Vulnerability index

Browse CVEs

164 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Debian Linux CRITICAL 9.8
CVE-2018-5206

When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.

Fix: 1.0.6+
Fix from $2,300 2018-01-06
Debian Linux MEDIUM 6.5
CVE-2017-1000445

ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore component and might lead to denial of service

Fix: 6.9.9-15+
Fix from $1,600 2018-01-02
Debian Linux MEDIUM 5.5
CVE-2017-18005

Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a TIFF file.

No fix yet
Fix from $1,600 2017-12-31
Debian Linux HIGH 7.5
CVE-2017-17439

In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for c…

Fix: after 7.4.0
Fix from $1,950 2017-12-06
Debian Linux HIGH 7.5
CVE-2017-8820

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers…

Fix: 0.2.5.16 / 0.2.8.17+
Fix from $1,950 2017-12-03
Debian Linux MEDIUM 5.5
CVE-2017-15955

bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to an "Access violation near NULL on destination operand" and crash when processing a ma…

Patch available
Fix from $1,600 2017-10-28
Debian Linux HIGH 8.8
CVE-2017-15930

In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelP…

Patch available
Fix from $1,950 2017-10-27
Debian Linux HIGH 7.5
CVE-2017-15721

In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. This is a separate, but similar, issue…

Fix: after 1.0.4
Fix from $1,950 2017-10-22
Debian Linux HIGH 7.5
CVE-2017-15723

In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message.

Fix: after 1.0.4
Fix from $1,950 2017-10-22
Debian Linux HIGH 8.8
CVE-2017-15565

In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.

No fix yet
Fix from $1,950 2017-10-17
Debian Linux MEDIUM 6.5
CVE-2017-14994

ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted D…

Patch available
Fix from $1,600 2017-10-04
Debian Linux HIGH 7.5
CVE-2017-14975

The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is n…

No fix yet
Fix from $1,950 2017-10-02
Debian Linux HIGH 7.5
CVE-2017-14977

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of…

No fix yet
Fix from $1,950 2017-10-02
Debian Linux MEDIUM 5.5
CVE-2017-14926

In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document.

Mitigation only
Fix from $1,600 2017-09-30
Debian Linux MEDIUM 5.5
CVE-2017-14928

In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document.

Mitigation only
Fix from $1,600 2017-09-30
Debian Linux MEDIUM 6.5
CVE-2017-14504

ReadPNMImage in coders/pnm.c in GraphicsMagick 1.3.26 does not ensure the correct number of colors for the XV 332 format, leading to a NULL Pointer D…

Patch available
Fix from $1,600 2017-09-17
Debian Linux MEDIUM 5.5
CVE-2017-14121

The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a craf…

Mitigation only
Fix from $1,600 2017-09-03
Debian Linux MEDIUM 6.5
CVE-2017-13768

Null Pointer Dereference in the IdentifyImage function in MagickCore/identify.c in ImageMagick through 7.0.6-10 allows an attacker to perform denial …

Fix: 6.9.9-11+
Fix from $1,600 2017-08-30
Debian Linux MEDIUM 6.5
CVE-2017-12809

QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privileged users to cause a denial of …

Fix: after 2.9.1
Fix from $1,600 2017-08-23
Debian Linux MEDIUM 6.5
CVE-2017-13065

GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c.

Mitigation only
Fix from $1,600 2017-08-22
Debian Linux MEDIUM 5.5
CVE-2017-11733

A null pointer dereference vulnerability was found in the function stackswap (called from decompileSTACKSWAP) in util/decompile.c in Ming 0.4.8, whic…

Mitigation only
Fix from $1,600 2017-07-29
Debian Linux MEDIUM 6.5
CVE-2017-9988

The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NUL…

No fix yet
Fix from $1,600 2017-06-28
Debian Linux MEDIUM 6.5
CVE-2017-9989

util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) at…

No fix yet
Fix from $1,600 2017-06-28
Debian Linux MEDIUM 5.5
CVE-2017-9503

QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a…

Fix: after 2.9.1
Fix from $1,600 2017-06-16
Debian Linux HIGH 7.5
CVE-2017-9468

In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can…

Fix: after 1.0.2
Fix from $1,950 2017-06-07
Debian Linux MEDIUM 6.5
CVE-2017-9216

libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_h…

Patch available
Fix from $1,600 2017-05-24
Debian Linux HIGH 7.5
CVE-2017-5193EPSS 6%

The nickcmp function in Irssi before 0.8.21 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a message w…

Fix: 0.8.21+
Fix from $1,950 2017-03-03
Debian Linux MEDIUM 6.5
CVE-2016-9559

coders/tiff.c in ImageMagick before 7.0.3.7 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted i…

Fix: 6.9.6-5 / 7.0.3-7+
Fix from $1,600 2017-03-01
Debian Linux HIGH 7.8
CVE-2017-6298

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "1 of 9. Null Pointer Deref / calloc return value not checked."

Fix: after 1.9
Fix from $1,950 2017-02-24
Debian Linux HIGH 7.5
CVE-2017-5991EPSS 15%

An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a N…

Fix: 1.11+
Fix from $1,950 2017-02-15