VYPR

CWE-822

Untrusted Pointer Dereference

BaseIncomplete

Description

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-129

CVEs mapped to this weakness (222)

page 7 of 12
  • CVE-2023-34309HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the…

  • CVE-2023-34301HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt CO File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this…

  • CVE-2023-34300HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Ashlar-Vellum Cobalt XE File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this…

  • CVE-2023-27342HigMay 3, 2024
    risk 0.51cvss 7.8epss 0.01

    PDF-XChange Editor EMF File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability…

  • CVE-2024-23136HigFeb 22, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

  • CVE-2024-21346HigFeb 13, 2024
    risk 0.51cvss 7.8epss 0.04

    Win32k Elevation of Privilege Vulnerability

  • CVE-2023-34333HigJan 9, 2024
    risk 0.51cvss 7.8epss 0.00

    AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference via a local network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. …

  • CVE-2023-34332HigJan 9, 2024
    risk 0.51cvss 7.8epss 0.00

    AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference by a local network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. …

  • CVE-2024-20682HigJan 9, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Cryptographic Services Remote Code Execution Vulnerability

  • CVE-2023-36011HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.01

    Win32k Elevation of Privilege Vulnerability

  • CVE-2023-41139HigNov 23, 2023
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted STP file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

  • CVE-2023-36045HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Graphics Remote Code Execution Vulnerability

  • CVE-2023-25515HigJun 23, 2023
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where unexpected untrusted data is parsed, which may lead to code execution, denial of service, escalation of privileges, data tampering, or information disclosure.

  • CVE-2022-42418HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists…

  • CVE-2022-42396HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists…

  • CVE-2022-2002HigDec 7, 2022
    risk 0.51cvss 7.8epss 0.00

    GE CIMPICITY versions 2022 and prior is vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code.

  • CVE-2022-2894HigAug 31, 2022
    risk 0.51cvss 7.8epss 0.00

    Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. The controls may allow seven untrusted pointer deference instances while processing a specific project file.

  • CVE-2021-38401HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.01

    Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an untrusted pointer dereference, which may allow an attacker to execute arbitrary code and cause the application to crash.

  • CVE-2021-31504HigAug 3, 2021
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.3.84 (package 16.6.3.134). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…

  • CVE-2021-31500HigJun 15, 2021
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific…