Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
MEDIUM 5.9 CVE-2021-3449EPSS 63% An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello… OpenSSL 1.1.1k / 12.22.1+ Fix from $1,6002021-03-25 HIGH 7.8 CVE-2021-26235 FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfc9, triggered when a user opens or views a malfo… Image Viewer after 7.5 Fix from $1,9502021-03-18 HIGH 7.5 CVE-2020-17525EPSS 40% Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a c… Subversion 1.10.7 / 1.14.1+ Fix from $1,9502021-03-17 HIGH 7.5 CVE-2021-28543 Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not aff… Fedora 0.17.1+ Fix from $1,9502021-03-16 MEDIUM 5.5 CVE-2021-25674 A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the system could cause a Denial-of-Ser… Simatic S7 Plcsim Mitigation only Fix from $1,6002021-03-15 HIGH 7.5 CVE-2021-28361 An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI target with a zero length (but d… Storage Performance Development Kit 20.01.01+ Fix from $1,9502021-03-13 HIGH 7.5 CVE-2021-28307 An issue was discovered in the fltk crate before 0.15.3 for Rust. There is a NULL pointer dereference during attempted use of a non-raster image for … Fltk 0.15.3+ Fix from $1,9502021-03-12 HIGH 7.5 CVE-2021-28306 An issue was discovered in the fltk crate before 0.15.3 for Rust. There is a NULL pointer dereference during attempted use of a multi label type if t… Fltk 0.15.3+ Fix from $1,9502021-03-12 HIGH 7.5 CVE-2021-20274 A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbehaves. Privoxy 3.0.32+ Fix from $1,9502021-03-09 MEDIUM 5.5 CVE-2021-26927 A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service. Fedora 2.0.25+ Fix from $1,6002021-02-23 MEDIUM 5.5 CVE-2020-27819 An issue was discovered in libxls before and including 1.6.1 when reading Microsoft Excel files. A NULL pointer dereference vulnerability exists when… Libxls 1.6.2+ Fix from $1,6002021-02-23 MEDIUM 6.7 CVE-2020-35499 A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have… Linux Kernel 5.10.4+ Fix from $1,6002021-02-19 MEDIUM 5.5 CVE-2020-12364 Null pointer reference in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before version Linux kernel version 5.5 may a… Graphics Drivers 26.20.100.7212+ Fix from $1,6002021-02-17 MEDIUM 5.5 CVE-2021-27203 In Dekart Private Disk 2.15, invalid use of the Type3 user buffer for IOCTL codes using METHOD_NEITHER results in arbitrary memory dereferencing. Private Disk No fix yet Fix from $1,6002021-02-16 MEDIUM 5.9 CVE-2021-23841EPSS 7% The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data conta… OpenSSL 1.0.2y / 1.1.1j+ Fix from $1,6002021-02-16 HIGH 7.5 CVE-2021-21702 In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP… PHP 7.3.27 / 7.4.15+ Fix from $1,9502021-02-15 MEDIUM 6.6 CVE-2021-21057 Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a nul… Acrobat after 20.013.20074 Fix from $1,6002021-02-11 HIGH 7.5 CVE-2021-25690 A null pointer dereference in Teradici PCoIP Soft Client versions prior to 20.07.3 could allow an attacker to crash the software. Pcoip Soft Client after 20.07.2 Fix from $1,9502021-02-11 HIGH 7.5 CVE-2020-13583 A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to de… Uc Http No fix yet Fix from $1,9502021-02-10 HIGH 7.5 CVE-2021-27186 Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metrics.c. Fluent Bit Patch available Fix from $1,9502021-02-10 HIGH 7.5 CVE-2020-13578 A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead … Fedora No fix yet Fix from $1,9502021-02-10 HIGH 7.5 CVE-2020-13574 A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead … Fedora No fix yet Fix from $1,9502021-02-10 HIGH 7.5 CVE-2020-13575 A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lea… Fedora No fix yet Fix from $1,9502021-02-10 HIGH 7.5 CVE-2020-13577 A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead … Fedora No fix yet Fix from $1,9502021-02-10 MEDIUM 6.5 CVE-2020-36148 Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentatio… Fedora after 1.1 Fix from $1,6002021-02-08 MEDIUM 6.5 CVE-2020-36149 Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentatio… Fedora after 1.1 Fix from $1,6002021-02-08 MEDIUM 5.5 CVE-2020-9453 In Epson iProjection v2.30, the driver file EMP_MPAU.sys allows local users to cause a denial of service (BSOD) or possibly have unspecified other im… Iprojection after 2.30 Fix from $1,6002021-02-05 MEDIUM 6.5 CVE-2019-25014 A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET … Openshift Service Mesh after 1.4.9 Fix from $1,6002021-01-29 HIGH 7.5 CVE-2020-13582 A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to de… Micrium Uc Http No fix yet Fix from $1,9502021-01-26 HIGH 7.5 CVE-2021-25903 An issue was discovered in the cache crate through 2021-01-01 for Rust. A raw pointer is dereferenced. Cache after 0.2.0 Fix from $1,9502021-01-26