Vulnerability index

Browse CVEs

51 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Directory Server HIGH 7.5
CVE-2026-11788

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing…

Mitigation only
Fix from $1,950 2026-06-09
Hardened Images MEDIUM 5.0
CVE-2026-6845

A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS…

Mitigation only
Fix from $1,600 2026-04-22
Hardened Images HIGH 7.5
CVE-2026-1584

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with…

Mitigation only
Fix from $1,950 2026-04-09
Hardened Images MEDIUM 5.5
CVE-2026-5745

A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_te…

Mitigation only
Fix from $1,600 2026-04-07
Enterprise Linux MEDIUM 6.5
CVE-2025-4478

A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue …

Fix: 3.16.0+
Fix from $1,600 2025-05-16
Enterprise Linux MEDIUM 5.5
CVE-2025-46399

A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function.

No fix yet
Fix from $1,600 2025-04-23
Enterprise Linux MEDIUM 5.5
CVE-2025-46400

In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobje…

No fix yet
Fix from $1,600 2025-04-23
Libvirt MEDIUM 6.2
CVE-2024-8235

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where all…

Fix: 10.7.0+
Fix from $1,600 2024-08-30
Enterprise Linux HIGH 7.5
CVE-2024-7006

A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures thro…

Fix: after 4.6.0
Fix from $1,950 2024-08-12
Libvirt MEDIUM 5.5
CVE-2024-2496

A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host inter…

Fix: 9.8.0+
Fix from $1,600 2024-03-18
Codeready Linux Builder Eus HIGH 7.5
CVE-2023-6356

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages whe…

Mitigation only
Fix from $1,950 2024-02-07
Shim MEDIUM 5.5
CVE-2023-40546

A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an err…

Fix: 15.8+
Fix from $1,600 2024-01-29
Enterprise Linux MEDIUM 6.5
CVE-2023-6683

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before…

Fix: 8.2.2+
Fix from $1,600 2024-01-12
Openstack Platform HIGH 7.5
CVE-2023-3354

A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections cro…

Fix: 8.1.0+
Fix from $1,950 2023-07-11
Enterprise Linux HIGH 7.5
CVE-2023-2953

A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

Fix: 11.7.9 / 12.6.8+
Fix from $1,950 2023-05-30
Directory Server MEDIUM 6.5
CVE-2022-2850

A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using…

Fix: after 2.4.1
Fix from $1,600 2022-10-14
Enterprise Linux MEDIUM 5.5
CVE-2022-25310

A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. Thi…

Fix: 1.0.12+
Fix from $1,600 2022-09-06
Enterprise Linux MEDIUM 6.5
CVE-2021-4209

A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause …

Fix: 3.7.3+
Fix from $1,600 2022-08-24
Enterprise Linux MEDIUM 6.0
CVE-2021-4158

A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the Q…

Fix: 7.0.0+
Fix from $1,600 2022-08-24
Enterprise Linux MEDIUM 6.5
CVE-2021-3596

A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not c…

Fix: 7.0.10-31+
Fix from $1,600 2022-02-24
Enterprise Linux MEDIUM 5.5
CVE-2022-0561

Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 …

Fix: after 4.3.0
Fix from $1,600 2022-02-11
Enterprise Linux MEDIUM 6.5
CVE-2021-4145

A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror…

Patch available
Fix from $1,600 2022-01-25
Enterprise Linux MEDIUM 6.7
CVE-2021-3543

A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descri…

Fix: 5.10.0+
Fix from $1,600 2021-06-01
389 Directory Server MEDIUM 6.5
CVE-2021-3514

When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing…

Mitigation only
Fix from $1,600 2021-05-28
Enterprise Linux HIGH 7.8
CVE-2021-30500

Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary c…

Patch available
Fix from $1,950 2021-05-27
Jboss Core Services MEDIUM 5.9
CVE-2021-3537

A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL der…

Fix: 2.9.11+
Fix from $1,600 2021-05-14
Enterprise Linux MEDIUM 5.5
CVE-2021-3443

A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A sp…

Fix: 2.0.27+
Fix from $1,600 2021-03-25
Openshift Service Mesh MEDIUM 6.5
CVE-2019-25014

A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET …

Fix: after 1.4.9
Fix from $1,600 2021-01-29
Enterprise Linux MEDIUM 5.5
CVE-2020-35507

There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit…

Fix: 2.34+
Fix from $1,600 2021-01-04
Enterprise Linux HIGH 7.5
CVE-2020-25692

A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated atta…

Fix: 2.4.55+
Fix from $1,950 2020-12-08