Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Linux Kernel MEDIUM 5.5
CVE-2024-26587

In the Linux kernel, the following vulnerability has been resolved: net: netdevsim: don't try to destroy PHC on VFs PHC gets initialized in nsim_in…

Fix: 6.6.14 / 6.7.2+
Fix from $1,600 2024-02-22
Fortios MEDIUM 6.5
CVE-2023-29179

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 thro…

Fix: 6.4.13 / 7.0.11+
Fix from $1,600 2024-02-22
Fortiproxy HIGH 7.5
CVE-2023-29180

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 t…

Fix: 2.0.13 / 6.0.17+
Fix from $1,950 2024-02-22
Cryptography HIGH 7.5
CVE-2024-26130

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to versi…

Fix: 42.0.4+
Fix from $1,950 2024-02-21
Nav2 MEDIUM 6.5
CVE-2024-25197

Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() f…

Fix: after 1.1.17
Fix from $1,600 2024-02-20
Atp100 Firmware MEDIUM 5.3
CVE-2023-6397

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions f…

Fix: 5.37+
Fix from $1,600 2024-02-20
Android HIGH 7.8
CVE-2024-0035

In onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to a missing null check. This co…

Patch available
Fix from $1,950 2024-02-16
Nginx Open Source HIGH 7.5
CVE-2024-24989

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note:…

Mitigation only
Fix from $1,950 2024-02-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2024-24775

When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (T…

Fix: 15.1.9 / 16.1.4+
Fix from $1,950 2024-02-14
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2024-23308

When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause t…

Fix: 17.1.1+
Fix from $1,950 2024-02-14
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2024-21763

When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffi…

Fix: 17.1.1+
Fix from $1,950 2024-02-14
Asp.net Core HIGH 7.5
CVE-2024-21404

.NET Denial of Service Vulnerability

Fix: 6.0.27 / 7.0.16+
Fix from $1,950 2024-02-13
Windows 10 1507 MEDIUM 6.5
CVE-2024-21356

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

Fix: 10.0.10240.20469 / 10.0.14393.6709+
Fix from $1,600 2024-02-13
Twister Antivirus MEDIUM 5.5
CVE-2024-1096

Twister Antivirus v8.17 is vulnerable to a Denial of Service vulnerability by triggering the 0x80112067, 0x801120CB 0x801120CC 0x80112044, 0x8011204B…

Mitigation only
Fix from $1,600 2024-02-13
Tecnomatix Plant Simulation MEDIUM 5.5
CVE-2024-23799

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007…

Fix: 2302.0007+
Fix from $1,600 2024-02-13
Tecnomatix Plant Simulation MEDIUM 5.5
CVE-2024-23800

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007…

Fix: 2302.0007+
Fix from $1,600 2024-02-13
Tecnomatix Plant Simulation MEDIUM 5.5
CVE-2024-23801

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007…

Fix: 2302.0007+
Fix from $1,600 2024-02-13
Parasolid MEDIUM 5.5
CVE-2024-22043

A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.251), Parasolid V35.1 (All versions < V35.1.170). The affected applicati…

Fix: 35.0.251 / 35.1.170+
Fix from $1,600 2024-02-13
Openpcs 7 MEDIUM 6.5
CVE-2023-48363

A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PCS …

Fix: after 18
Fix from $1,600 2024-02-13
Openpcs 7 MEDIUM 6.5
CVE-2023-48364

A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PCS …

Fix: after 18
Fix from $1,600 2024-02-13
Envoy HIGH 7.5
CVE-2024-23327

Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, the Envoy instance will segfau…

Fix: 1.26.7 / 1.27.3+
Fix from $1,950 2024-02-09
Bento4 MEDIUM 5.5
CVE-2024-25453

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.

No fix yet
Fix from $1,600 2024-02-09
Bento4 MEDIUM 5.5
CVE-2024-25454

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.

No fix yet
Fix from $1,600 2024-02-09
Codeready Linux Builder Eus HIGH 7.5
CVE-2023-6356

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages whe…

Mitigation only
Fix from $1,950 2024-02-07
Linux Kernel HIGH 7.5
CVE-2023-6535

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages whe…

Mitigation only
Fix from $1,950 2024-02-07
Linux Kernel HIGH 7.5
CVE-2023-6536

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages whe…

Fix: 5.4.268 / 5.10.209+
Fix from $1,950 2024-02-07
Aqt1000 Firmware HIGH 7.5
CVE-2023-43522

Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.

Mitigation only
Fix from $1,950 2024-02-06
Linux Kernel MEDIUM 5.3
CVE-2024-24860

A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dere…

Fix: after 6.7.2
Fix from $1,600 2024-02-05
Shim MEDIUM 5.5
CVE-2023-40546

A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an err…

Fix: 15.8+
Fix from $1,600 2024-01-29
Vba32 MEDIUM 5.5
CVE-2024-23441

Vba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A7 IOCTL code of the Vba32m64.sys driver.

No fix yet
Fix from $1,600 2024-01-29