Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Libming HIGH 8.8
CVE-2018-20428

libming 0.4.8 has a NULL pointer dereference in the strlenext function of the decompile.c file, a different vulnerability than CVE-2018-7874.

No fix yet
Fix from $1,950 2018-12-24
Libming HIGH 8.8
CVE-2018-20429

libming 0.4.8 has a NULL pointer dereference in the getName function of the decompile.c file, a different vulnerability than CVE-2018-7872 and CVE-20…

No fix yet
Fix from $1,950 2018-12-24
Debian Linux MEDIUM 6.5
CVE-2018-20431

GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.

Fix: after 1.8
Fix from $1,600 2018-12-24
Libming HIGH 8.8
CVE-2018-20425

libming 0.4.8 has a NULL pointer dereference in the pushdup function of the decompile.c file.

No fix yet
Fix from $1,950 2018-12-24
Libraw MEDIUM 6.5
CVE-2018-20363

LibRaw::raw2image in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.

Fix: after 0.19.1
Fix from $1,600 2018-12-22
Libraw MEDIUM 6.5
CVE-2018-20364

LibRaw::copy_bayer in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.

Fix: after 0.19.1
Fix from $1,600 2018-12-22
Freeware Advanced Audio Decoder 2 MEDIUM 5.5
CVE-2018-20357

A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnera…

No fix yet
Fix from $1,600 2018-12-22
Freeware Advanced Audio Decoder 2 MEDIUM 5.5
CVE-2018-20362

A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability…

No fix yet
Fix from $1,600 2018-12-22
Igraph MEDIUM 6.5
CVE-2018-20349

The igraph_i_strdiff function in igraph_trie.c in igraph through 0.7.1 has an NULL pointer dereference that allows attackers to cause a denial of ser…

Fix: after 0.7.1
Fix from $1,600 2018-12-22
Ubuntu Linux HIGH 7.5
CVE-2018-20191

hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a d…

Fix: after 3.1.0
Fix from $1,950 2018-12-20
Ubuntu Linux HIGH 7.5
CVE-2018-20125

hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq…

Fix: after 3.1.0
Fix from $1,950 2018-12-20
Fedora MEDIUM 6.5
CVE-2018-1000879

libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vuln…

Fix: 3.4.0+
Fix from $1,600 2018-12-20
Ubuntu Linux HIGH 7.5
CVE-2018-20024

LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS.

Fix: 0.9.12+
Fix from $1,950 2018-12-19
Freeware Advanced Audio Decoder 2 MEDIUM 5.5
CVE-2018-20195

A NULL pointer dereference was discovered in ic_predict of libfaad/ic_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability…

No fix yet
Fix from $1,600 2018-12-18
Freeware Advanced Audio Decoder 2 MEDIUM 5.5
CVE-2018-20198

A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability…

No fix yet
Fix from $1,600 2018-12-18
Debian Linux MEDIUM 5.5
CVE-2018-20199

A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability…

Fix: 2.9.0+
Fix from $1,600 2018-12-18
Libsass MEDIUM 6.5
CVE-2018-20190

In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Eval::operator()(Sass::Supports_Operator*) in eval.cpp may cause a Denial of Servi…

No fix yet
Fix from $1,600 2018-12-17
Ubuntu Linux MEDIUM 6.5
CVE-2018-5812

An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to trigger a…

Fix: 0.18.9+
Fix from $1,600 2018-12-07
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-5801

An error within the "LibRaw::unpack()" function (src/libraw_cxx.cpp) in LibRaw versions prior to 0.18.7 can be exploited to trigger a NULL pointer de…

Fix: 0.18.7+
Fix from $1,600 2018-12-07
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-5806

An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL …

Fix: 0.18.8+
Fix from $1,600 2018-12-07
PHP HIGH 7.5
CVE-2018-19935EPSS 6%

ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application cr…

Fix: 5.6.39 / 7.0.33+
Fix from $1,950 2018-12-07
Mi A2 Lite Firmware HIGH 7.5
CVE-2018-19939

The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices throu…

Fix: after 2018-08-27
Fix from $1,950 2018-12-07
Mupdf MEDIUM 5.5
CVE-2018-19882

In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of service (href_att NULL pointer dere…

No fix yet
Fix from $1,600 2018-12-06
Chrome MEDIUM 6.5
CVE-2018-6116

A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory ac…

Fix: 66.0.3359.117+
Fix from $1,600 2018-12-04
Libsass MEDIUM 6.5
CVE-2018-19797

In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (used by ast.cpp and ast_selector…

Patch available
Fix from $1,600 2018-12-03
Libsixel MEDIUM 6.5
CVE-2018-19757

There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that will cause a denial of service.

No fix yet
Fix from $1,600 2018-11-30
Wireshark MEDIUM 5.5
CVE-2018-19624

In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed in epan/dissectors/packet-pvfs2.c by preventing a…

Fix: after 2.6.4
Fix from $1,600 2018-11-29
Qts HIGH 7.5
CVE-2018-14747

NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and …

Mitigation only
Fix from $1,950 2018-11-28
Ubuntu Linux MEDIUM 6.5
CVE-2018-16851

Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the processing of an LDAP search befor…

Fix: 4.7.12 / 4.8.7+
Fix from $1,600 2018-11-28
Exiv2 MEDIUM 6.5
CVE-2018-19607

Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application c…

Patch available
Fix from $1,600 2018-11-27