Skip to main content

CWE archive

CWE-476 CVEs

Programmatic archive

5,433 CVEs tagged with CWE-476119 Critical, 1,293 High, 3,808 Medium, 212 Low, 1 Unrated.

CVE-2017-7382

Published Apr 3, 2017

The PdfFontFactory.cpp:200:88 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7381

Published Apr 3, 2017

The doc/PdfPage.cpp:609:23 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7380

Published Apr 3, 2017

The doc/PdfPage.cpp:614:20 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6441

Published Apr 3, 2017

The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5951

Published Apr 3, 2017

The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10220

Published Apr 3, 2017

The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference an…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10218

Published Apr 3, 2017

The pdf14_pop_transparency_group function in base/gdevp14.c in the PDF Transparency module in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10210

Published Apr 3, 2017

libyara/lexer.l in YARA 3.5.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted rule that is mishandled in the yy…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10209

Published Apr 3, 2017

The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2388

Published Apr 2, 2017

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireFamily" component. It allows attackers to cause a denial of…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7374

Published Mar 31, 2017

Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2647

Published Mar 31, 2017

The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors invol…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9814

Published Mar 30, 2017

ImageMagick allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted wpg file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9812

Published Mar 30, 2017

ImageMagick allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted ps file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8884

Published Mar 28, 2017

The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo comman…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7274

Published Mar 27, 2017

The r_pkcs7_parse_cms function in libr/util/r_pkcs7.c in radare2 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4912

Published Mar 27, 2017

The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8762

Published Mar 27, 2017

The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a zero-length EAP-PWD packe…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7243

Published Mar 24, 2017

Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending a "Change cipher spec" packet without pre-handshake.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10132

Published Mar 24, 2017

regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10129

Published Mar 24, 2017

The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8885

Published Mar 23, 2017

The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.9 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7225

Published Mar 22, 2017

The find_nearest_line function in addr2line in GNU Binutils 2.28 does not handle the case where the main file name and the directory name are both empty, triggering a NULL pointer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 5,126-5,150 of 5,433 CVEsPage 206 of 218