Skip to main content

CWE archive

CWE-476 CVEs

Programmatic archive

5,444 CVEs tagged with CWE-476119 Critical, 1,295 High, 3,817 Medium, 212 Low, 1 Unrated.

CVE-2017-7475

Published May 19, 2017

Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9083

Published May 19, 2017

poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9051

Published May 18, 2017

libav before 12.1 is vulnerable to an invalid read of size 1 due to NULL pointer dereferencing in the nsv_read_chunk function in libavformat/nsvdec.c.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-9040

Published May 18, 2017

GNU Binutils 2017-04-03 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash), related to the process_mips_specific function in rea…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-9000

Published May 16, 2017

In TrustZone an untrusted pointer dereference vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0635

Published May 12, 2017

A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboo…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0351

Published May 9, 2017

All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to de…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0349

Published May 9, 2017

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from a user…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0348

Published May 9, 2017

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a NULL pointer dereference may lead to denial o…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0341

Published May 9, 2017

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input can trigge…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8825

Published May 8, 2017

A null dereference vulnerability has been found in the MIME handling component of LibEtPan before 1.8, as used in MailCore and MailCore 2. A crash can occur in low-level/imf/maili…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8847

Published May 8, 2017

The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8843

Published May 8, 2017

The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a cra…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3730

Published May 4, 2017

In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL p…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-7053

Published May 4, 2017

In OpenSSL 1.1.0 before 1.1.0c, applications parsing invalid CMS structures can crash with a NULL pointer dereference. This is caused by a bug in the handling of the ASN.1 CHOICE…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-8395

Published May 1, 2017

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid write of size 8 because of missing a malloc() return-value…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8394

Published May 1, 2017

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 4 due to NULL pointer dereferencing of _bfd_el…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8392

Published May 1, 2017

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a check to determine whet…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8106

Published Apr 24, 2017

The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000360

Published Apr 24, 2017

StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDaylight odl-mdsal-xsql is vulnerab…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000358

Published Apr 24, 2017

Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature contains this flaw. Version: Op…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7994

Published Apr 21, 2017

The function TextExtractor::ExtractText in TextExtractor.cpp:77 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application cras…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8726

Published Apr 13, 2017

An exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runScript iw_filename functionality of Moxa AWK-3131A Wireless Access Point running…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8723

Published Apr 13, 2017

An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 5,101-5,125 of 5,444 CVEsPage 205 of 218