Vulnerability index

Browse CVEs

5,204 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Debian Linux HIGH 7.5
CVE-2025-25475

A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafte…

Patch available
Fix from $1,950 2025-02-18
Libxml2 HIGH 7.5
CVE-2025-27113

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.

Fix: 2.12.10 / 2.13.6+
Fix from $1,950 2025-02-18
Debian Linux MEDIUM 6.5
CVE-2025-22921

FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.

Mitigation only
Fix from $1,600 2025-02-18
Fluent Bit HIGH 7.5
CVE-2024-50608

An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on an IP address and port, one ca…

No fix yet
Fix from $1,950 2025-02-18
Fluent Bit HIGH 7.5
CVE-2024-50609

An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP address and port, one can send a p…

No fix yet
Fix from $1,950 2025-02-18
Ffmpeg MEDIUM 5.5
CVE-2025-1373

A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic. Affected by this issue is the function mov_read_trak of the file lib…

Fix: after 7.1
Fix from $1,600 2025-02-17
Elfutils MEDIUM 5.5
CVE-2025-1371

A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of …

Mitigation only
Fix from $1,600 2025-02-17
Headunit Ntg6 Mercedes Benz User Experience HIGH 7.5
CVE-2023-34398

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive accor…

Fix: after 2021
Fix from $1,950 2025-02-13
Headunit Ntg6 Mercedes Benz User Experience HIGH 7.5
CVE-2023-34400

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. In case of parsing file, service try to define header …

Fix: after 2021
Fix from $1,950 2025-02-13
Exynos 1480 Firmware HIGH 7.5
CVE-2024-46922

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The absence of a null check leads to a Denial of Service at amdgpu_cs_parse…

Mitigation only
Fix from $1,950 2025-02-12
Unclassified HIGH 7.4
CVE-2024-39356

NULL pointer dereference in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthentica…

Mitigation only
Fix from $1,950 2025-02-12
Unclassified HIGH 7.9
CVE-2024-32941

NULL pointer dereference for some Intel(R) MLC software before version v3.11b may allow an authenticated user to potentially enable denial of service…

Mitigation only
Fix from $1,950 2025-02-12
Substance 3d Stager MEDIUM 5.5
CVE-2025-21155

Substance3D - Stager versions 3.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-o…

Fix: 3.1.1+
Fix from $1,600 2025-02-11
Indesign MEDIUM 5.5
CVE-2025-21125

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application d…

Fix: 19.5.2+
Fix from $1,600 2025-02-11
Linux Kernel MEDIUM 5.5
CVE-2025-21689

In the Linux kernel, the following vulnerability has been resolved: USB: serial: quatech2: fix null-ptr-deref in qt2_process_read_urb() This patch …

Fix: 5.4.290 / 5.10.234+
Fix from $1,600 2025-02-10
Unclassified MEDIUM 5.1
CVE-2025-24031

PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. In versions 0.6.12 and prior, the pam_pkcs11 module segfaul…

Mitigation only
Fix from $1,600 2025-02-10
Dir 823x Firmware MEDIUM 6.5
CVE-2025-1103EPSS 13%

A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802. This affects the function set_wifi_blacklists of th…

No fix yet
Fix from $1,600 2025-02-07
Defense Platform MEDIUM 5.5
CVE-2025-24483

NULL pointer dereference vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted da…

Fix: after 3.9.51.0
Fix from $1,600 2025-02-06
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-20045

When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routi…

Fix: 16.1.5 / 17.1.2+
Fix from $1,950 2025-02-05
Mall Tiny MEDIUM 6.5
CVE-2024-57435

In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a null pointer dereference occurri…

No fix yet
Fix from $1,600 2025-01-31
Linux Kernel MEDIUM 5.5
CVE-2025-21682

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: always recalculate features after XDP clearing, fix null-deref Recal…

Fix: 6.12.11+
Fix from $1,600 2025-01-31
Linux Kernel MEDIUM 5.5
CVE-2025-21669

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: discard packets if the transport changes If the socket has been d…

Fix: 5.15.177 / 6.1.127+
Fix from $1,600 2025-01-31
Linux Kernel MEDIUM 5.5
CVE-2025-21670

In the Linux kernel, the following vulnerability has been resolved: vsock/bpf: return early if transport is not assigned Some of the core functions…

Fix: 6.6.74 / 6.12.11+
Fix from $1,600 2025-01-31
Linux Kernel MEDIUM 5.5
CVE-2025-21675

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clear port select structure when fail to create Clear the port select…

Fix: 6.1.127 / 6.6.74+
Fix from $1,600 2025-01-31
Linux Kernel MEDIUM 5.5
CVE-2025-21676

In the Linux kernel, the following vulnerability has been resolved: net: fec: handle page_pool_dev_alloc_pages error The fec_enet_update_cbd functi…

Fix: 6.6.74 / 6.12.11+
Fix from $1,600 2025-01-31
Linux Kernel MEDIUM 5.5
CVE-2024-57948

In the Linux kernel, the following vulnerability has been resolved: mac802154: check local interfaces before deleting sdata list syzkaller reported…

Fix: 5.4.290 / 5.10.234+
Fix from $1,600 2025-01-31
Linux Kernel MEDIUM 5.5
CVE-2025-21666

In the Linux kernel, the following vulnerability has been resolved: vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] Recent reports hav…

Fix: 5.15.177 / 6.1.127+
Fix from $1,600 2025-01-31
Ipados HIGH 7.5
CVE-2025-24177

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoi…

Fix: 15.3 / 18.3+
Fix from $1,950 2025-01-27
Unclassified MEDIUM 5.3
CVE-2025-0696

A NULL Pointer Dereference vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the…

Mitigation only
Fix from $1,600 2025-01-27
Openimageio CRITICAL 9.8
CVE-2024-55193

OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.

No fix yet
Fix from $2,300 2025-01-23