Skip to main content

CWE archive

CWE-476 CVEs

Programmatic archive

5,472 CVEs tagged with CWE-476132 Critical, 1,524 High, 3,602 Medium, 212 Low, 2 Unrated.

CVE-2017-11189

Published Jul 12, 2017

unrarlib.c in unrar-free 0.0.1 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash), which could be relevant if unrarlib is u…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11125

Published Jul 10, 2017

libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_get_path function in util.c.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11124

Published Jul 10, 2017

libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_unserialize function in archive.c.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11113

Published Jul 8, 2017

In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo libr…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2017-11101

Published Jul 7, 2017

When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_Relocate() function in lib/modules/swftools.c.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11100

Published Jul 7, 2017

When SWFTools 0.9.2 processes a crafted file in swfextract, it can lead to a NULL Pointer Dereference in the swf_FoldSprite() function in lib/rxfswf.c.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11097

Published Jul 7, 2017

When SWFTools 0.9.2 processes a crafted file in swfc, it can lead to a NULL Pointer Dereference in the dict_lookup() function in lib/q.c.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11096

Published Jul 7, 2017

When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_DeleteFilter() function in lib/modules/swffilter.c.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-10965

Published Jul 7, 2017

An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-0686

Published Jul 6, 2017

A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34231231.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-10917

Published Jul 5, 2017

Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-10792

Published Jul 2, 2017

There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when at…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-10790

Published Jul 2, 2017

The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value wi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9989

Published Jun 28, 2017

util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9988

Published Jun 28, 2017

The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7522

Published Jun 27, 2017

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-7458

Published Jun 26, 2017

The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-9100

Published Jun 25, 2017

The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) vi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3169

Published Jun 20, 2017

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP reque…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-9503

Published Jun 16, 2017

QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL point…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7507

Published Jun 16, 2017

GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6899

Published Jun 16, 2017

The msm_bus_dbg_update_request_write function in drivers/platform/msm/msm_bus/msm_bus_dbg.c in android_kernel_huawei_msm8916 through 2017-06-16 in LineageOS, and possibly other ke…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,076-5,100 of 5,472 CVEsPage 204 of 219