Skip to main content

CWE archive

CWE-476 CVEs

Programmatic archive

5,433 CVEs tagged with CWE-476119 Critical, 1,293 High, 3,808 Medium, 212 Low, 1 Unrated.

CVE-2017-7209

Published Mar 21, 2017

The dump_section_as_bytes function in readelf in GNU Binutils 2.28 accesses a NULL pointer while reading section contents in a corrupt binary, leading to a program crash.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7207

Published Mar 21, 2017

The mem_get_bits_rectangle function in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PostSc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6178

Published Mar 20, 2017

The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call, which triggers a NULL pointer dereference.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6951

Published Mar 16, 2017

The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS)…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5937

Published Mar 15, 2017

The util_format_is_pure_uint function in vrend_renderer.c in Virgil 3d project (aka virglrenderer) 0.6.0 and earlier allows local guest OS users to cause a denial of service (NULL…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8898

Published Mar 15, 2017

The WriteImages function in magick/constitute.c in ImageMagick before 6.9.2-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image f…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6850

Published Mar 15, 2017

The jp2_cdef_destroy function in jp2_cod.c in JasPer before 2.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6849

Published Mar 15, 2017

The PoDoFo::PdfColorGray::~PdfColorGray function in PdfColor.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6848

Published Mar 15, 2017

The PoDoFo::PdfXObject::PdfXObject function in PdfXObject.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6847

Published Mar 15, 2017

The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6846

Published Mar 15, 2017

The GraphicsStack::TGraphicsStackElement::SetNonStrokingColorSpace function in graphicsstack.h in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer d…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6845

Published Mar 15, 2017

The PoDoFo::PdfColor::operator function in PdfColor.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6842

Published Mar 15, 2017

The ColorChanger::GetColorFromStack function in colorchanger.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6841

Published Mar 15, 2017

The GraphicsStack::TGraphicsStackElement::~TGraphicsStackElement function in graphicsstack.h in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer der…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6210

Published Mar 15, 2017

The vrend_decode_reset function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (NULL pointer dereference and QEMU process…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10250

Published Mar 15, 2017

The jp2_colr_destroy function in jp2_cod.c in JasPer before 1.900.13 allows remote attackers to cause a denial of service (NULL pointer dereference) by leveraging incorrect cleanu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10248

Published Mar 15, 2017

The jpc_tsfb_synthesize function in jpc_tsfb.c in JasPer before 1.900.9 allows remote attackers to cause a denial of service (NULL pointer dereference) via vectors involving an em…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5668

Published Mar 14, 2017

bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer re…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-6311

Published Mar 10, 2017

gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to prin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6350

Published Mar 7, 2017

OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (NULL pointer dereference and panic) via a sysctl call with a path starting with 10,9.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6501

Published Mar 6, 2017

An issue was discovered in ImageMagick 6.9.7. A specially crafted xcf file could lead to a NULL pointer dereference.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6497

Published Mar 6, 2017

An issue was discovered in ImageMagick 6.9.7. A specially crafted psd file could lead to a NULL pointer dereference (thus, a DoS).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5193

Published Mar 3, 2017

The nickcmp function in Irssi before 0.8.21 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a message without a nick.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 5,151-5,175 of 5,433 CVEsPage 207 of 218