Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Debian Linux HIGH 7.5
CVE-2018-0490

An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotoc…

Fix: after 0.3.1.9
Fix from $1,950 2018-03-05
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-7642

The swap_std_reloc_in function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remot…

Mitigation only
Fix from $1,600 2018-03-02
Linux Kernel MEDIUM 6.5
CVE-2018-1066

The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker …

Fix: after 4.10.15
Fix from $1,600 2018-03-02
Ubuntu Linux HIGH 8.8
CVE-2017-18209

In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointer dereference vulnerability occurs because a memo…

Patch available
Fix from $1,950 2018-03-01
Imagemagick CRITICAL 9.8
CVE-2017-18210

In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function BenchmarkOpenCLDevices in MagickCore/opencl.c because a memo…

Patch available
Fix from $2,300 2018-03-01
Ubuntu Linux CRITICAL 9.8
CVE-2017-18211

In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a program-loo…

Patch available
Fix from $2,300 2018-03-01
Xerces C\+\+ CRITICAL 9.8
CVE-2017-12627EPSS 8%

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain condition…

Fix: 3.2.1+
Fix from $2,300 2018-03-01
Binutils MEDIUM 5.5
CVE-2018-7570

The assign_file_positions_for_non_load_sections function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin…

Patch available
Fix from $1,600 2018-02-28
Zsh HIGH 8.1
CVE-2017-18205

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no a…

Fix: 5.4+
Fix from $1,950 2018-02-27
Ubuntu Linux CRITICAL 9.8
CVE-2018-7548

In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.

Fix: after 5.4.2
Fix from $2,300 2018-02-27
Icinga MEDIUM 6.5
CVE-2018-6534

An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted messages, an attacker can cause a NULL pointer dereference, which c…

Fix: after 2.8.1
Fix from $1,600 2018-02-27
Debian Linux MEDIUM 6.5
CVE-2018-7542

An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL pointer dereference and hyperv…

Fix: after 4.10.0
Fix from $1,600 2018-02-27
Linux Kernel MEDIUM 5.5
CVE-2018-7492

A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux kernel before 4.14.7 allowing local attackers to ca…

Fix: 4.14.7+
Fix from $1,600 2018-02-26
Libcdio MEDIUM 6.5
CVE-2017-18199

realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (NULL Pointer Dereference) via a crafted i…

Fix: 1.0.0+
Fix from $1,600 2018-02-24
Xpdf MEDIUM 5.5
CVE-2018-7452

A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf fil…

No fix yet
Fix from $1,600 2018-02-24
Xpdf MEDIUM 5.5
CVE-2018-7454

A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as…

Mitigation only
Fix from $1,600 2018-02-24
Debian Linux MEDIUM 6.5
CVE-2018-7456

A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0a…

Patch available
Fix from $1,600 2018-02-24
Wireshark HIGH 7.5
CVE-2018-7336

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the FCP protocol dissector could crash. This was addressed in epan/dissectors/packet-fcp.c by checki…

Fix: after 2.4.4
Fix from $1,950 2018-02-23
Asterisk HIGH 7.5
CVE-2018-7285EPSS 5%

A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1. The RTP support in Asterisk maintains its own registry of dynamic codecs …

Fix: after 15.2.1
Fix from $1,950 2018-02-22
Debian Linux MEDIUM 5.9
CVE-2015-5316

The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configurat…

Fix: 2.6+
Fix from $1,600 2018-02-21
Floodlight MEDIUM 5.9
CVE-2015-6569

Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NUL…

Fix: 1.2+
Fix from $1,600 2018-02-21
System Management Homepage HIGH 7.5
CVE-2017-12545EPSS 7%

A remote denial of service vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

Fix: 7.6.1+
Fix from $1,950 2018-02-15
Xpdf MEDIUM 5.5
CVE-2018-7175

An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with…

Mitigation only
Fix from $1,600 2018-02-15
Debian Linux HIGH 7.5
CVE-2018-7050

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL pointer dereference occurs for an "empty" nick.

Fix: 1.0.7+
Fix from $1,950 2018-02-15
Ubuntu Linux HIGH 7.5
CVE-2018-7052

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. When the number of windows exceeds the available space, a crash due to a NULL p…

Fix: 1.0.7+
Fix from $1,950 2018-02-15
Debian Linux HIGH 7.5
CVE-2017-18189EPSS 5%

In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a …

Fix: after 14.4.2
Fix from $1,950 2018-02-15
Windows 8.1 MEDIUM 5.3
CVE-2018-0833EPSS 40%

The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2 allows a denial of service v…

Patch available
Fix from $1,600 2018-02-15
Internet Graphics Server MEDIUM 6.5
CVE-2018-2384

Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessing the SAP Internet Graphics …

Mitigation only
Fix from $1,600 2018-02-14
Ubuntu Linux HIGH 7.5
CVE-2018-6951EPSS 8%

An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of…

Fix: after 2.7.6
Fix from $1,950 2018-02-13
Ubuntu Linux MEDIUM 6.5
CVE-2018-6942

An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS …

Fix: after 2.9
Fix from $1,600 2018-02-13