Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Linux Kernel MEDIUM 5.5
CVE-2019-12378

An issue was discovered in ip6_ra_control in net/ipv6/ipv6_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, whi…

Fix: after 5.1.5
Fix from $1,600 2019-05-28
Linux Kernel MEDIUM 5.5
CVE-2019-12381

An issue was discovered in ip_ra_control in net/ipv4/ip_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which …

Fix: after 5.1.5
Fix from $1,600 2019-05-28
Linux Kernel MEDIUM 5.5
CVE-2019-12382

An issue was discovered in drm_load_edid_firmware in drivers/gpu/drm/drm_edid_load.c in the Linux kernel through 5.1.5. There is an unchecked kstrdup…

Fix: after 5.1.5
Fix from $1,600 2019-05-28
Qemu HIGH 7.5
CVE-2019-12155EPSS 6%

interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.

Patch available
Fix from $1,950 2019-05-24
Libreswan HIGH 7.5
CVE-2019-12312

In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer dereference by initiating an IK…

Fix: 3.28+
Fix from $1,950 2019-05-24
Asterisk HIGH 7.5
CVE-2016-7550

asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote).

No fix yet
Fix from $1,950 2019-05-23
Sdl2 Image MEDIUM 6.5
CVE-2019-12217

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There…

No fix yet
Fix from $1,600 2019-05-20
Sdl2 Image MEDIUM 6.5
CVE-2019-12218

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There…

No fix yet
Fix from $1,600 2019-05-20
Linux Kernel MEDIUM 5.5
CVE-2018-7191

In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is not called before register_netdevice. This allows local users to cause…

Fix: 4.13.14+
Fix from $1,600 2019-05-17
Miniupnpd HIGH 7.5
CVE-2019-12108

A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap…

Fix: after 2.1
Fix from $1,950 2019-05-15
Miniupnpd HIGH 7.5
CVE-2019-12109

A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap…

Fix: after 2.1
Fix from $1,950 2019-05-15
Miniupnpd HIGH 7.5
CVE-2019-12110

An AddPortMapping Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in upnpredirect.c.

Fix: after 2.1
Fix from $1,950 2019-05-15
Debian Linux HIGH 7.5
CVE-2019-12111

A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c.

Fix: after 2.1
Fix from $1,950 2019-05-15
Fedora HIGH 7.5
CVE-2019-8936EPSS 6%

NTP through 4.2.8p12 has a NULL Pointer Dereference.

Fix: 4.2.8 / 9.2+
Fix from $1,950 2019-05-15
Libnyoci HIGH 7.5
CVE-2019-12101

coap_decode_option in coap.c in LibNyoci 0.07.00rc1 mishandles certain packets with "Uri-Path: (null)" and consequently allows remote attackers to ca…

No fix yet
Fix from $1,950 2019-05-15
Wechat MEDIUM 5.5
CVE-2019-11419

vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause a denial of service (applicat…

Fix: after 7.0.3
Fix from $1,600 2019-05-14
Roav Dashcam A1 Firmware HIGH 7.5
CVE-2018-4024

An exploitable denial-of-service vulnerability exists in the thumbnail display functionality of the NT9665X Chipset firmware, running on the Anker Ro…

No fix yet
Fix from $1,950 2019-05-13
Fedora HIGH 7.5
CVE-2019-11494

In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH com…

Fix: after 2.3.5.2
Fix from $1,950 2019-05-08
Linux Kernel HIGH 7.5
CVE-2019-11810EPSS 6%

An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_allo…

Fix: 3.16.69 / 3.18.139+
Fix from $1,950 2019-05-07
Recutils MEDIUM 6.5
CVE-2019-11637

An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leadin…

No fix yet
Fix from $1,600 2019-05-01
Recutils MEDIUM 6.5
CVE-2019-11638

An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec…

No fix yet
Fix from $1,600 2019-05-01
Ubuntu Linux HIGH 7.5
CVE-2019-11596

In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when …

Fix: 1.5.14+
Fix from $1,950 2019-04-29
Hostapd MEDIUM 5.9
CVE-2019-11555

The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly sta…

Fix: 2.8+
Fix from $1,600 2019-04-26
Thunderbird HIGH 7.5
CVE-2018-18513

A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service …

Fix: 60.5.0+
Fix from $1,950 2019-04-26
Tensorflow MEDIUM 6.5
CVE-2019-9635

NULL pointer dereference in Google TensorFlow before 1.12.2 could cause a denial of service via an invalid GIF file.

Fix: 1.12.2+
Fix from $1,600 2019-04-24
Tensorflow MEDIUM 6.5
CVE-2018-7576

Google TensorFlow 1.6.x and earlier is affected by: Null Pointer Dereference. The type of exploitation is: context-dependent.

Fix: after 1.6.0
Fix from $1,600 2019-04-23
Atftp MEDIUM 5.9
CVE-2019-11366

An issue was discovered in atftpd in atftp 0.7.1. It does not lock the thread_list_mutex mutex before assigning the current thread data structure. As…

Patch available
Fix from $1,600 2019-04-20
Qemu HIGH 7.5
CVE-2019-5008

hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device dr…

Patch available
Fix from $1,950 2019-04-19
Debian Linux HIGH 8.8
CVE-2019-11338

libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of servi…

Patch available
Fix from $1,950 2019-04-19
Wireshark HIGH 7.5
CVE-2019-10901EPSS 6%

In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by handl…

Fix: after 2.6.7
Fix from $1,950 2019-04-09