VYPR

CWE-822

Untrusted Pointer Dereference

BaseIncomplete

Description

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-129

CVEs mapped to this weakness (222)

page 6 of 12
  • CVE-2024-53034HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag reset.

  • CVE-2024-53033HigMar 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address.

  • CVE-2025-21381HigFeb 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2025-21358HigFeb 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Windows Core Messaging Elevation of Privileges Vulnerability

  • CVE-2024-45584HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.

  • CVE-2025-21363HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Microsoft Word Remote Code Execution Vulnerability

  • CVE-2024-49090HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2024-43636HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Win32k Elevation of Privilege Vulnerability

  • CVE-2024-43629HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.04

    Windows DWM Core Library Elevation of Privilege Vulnerability

  • CVE-2024-43516HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Secure Kernel Mode Elevation of Privilege Vulnerability

  • CVE-2024-21455HigOct 7, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.

  • CVE-2024-33038HigSep 2, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.

  • CVE-2024-38187HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

  • CVE-2024-38185HigAug 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

  • CVE-2024-0091HigJun 13, 2024
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering.

  • CVE-2023-40472HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    PDF-XChange Editor JavaScript String Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this…

  • CVE-2023-40471HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    PDF-XChange Editor App Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the…

  • CVE-2023-39501HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    PDF-XChange Editor OXPS File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this…

  • CVE-2023-35711HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt XE File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this…

  • CVE-2023-34311HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the…