Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
OpenSSL MEDIUM 5.9
CVE-2021-3449EPSS 63%

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello…

Fix: 1.1.1k / 12.22.1+
Fix from $1,600 2021-03-25
Image Viewer HIGH 7.8
CVE-2021-26235

FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfc9, triggered when a user opens or views a malfo…

Fix: after 7.5
Fix from $1,950 2021-03-18
Subversion HIGH 7.5
CVE-2020-17525EPSS 40%

Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a c…

Fix: 1.10.7 / 1.14.1+
Fix from $1,950 2021-03-17
Fedora HIGH 7.5
CVE-2021-28543

Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not aff…

Fix: 0.17.1+
Fix from $1,950 2021-03-16
Simatic S7 Plcsim MEDIUM 5.5
CVE-2021-25674

A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the system could cause a Denial-of-Ser…

Mitigation only
Fix from $1,600 2021-03-15
Storage Performance Development Kit HIGH 7.5
CVE-2021-28361

An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI target with a zero length (but d…

Fix: 20.01.01+
Fix from $1,950 2021-03-13
Fltk HIGH 7.5
CVE-2021-28307

An issue was discovered in the fltk crate before 0.15.3 for Rust. There is a NULL pointer dereference during attempted use of a non-raster image for …

Fix: 0.15.3+
Fix from $1,950 2021-03-12
Fltk HIGH 7.5
CVE-2021-28306

An issue was discovered in the fltk crate before 0.15.3 for Rust. There is a NULL pointer dereference during attempted use of a multi label type if t…

Fix: 0.15.3+
Fix from $1,950 2021-03-12
Privoxy HIGH 7.5
CVE-2021-20274

A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbehaves.

Fix: 3.0.32+
Fix from $1,950 2021-03-09
Fedora MEDIUM 5.5
CVE-2021-26927

A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.

Fix: 2.0.25+
Fix from $1,600 2021-02-23
Libxls MEDIUM 5.5
CVE-2020-27819

An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer dereference vulnerability exists when…

Fix: 1.6.2+
Fix from $1,600 2021-02-23
Linux Kernel MEDIUM 6.7
CVE-2020-35499

A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have…

Fix: 5.10.4+
Fix from $1,600 2021-02-19
Graphics Drivers MEDIUM 5.5
CVE-2020-12364

Null pointer reference in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before version Linux kernel version 5.5 may a…

Fix: 26.20.100.7212+
Fix from $1,600 2021-02-17
Private Disk MEDIUM 5.5
CVE-2021-27203

In Dekart Private Disk 2.15, invalid use of the Type3 user buffer for IOCTL codes using METHOD_NEITHER results in arbitrary memory dereferencing.

No fix yet
Fix from $1,600 2021-02-16
OpenSSL MEDIUM 5.9
CVE-2021-23841EPSS 7%

The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data conta…

Fix: 1.0.2y / 1.1.1j+
Fix from $1,600 2021-02-16
PHP HIGH 7.5
CVE-2021-21702

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP…

Fix: 7.3.27 / 7.4.15+
Fix from $1,950 2021-02-15
Acrobat MEDIUM 6.6
CVE-2021-21057

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a nul…

Fix: after 20.013.20074
Fix from $1,600 2021-02-11
Pcoip Soft Client HIGH 7.5
CVE-2021-25690

A null pointer dereference in Teradici PCoIP Soft Client versions prior to 20.07.3 could allow an attacker to crash the software.

Fix: after 20.07.2
Fix from $1,950 2021-02-11
Uc Http HIGH 7.5
CVE-2020-13583

A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to de…

No fix yet
Fix from $1,950 2021-02-10
Fluent Bit HIGH 7.5
CVE-2021-27186

Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metrics.c.

Patch available
Fix from $1,950 2021-02-10
Fedora HIGH 7.5
CVE-2020-13578

A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead …

No fix yet
Fix from $1,950 2021-02-10
Fedora HIGH 7.5
CVE-2020-13574

A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead …

No fix yet
Fix from $1,950 2021-02-10
Fedora HIGH 7.5
CVE-2020-13575

A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lea…

No fix yet
Fix from $1,950 2021-02-10
Fedora HIGH 7.5
CVE-2020-13577

A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead …

No fix yet
Fix from $1,950 2021-02-10
Fedora MEDIUM 6.5
CVE-2020-36148

Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentatio…

Fix: after 1.1
Fix from $1,600 2021-02-08
Fedora MEDIUM 6.5
CVE-2020-36149

Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentatio…

Fix: after 1.1
Fix from $1,600 2021-02-08
Iprojection MEDIUM 5.5
CVE-2020-9453

In Epson iProjection v2.30, the driver file EMP_MPAU.sys allows local users to cause a denial of service (BSOD) or possibly have unspecified other im…

Fix: after 2.30
Fix from $1,600 2021-02-05
Openshift Service Mesh MEDIUM 6.5
CVE-2019-25014

A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET …

Fix: after 1.4.9
Fix from $1,600 2021-01-29
Micrium Uc Http HIGH 7.5
CVE-2020-13582

A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to de…

No fix yet
Fix from $1,950 2021-01-26
Cache HIGH 7.5
CVE-2021-25903

An issue was discovered in the cache crate through 2021-01-01 for Rust. A raw pointer is dereferenced.

Fix: after 0.2.0
Fix from $1,950 2021-01-26