Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
HTTP Server HIGH 7.5
CVE-2021-34798EPSS 65%

Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.

Fix: after 5.19.1
Fix from $1,950 2021-09-16
Commoncryptolib HIGH 7.5
CVE-2021-38177

SAP CommonCryptoLib version 8.5.38 or lower is vulnerable to null pointer dereference vulnerability when an unauthenticated attacker sends crafted ma…

Fix: after 8.5.38
Fix from $1,950 2021-09-14
Gpac MEDIUM 5.5
CVE-2021-32138

The DumpTrackInfo function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box co…

Patch available
Fix from $1,600 2021-09-13
Gpac MEDIUM 5.5
CVE-2021-32139

The gf_isom_vp_config_get function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the M…

Patch available
Fix from $1,600 2021-09-13
Gpac MEDIUM 5.5
CVE-2021-32132

The abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box co…

Patch available
Fix from $1,600 2021-09-13
Gpac MEDIUM 5.5
CVE-2021-32135

The trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box co…

Patch available
Fix from $1,600 2021-09-13
Gpac MEDIUM 5.5
CVE-2021-32134

The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box…

Patch available
Fix from $1,600 2021-09-13
Android MEDIUM 5.5
CVE-2021-25462

NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25458

NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.

Mitigation only
Fix from $1,600 2021-09-09
Qca6174a Firmware HIGH 7.0
CVE-2021-30290

Possible null pointer dereference due to race condition between timeline fence signal and time line fence destroy in Snapdragon Auto, Snapdragon Conn…

Patch available
Fix from $1,950 2021-09-09
Qca6174a Firmware MEDIUM 5.5
CVE-2021-30294

Potential null pointer dereference in KGSL GPU auxiliary command due to improper validation of user input in Snapdragon Auto, Snapdragon Connectivity…

Patch available
Fix from $1,600 2021-09-09
Apq8017 Firmware CRITICAL 9.8
CVE-2021-1946

Null Pointer Dereference may occur due to improper validation while processing crafted SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon Co…

Mitigation only
Fix from $2,300 2021-09-09
Apq8009 Firmware MEDIUM 5.5
CVE-2021-1935

Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdragon Compute, Snapdr…

Mitigation only
Fix from $1,600 2021-09-09
Ios Xr HIGH 7.5
CVE-2021-34737

A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to trigger a c…

Fix: 7.3.2 / 7.4.1+
Fix from $1,950 2021-09-09
Safari HIGH 7.5
CVE-2021-30698

A null pointer dereference was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, Safari 14.1.1, iOS 14.6 and iPadO…

Fix: 11.4 / 14.1.1+
Fix from $1,950 2021-09-08
Fedora HIGH 7.5
CVE-2020-19752

The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.

Patch available
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39251

A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Modicon M340 Bmxp341000 HIGH 7.5
CVE-2021-22792

A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the co…

Patch available
Fix from $1,950 2021-09-02
After Effects MEDIUM 5.5
CVE-2021-28601

Adobe After Effects version 18.2 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unau…

Fix: after 18.2
Fix from $1,600 2021-08-24
Iec104 HIGH 7.5
CVE-2020-18731

A segmentation violation in the Iec104_Deal_FirmUpdate function of IEC104 v1.0 allows attackers to cause a denial of service (DOS).

No fix yet
Fix from $1,950 2021-08-23
Iec104 HIGH 7.5
CVE-2020-18730

A segmentation violation in the Iec104_Deal_I function of IEC104 v1.0 allows attackers to cause a denial of service (DOS).

No fix yet
Fix from $1,950 2021-08-23
Fedora MEDIUM 6.5
CVE-2021-37750

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_re…

Fix: 1.18.5 / 1.19.3+
Fix from $1,600 2021-08-23
Acrobat Dc MEDIUM 6.5
CVE-2021-35984

Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Null pointer…

Fix: after 21.005.20054
Fix from $1,600 2021-08-20
Acrobat Dc MEDIUM 5.5
CVE-2021-35985

Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Null pointer…

Fix: after 21.005.20054
Fix from $1,600 2021-08-20
Bento4 HIGH 7.5
CVE-2020-23330

An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_Stz2Atom::GetSampleSize component located in /Core/Ap…

Fix: 1.6.0-635+
Fix from $1,950 2021-08-17
Bento4 HIGH 7.5
CVE-2020-23331

An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_DescriptorListWriter::Action component located in /Co…

No fix yet
Fix from $1,950 2021-08-17
Tensorflow MEDIUM 5.5
CVE-2021-37688

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a…

Fix: 2.3.4 / 2.4.3+
Fix from $1,600 2021-08-12
Tensorflow MEDIUM 5.5
CVE-2021-37689

TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can craft a TFLite model that would trigger a…

Fix: 2.3.4 / 2.4.3+
Fix from $1,600 2021-08-12
Tensorflow HIGH 7.8
CVE-2021-37648

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the code for `tf.raw_ops.SaveV2` does not properly valida…

Fix: 2.3.4 / 2.4.3+
Fix from $1,950 2021-08-12
Tensorflow HIGH 7.8
CVE-2021-37681

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of SVDF in TFLite is [vulnerable to a …

Fix: 2.3.4 / 2.4.3+
Fix from $1,950 2021-08-12