsoft Word Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.04
Windows DWM Core Library Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
- risk 0.51cvss 7.8epss 0.01
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering.
- risk 0.51cvss 7.8epss 0.00
PDF-XChange Editor JavaScript String Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this…
- risk 0.51cvss 7.8epss 0.00
PDF-XChange Editor App Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the…
- risk 0.51cvss 7.8epss 0.00
PDF-XChange Editor OXPS File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this…
- risk 0.51cvss 7.8epss 0.00
Ashlar-Vellum Cobalt XE File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this…
- risk 0.51cvss 7.8epss 0.00
Ashlar-Vellum Cobalt Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the…