Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Net HIGH 7.5
CVE-2018-17075

The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse…

Fix: after 2018-07-12
Fix from $1,950 2018-09-16
Debian Linux MEDIUM 6.5
CVE-2018-17000

A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an a…

No fix yet
Fix from $1,600 2018-09-13
Ubuntu Linux MEDIUM 6.5
CVE-2018-16749

In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows an attacker to cause a denial of service (WriteBl…

Fix: 6.9.9-42+
Fix from $1,600 2018-09-09
Debian Linux CRITICAL 9.8
CVE-2018-16657

In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. T…

Fix: 5.0.7 / 5.1.4+
Fix from $2,300 2018-09-07
Netwide Assembler MEDIUM 5.5
CVE-2018-16517EPSS 5%

asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted f…

Fix: after 2.13.03
Fix from $1,600 2018-09-06
Zephyr CRITICAL 9.8
CVE-2018-1000800

zephyr-rtos version 1.12.0 contains a NULL base pointer reference vulnerability in sys_ring_buf_put(), sys_ring_buf_get() that can result in CPU Page…

No fix yet
Fix from $2,300 2018-09-06
Jsish MEDIUM 6.5
CVE-2018-1000661

jsish version 2.4.67 contains a CWE-476: NULL Pointer Dereference vulnerability in Jsi_LogMsg (jsiUtils.c:196) that can result in Crash due to segmen…

Mitigation only
Fix from $1,600 2018-09-06
Virtualization Host MEDIUM 6.5
CVE-2018-10914

It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote de…

Fix: 3.12.14 / 4.1.8+
Fix from $1,600 2018-09-04
Ubuntu Linux CRITICAL 9.8
CVE-2018-16428

In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.

Patch available
Fix from $2,300 2018-09-04
Imagemagick CRITICAL 9.8
CVE-2018-16328

In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.

Fix: 7.0.8-8+
Fix from $2,300 2018-09-01
Imagemagick CRITICAL 9.8
CVE-2018-16329

In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the GetMagickProperty function in MagickCore/property.c.

Fix: 7.0.8-8+
Fix from $2,300 2018-09-01
Acrobat Dc HIGH 8.8
CVE-2018-12799EPSS 7%

Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and 2015.006.30434 and earlier have an untrusted pointer de…

Fix: after 18.011.20055
Fix from $1,950 2018-08-29
Ubuntu Linux MEDIUM 5.5
CVE-2018-15858

Unchecked NULL pointer usage when handling invalid aliases in CopyKeyAliasesToKeymap in xkbcomp/keycodes.c in xkbcommon before 0.8.1 could be used by…

Fix: 0.8.1+
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15859

Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attacker…

Fix: after 0.8.1
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15861

Unchecked NULL pointer usage in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer de…

Fix: after 0.8.1
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15862

Unchecked NULL pointer usage in LookupModMask in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer der…

Fix: after 0.8.1
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15863

Unchecked NULL pointer usage in ResolveStateAndPredicate in xkbcomp/compat.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NUL…

Fix: after 0.8.1
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15864

Unchecked NULL pointer usage in resolve_keysym in xkbcomp/parser.y in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer …

Fix: after 0.8.1
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15854

Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by s…

Fix: 0.8.1+
Fix from $1,600 2018-08-25
Ubuntu Linux MEDIUM 5.5
CVE-2018-15855

Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by s…

Fix: 0.8.1+
Fix from $1,600 2018-08-25
Libbpg MEDIUM 6.5
CVE-2017-2575

A vulnerability was found while fuzzing libbpg 0.9.7. It is a NULL pointer dereference issue due to missing check of the return value of function mal…

Mitigation only
Fix from $1,600 2018-08-22
Libvirt MEDIUM 6.5
CVE-2017-2635

A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this f…

Fix: after 3.0.0
Fix from $1,600 2018-08-22
Ubuntu Linux MEDIUM 6.5
CVE-2018-10918

A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An authenticated attacker could use …

Fix: 4.7.9 / 4.8.4+
Fix from $1,600 2018-08-22
Jsish MEDIUM 6.5
CVE-2018-1000655

Jsish version 2.4.65 contains a CWE-476: NULL Pointer Dereference vulnerability in Function jsi_ValueCopyMove from jsiValue.c:240 that can result in …

No fix yet
Fix from $1,600 2018-08-20
Jerryscript MEDIUM 6.5
CVE-2018-1000636

JerryScript version Tested on commit f86d7459d195c8ba58479d1861b0cc726c8b3793. Analysing history it seems that the issue has been present since commi…

Patch available
Fix from $1,600 2018-08-20
Appweb HIGH 7.5
CVE-2018-15504

An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with tim…

Fix: 4.0.1 / 7.0.2+
Fix from $1,950 2018-08-18
Appweb HIGH 7.5
CVE-2018-15505

An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field …

Fix: 4.0.1 / 7.0.2+
Fix from $1,950 2018-08-18
PHP HIGH 7.5
CVE-2018-14884

An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a …

Fix: 7.0.27 / 7.1.13+
Fix from $1,950 2018-08-03
Debian Linux MEDIUM 6.5
CVE-2016-9572

A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for de…

Patch available
Fix from $1,600 2018-08-01
Ceph MEDIUM 6.5
CVE-2016-8626

A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launc…

Fix: 0.94.3.9-8+
Fix from $1,600 2018-07-31