Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Jerryscript HIGH 7.5
CVE-2017-9250

The lexer_process_char_literal function in jerry-core/parser/js/js-lexer.c in JerryScript 1.0 does not skip memory allocation for empty strings, whic…

Patch available
Fix from $1,950 2017-05-28
Windows Defender MEDIUM 5.5
CVE-2017-8535EPSS 17%

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Window…

Patch available
Fix from $1,600 2017-05-26
Windows Defender MEDIUM 5.5
CVE-2017-8536EPSS 17%

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Window…

Patch available
Fix from $1,600 2017-05-26
Windows Defender MEDIUM 5.5
CVE-2017-8537EPSS 17%

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Window…

Patch available
Fix from $1,600 2017-05-26
Forefront Security MEDIUM 5.5
CVE-2017-8539EPSS 6%

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Window…

Fix: after 1.1.13704.0
Fix from $1,600 2017-05-26
Forefront Security MEDIUM 5.5
CVE-2017-8542EPSS 6%

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Window…

Fix: after 1.1.13704.0
Fix from $1,600 2017-05-26
PHP HIGH 7.5
CVE-2017-9229EPSS 5%

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A SIGSEGV occurs in lef…

Fix: 5.6.31 / 7.0.21+
Fix from $1,950 2017-05-24
Debian Linux MEDIUM 6.5
CVE-2017-9216

libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_h…

Patch available
Fix from $1,600 2017-05-24
Systemd HIGH 7.5
CVE-2017-9217EPSS 15%

systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question se…

Fix: after 233
Fix from $1,950 2017-05-24
Linux Kernel MEDIUM 5.5
CVE-2017-9211

The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check…

Fix: after 4.11.2
Fix from $1,600 2017-05-23
Pgbouncer HIGH 7.5
CVE-2015-4054

PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before …

Fix: after 1.5.4
Fix from $1,950 2017-05-23
Workstation Player MEDIUM 6.5
CVE-2017-4916

VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this iss…

Patch available
Fix from $1,600 2017-05-22
Cairo MEDIUM 5.5
CVE-2017-7475

Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.

Patch available
Fix from $1,600 2017-05-19
Poppler MEDIUM 6.5
CVE-2017-9083

poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For exampl…

No fix yet
Fix from $1,600 2017-05-19
Libav CRITICAL 9.8
CVE-2017-9051

libav before 12.1 is vulnerable to an invalid read of size 1 due to NULL pointer dereferencing in the nsv_read_chunk function in libavformat/nsvdec.c.

Fix: after 12.0
Fix from $2,300 2017-05-18
Binutils MEDIUM 5.5
CVE-2017-9040

GNU Binutils 2017-04-03 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash), related to the process…

Patch available
Fix from $1,600 2017-05-18
Android HIGH 7.8
CVE-2015-9000

In TrustZone an untrusted pointer dereference vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux k…

Patch available
Fix from $1,950 2017-05-16
Android MEDIUM 5.5
CVE-2017-0635

A remote denial of service vulnerability in HevcUtils.cpp in libstagefright in Mediaserver could enable an attacker to use a specially crafted file t…

Patch available
Fix from $1,600 2017-05-12
Gpu Driver HIGH 7.8
CVE-2017-0341

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where …

Mitigation only
Fix from $1,950 2017-05-09
Gpu Driver HIGH 7.8
CVE-2017-0348

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a NULL pointer de…

Mitigation only
Fix from $1,950 2017-05-09
Gpu Driver HIGH 7.8
CVE-2017-0349

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where…

Mitigation only
Fix from $1,950 2017-05-09
Gpu Driver HIGH 7.8
CVE-2017-0351

All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by inv…

Mitigation only
Fix from $1,950 2017-05-09
Libetpan HIGH 7.5
CVE-2017-8825

A null dereference vulnerability has been found in the MIME handling component of LibEtPan before 1.8, as used in MailCore and MailCore 2. A crash ca…

Fix: after 1.7.2
Fix from $1,950 2017-05-08
Long Range Zip MEDIUM 5.5
CVE-2017-8843

The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference an…

Patch available
Fix from $1,600 2017-05-08
Long Range Zip MEDIUM 5.5
CVE-2017-8847

The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer der…

Patch available
Fix from $1,600 2017-05-08
OpenSSL HIGH 7.5
CVE-2017-3730EPSS 55%

In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client atte…

Patch available
Fix from $1,950 2017-05-04
Binutils HIGH 7.5
CVE-2017-8392

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of mis…

Patch available
Fix from $1,950 2017-05-01
Binutils HIGH 7.5
CVE-2017-8394

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 4 due to NULL po…

Patch available
Fix from $1,950 2017-05-01
Binutils HIGH 7.5
CVE-2017-8395

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid write of size 8 because of mi…

Patch available
Fix from $1,950 2017-05-01
Linux Kernel MEDIUM 5.5
CVE-2017-8106

The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of serv…

Mitigation only
Fix from $1,600 2017-04-24