Vulnerabilities > NULL Pointer Dereference

DATE CVE VULNERABILITY TITLE RISK
2017-06-28 CVE-2017-9989 NULL Pointer Dereference vulnerability in multiple products
util/outputtxt.c in libming 0.4.8 mishandles memory allocation.
network
low complexity
libming debian CWE-476
6.5
2017-06-28 CVE-2017-9988 NULL Pointer Dereference vulnerability in multiple products
The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation.
network
low complexity
libming debian CWE-476
6.5
2017-06-27 CVE-2015-5180 NULL Pointer Dereference vulnerability in multiple products
res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).
network
low complexity
canonical gnu CWE-476
7.5
2017-06-27 CVE-2017-7522 NULL Pointer Dereference vulnerability in Openvpn
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.
network
low complexity
openvpn CWE-476
6.5
2017-06-26 CVE-2017-7458 NULL Pointer Dereference vulnerability in Ntop Ntopng
The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty field that should have contained a hostname or IP address.
network
low complexity
ntop CWE-476
7.5
2017-06-25 CVE-2015-9100 NULL Pointer Dereference vulnerability in Lame Project Lame 3.99.5
The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.
local
low complexity
lame-project CWE-476
5.5
2017-06-20 CVE-2017-3169 NULL Pointer Dereference vulnerability in Apache Http Server
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.
network
low complexity
apache CWE-476
critical
9.8
2017-06-16 CVE-2017-9503 NULL Pointer Dereference vulnerability in multiple products
QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas command processing.
local
low complexity
qemu debian CWE-476
5.5
2017-06-16 CVE-2017-7507 NULL Pointer Dereference vulnerability in GNU Gnutls
GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents.
network
low complexity
gnu CWE-476
7.5
2017-06-16 CVE-2017-6899 NULL Pointer Dereference vulnerability in Lineageos
The msm_bus_dbg_update_request_write function in drivers/platform/msm/msm_bus/msm_bus_dbg.c in android_kernel_huawei_msm8916 through 2017-06-16 in LineageOS, and possibly other kernels for MSM devices, allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted /sys/kernel/debug/msm-bus-dbg/client-data/update-request write request.
local
low complexity
lineageos CWE-476
6.2