Vulnerabilities > NULL Pointer Dereference

DATE CVE VULNERABILITY TITLE RISK
2017-09-12 CVE-2017-14400 NULL Pointer Dereference vulnerability in Imagemagick 7.0.71
In ImageMagick 7.0.7-1 Q16, the PersistPixelCache function in magick/cache.c mishandles the pixel cache nexus, which allows remote attackers to cause a denial of service (NULL pointer dereference in the function GetVirtualPixels in MagickCore/cache.c) via a crafted file.
network
low complexity
imagemagick CWE-476
6.5
2017-09-12 CVE-2017-14318 NULL Pointer Dereference vulnerability in XEN
An issue was discovered in Xen 4.5.x through 4.9.x.
local
low complexity
xen CWE-476
6.5
2017-09-09 CVE-2017-14228 NULL Pointer Dereference vulnerability in multiple products
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function paste_tokens() in preproc.c, aka a NULL pointer dereference.
local
low complexity
nasm canonical CWE-476
5.5
2017-09-09 CVE-2017-14225 NULL Pointer Dereference vulnerability in Ffmpeg 3.3.3
The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, leading to a NULL pointer dereference.
network
low complexity
ffmpeg CWE-476
8.8
2017-09-07 CVE-2017-14181 NULL Pointer Dereference vulnerability in Aacplusenc Project Aacplusenc 0.17.5
DeleteBitBuffer in libbitbuf/bitbuffer.c in mp4tools aacplusenc 0.17.5 allows remote attackers to cause a denial of service (invalid memory write, SEGV on unknown address 0x000000000030, and application crash) or possibly have unspecified other impact via a crafted .wav file, aka a NULL pointer dereference.
local
low complexity
aacplusenc-project CWE-476
7.8
2017-09-06 CVE-2017-12476 NULL Pointer Dereference vulnerability in Bento4
The AP4_AvccAtom::InspectFields function in Core/Ap4AvccAtom.cpp in Bento4 mp4dump before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.
local
low complexity
bento4 CWE-476
5.5
2017-09-06 CVE-2017-12475 NULL Pointer Dereference vulnerability in Axiosys Bento4
The AP4_Processor::Process function in Core/Ap4Processor.cpp in Bento4 mp4encrypt before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.
local
low complexity
axiosys CWE-476
5.5
2017-09-06 CVE-2017-12474 NULL Pointer Dereference vulnerability in Bento4
The AP4_AtomSampleTable::GetSample function in Core/Ap4AtomSampleTable.cpp in Bento4 mp42ts before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.
local
low complexity
bento4 CWE-476
5.5
2017-09-05 CVE-2017-14149 NULL Pointer Dereference vulnerability in Embedthis Goahead
GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request.
network
low complexity
embedthis CWE-476
7.5
2017-09-03 CVE-2017-14121 NULL Pointer Dereference vulnerability in multiple products
The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive.
local
low complexity
rarlab debian CWE-476
5.5