Skip to main content

CWE archive

CWE-476 CVEs

Programmatic archive

5,496 CVEs tagged with CWE-476132 Critical, 1,531 High, 3,618 Medium, 213 Low, 2 Unrated.

CVE-2017-14318

Published Sep 12, 2017

An issue was discovered in Xen 4.5.x through 4.9.x. The function `__gnttab_cache_flush` handles GNTTABOP_cache_flush grant table operations. It checks to see if the calling domain…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14225

Published Sep 9, 2017

The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this,…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14181

Published Sep 7, 2017

DeleteBitBuffer in libbitbuf/bitbuffer.c in mp4tools aacplusenc 0.17.5 allows remote attackers to cause a denial of service (invalid memory write, SEGV on unknown address 0x000000…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12476

Published Sep 6, 2017

The AP4_AvccAtom::InspectFields function in Core/Ap4AvccAtom.cpp in Bento4 mp4dump before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12475

Published Sep 6, 2017

The AP4_Processor::Process function in Core/Ap4Processor.cpp in Bento4 mp4encrypt before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12474

Published Sep 6, 2017

The AP4_AtomSampleTable::GetSample function in Core/Ap4AtomSampleTable.cpp in Bento4 mp42ts before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer der…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14149

Published Sep 5, 2017

GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14121

Published Sep 3, 2017

The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this ma…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-13764

Published Aug 30, 2017

In Wireshark 2.4.0, the Modbus dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/packet-mbtcp.c by adding length validation.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10505

Published Aug 30, 2017

NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb fu…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-13712

Published Aug 28, 2017

NULL Pointer Dereference in the id3v2AddAudioDuration function in libmp3lame/id3tag.c in LAME 3.99.5 allows attackers to perform Denial of Service by triggering a NULL first argum…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12952

Published Aug 28, 2017

The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12950

Published Aug 28, 2017

The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12923

Published Aug 28, 2017

OLEStream::WriteVT_LPSTR in olestrm.cpp in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted fpx image.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12922

Published Aug 28, 2017

wchar.c in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted fpx image.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12921

Published Aug 28, 2017

PFileFlashPixView::GetGlobalInfoProperty in f_fpxvw.cpp in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted fpx image.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12920

Published Aug 28, 2017

CDirectory::GetDirEntry in dir.cxx in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted fpx image.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0928

Published Aug 28, 2017

libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13710

Published Aug 27, 2017

The setup_group function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of servi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13686

Published Aug 24, 2017

net/ipv4/route.c in the Linux kernel 4.13-rc1 through 4.13-rc6 is too late to check for a NULL fi field when RTM_F_FIB_MATCH is set, which allows local users to cause a denial of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7516

Published Aug 24, 2017

ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switch disconnect) by sending two Ethernet frames with…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12809

Published Aug 23, 2017

QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privileged users to cause a denial of service (NULL pointer derefere…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 5,051-5,075 of 5,496 CVEsPage 203 of 220