Vulnerabilities > NULL Pointer Dereference

DATE CVE VULNERABILITY TITLE RISK
2016-11-28 CVE-2016-9313 NULL Pointer Dereference vulnerability in Linux Kernel
security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly have unspecified other impact via a crafted application that uses the big_key data type.
local
low complexity
linux CWE-476
7.8
2016-11-28 CVE-2016-8646 NULL Pointer Dereference vulnerability in Linux Kernel
The hash_accept function in crypto/algif_hash.c in the Linux kernel before 4.3.6 allows local users to cause a denial of service (OOPS) by attempting to trigger use of in-kernel hash algorithms for a socket that has received zero bytes of data.
local
low complexity
linux CWE-476
5.5
2016-11-28 CVE-2016-8630 NULL Pointer Dereference vulnerability in Linux Kernel
The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel before 4.8.7, when KVM is enabled, allows local users to cause a denial of service (host OS crash) via a certain use of a ModR/M byte in an undefined instruction.
local
low complexity
linux CWE-476
5.5
2016-11-28 CVE-2015-8970 NULL Pointer Dereference vulnerability in Linux Kernel
crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted application that does not supply a key, related to the lrw_crypt function in crypto/lrw.c.
local
low complexity
linux CWE-476
5.5
2016-11-23 CVE-2016-9562 NULL Pointer Dereference vulnerability in SAP Netweaver 7.40
SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the sap.com~P4TunnelingApp!web/myServlet URI, aka SAP Security Note 2313835.
network
low complexity
sap CWE-476
5.0
2016-11-16 CVE-2016-7914 NULL Pointer Dereference vulnerability in Linux Kernel
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and out-of-bounds read) via an application that uses associative-array data structures, as demonstrated by the keyutils test suite.
network
linux CWE-476
7.1
2016-11-12 CVE-2016-9296 NULL Pointer Dereference vulnerability in 7-Zip P7Zip 16.02
A null pointer dereference bug affects the 16.02 and many old versions of p7zip.
network
low complexity
7-zip CWE-476
5.0
2016-11-12 CVE-2016-9294 NULL Pointer Dereference vulnerability in Artifex Mujs
Artifex Software, Inc.
network
low complexity
artifex CWE-476
7.5
2016-11-08 CVE-2016-4959 NULL Pointer Dereference vulnerability in Nvidia GPU Driver
For the NVIDIA Quadro, NVS, and GeForce products, there is a Remote Desktop denial of service.
network
low complexity
nvidia CWE-476
7.8
2016-11-03 CVE-2016-7160 NULL Pointer Dereference vulnerability in Samsung Mobile 6.0
A vulnerability on Samsung Mobile M(6.0) devices exists because external access to SystemUI activities is not properly restricted, leading to a SystemUI crash and device restart, aka SVE-2016-6248.
network
low complexity
samsung CWE-476
7.8