Vulnerability index

Browse CVEs

164 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Debian Linux HIGH 7.5
CVE-2022-39028

telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In…

Fix: after 2.3
Fix from $1,950 2022-08-30
Debian Linux MEDIUM 5.5
CVE-2022-30975

In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.

Fix: after 1.2.0
Fix from $1,600 2022-05-18
Debian Linux MEDIUM 5.5
CVE-2021-42528

XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated a…

Fix: after 2021.07
Fix from $1,600 2022-05-02
Debian Linux HIGH 7.5
CVE-2021-20299

A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer der…

Fix: 2.5.4+
Fix from $1,950 2022-03-16
Debian Linux MEDIUM 5.5
CVE-2022-0908

Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could le…

Fix: after 4.3.0
Fix from $1,600 2022-03-11
Debian Linux MEDIUM 5.5
CVE-2021-4043

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.

Fix: 1.1.0+
Fix from $1,600 2022-02-04
Debian Linux CRITICAL 9.1
CVE-2021-45079

In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the ca…

Fix: 5.9.5+
Fix from $2,300 2022-01-31
Debian Linux MEDIUM 5.5
CVE-2021-22570

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file…

Fix: 3.15.0+
Fix from $1,600 2022-01-26
Debian Linux MEDIUM 6.1
CVE-2021-40732

XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memor…

Fix: after 2020.1
Fix from $1,600 2021-10-13
Debian Linux MEDIUM 6.5
CVE-2021-3671

A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authen…

Fix: 4.13.12 / 4.14.8+
Fix from $1,600 2021-10-12
Debian Linux MEDIUM 5.5
CVE-2021-32276

An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located in output.c. It allows an att…

Fix: after 2.10.0
Fix from $1,600 2021-09-20
Debian Linux MEDIUM 5.5
CVE-2021-32280

An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c…

Fix: 3.2.8+
Fix from $1,600 2021-09-20
Debian Linux HIGH 7.8
CVE-2021-39251

A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.5
CVE-2021-36222EPSS 10%

ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows rem…

Fix: 1.18.4 / 1.19.2+
Fix from $1,950 2021-07-22
Debian Linux MEDIUM 5.5
CVE-2021-27345

A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a c…

Patch available
Fix from $1,600 2021-06-10
Debian Linux MEDIUM 5.5
CVE-2020-25467

A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) v…

Patch available
Fix from $1,600 2021-06-10
Debian Linux MEDIUM 6.5
CVE-2019-12067

The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_…

Patch available
Fix from $1,600 2021-06-02
Debian Linux MEDIUM 6.5
CVE-2021-20196

A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commands if the s…

Patch available
Fix from $1,600 2021-05-26
Debian Linux HIGH 7.5
CVE-2020-20450

FFmpeg 4.2 is affected by null pointer dereference passed as argument to libavformat/aviobuf.c, which could cause a Denial of Service.

Mitigation only
Fix from $1,950 2021-05-25
Debian Linux MEDIUM 6.5
CVE-2021-30485

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd(), while parsing a crafted XML file, performs incorrect memory …

Patch available
Fix from $1,600 2021-04-11
Debian Linux MEDIUM 5.3
CVE-2021-20296

A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression f…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-04-01
Debian Linux MEDIUM 6.0
CVE-2020-29484

An issue was discovered in Xen through 4.14.x. When a Xenstore watch fires, the xenstore client that registered the watch will receive a Xenstore mes…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 6.2
CVE-2020-29571

An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time functions specific to FIFO event channels depends on the …

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Debian Linux MEDIUM 5.5
CVE-2020-16588

A Null Pointer Deference issue exists in Academy Software Foundation OpenEXR 2.3.0 in generatePreview in makePreview.cpp that can cause a denial of s…

Patch available
Fix from $1,600 2020-12-09
Debian Linux MEDIUM 6.5
CVE-2019-20917

An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against maria…

Fix: 2.0.28 / 3.3.0+
Fix from $1,600 2020-09-11
Debian Linux MEDIUM 5.5
CVE-2020-16306

A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of se…

No fix yet
Fix from $1,600 2020-08-13
Debian Linux MEDIUM 5.5
CVE-2020-16307

A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker…

No fix yet
Fix from $1,600 2020-08-13
Debian Linux MEDIUM 5.5
CVE-2020-16293

A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex Software GhostS…

Fix: 9.52+
Fix from $1,600 2020-08-13
Debian Linux MEDIUM 5.5
CVE-2020-16295

A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to c…

Fix: 9.52+
Fix from $1,600 2020-08-13
Debian Linux MEDIUM 5.9
CVE-2020-16135

libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.

Patch available
Fix from $1,600 2020-07-29