Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Ips Pdf HIGH 7.5
CVE-2020-11158

u'Null pointer dereference in HP OfficeJet Pro 8210 jbig2 filter due to lack of check of PDF font array leads to denial of service' in IPS PDF releas…

Mitigation only
Fix from $1,950 2020-09-08
Apq8053 Firmware HIGH 8.1
CVE-2018-13903

u'Error in UE due to race condition in EPCO handling' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Sna…

Mitigation only
Fix from $1,950 2020-09-08
Fedora HIGH 7.5
CVE-2020-24659

An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is s…

Fix: 3.6.15+
Fix from $1,950 2020-09-04
FreeBSD MEDIUM 5.5
CVE-2020-24385

In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in the Linux emulation layer that …

Fix: 1.2.6+
Fix from $1,600 2020-09-03
Firepower Extensible Operating System HIGH 8.6
CVE-2020-3517

A vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated attacker to cau…

Fix: 1.1.4.179 / 2.0.1.153+
Fix from $1,950 2020-08-27
Gatemanager 8250 Firmware CRITICAL 9.8
CVE-2020-14500

Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data.

Mitigation only
Fix from $2,300 2020-08-25
Goxmldsig HIGH 7.5
CVE-2020-7711

This affects all versions of package github.com/russellhaering/goxmldsig. There is a crash on nil-pointer dereference caused by sending malformed XML…

No fix yet
Fix from $1,950 2020-08-23
Linux Kernel HIGH 7.8
CVE-2020-14356

A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local…

Fix: 4.9.231 / 4.14.189+
Fix from $1,950 2020-08-19
Lua HIGH 7.5
CVE-2020-24369

ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.

Patch available
Fix from $1,950 2020-08-17
Debian Linux MEDIUM 5.5
CVE-2020-16306

A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of se…

No fix yet
Fix from $1,600 2020-08-13
Debian Linux MEDIUM 5.5
CVE-2020-16307

A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker…

No fix yet
Fix from $1,600 2020-08-13
Debian Linux MEDIUM 5.5
CVE-2020-16293

A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex Software GhostS…

Fix: 9.52+
Fix from $1,600 2020-08-13
Debian Linux MEDIUM 5.5
CVE-2020-16295

A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to c…

Fix: 9.52+
Fix from $1,600 2020-08-13
Debian Linux MEDIUM 5.9
CVE-2020-16135

libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.

Patch available
Fix from $1,600 2020-07-29
Ht801 Firmware HIGH 7.5
CVE-2020-5762

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticat…

Fix: after 1.0.17.5
Fix from $1,950 2020-07-29
Balsa HIGH 7.5
CVE-2020-16118

In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PR…

Fix: 2.6.0+
Fix from $1,950 2020-07-29
Debian Linux MEDIUM 5.9
CVE-2020-16117

In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.…

Fix: 3.35.91+
Fix from $1,600 2020-07-29
Cherokee HIGH 7.5
CVE-2020-12845

Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the ser…

Fix: after 1.2.104
Fix from $1,950 2020-07-27
Pi Data Archive HIGH 7.1
CVE-2020-10600

An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking qu…

Fix: after 2019
Fix from $1,950 2020-07-24
Data Archive MEDIUM 5.3
CVE-2020-10602

In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Network Manager due to a race condition. This ca…

Mitigation only
Fix from $1,600 2020-07-24
Ubuntu Linux HIGH 7.5
CVE-2020-3481

A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remo…

Fix: after 0.102.3
Fix from $1,950 2020-07-20
Libredwg MEDIUM 6.5
CVE-2020-15807

GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.

Fix: 0.11+
Fix from $1,600 2020-07-17
Libredwg CRITICAL 9.8
CVE-2019-20914

An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in co…

Fix: after 0.9.3
Fix from $2,300 2020-07-16
Libredwg HIGH 7.5
CVE-2019-20909

An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.

Fix: after 0.9.3
Fix from $1,950 2020-07-16
Tomcat HIGH 7.5
CVE-2020-13934EPSS 64%

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after…

Fix: after 9.0.36
Fix from $1,950 2020-07-14
Appweb HIGH 7.5
CVE-2020-15689

Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This…

Fix: 7.2.2 / 8.1.0+
Fix from $1,950 2020-07-13
Storage MEDIUM 6.5
CVE-2020-10730

A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4…

Fix: 4.10.17 / 4.11.11+
Fix from $1,600 2020-07-07
Coreos HIGH 7.5
CVE-2020-5597

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Mode…

Mitigation only
Fix from $1,950 2020-07-07
Fedora MEDIUM 5.5
CVE-2020-15304

An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in…

Fix: 2.5.2+
Fix from $1,600 2020-06-26
Acrobat Dc MEDIUM 5.5
CVE-2020-9610

Adobe Acrobat and Reader versions 2020.006.20042 and earlier, 2017.011.30166 and earlier, 2017.011.30166 and earlier, and 2015.006.30518 and earlier …

Fix: 15.006.30518 / 17.011.30166+
Fix from $1,600 2020-06-25