CWE-822
212 CVEs • Abstraction: Base
Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
CVEs (212)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via...Show more |
Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim...Show more |
1Microsoft 7365 Apps ExcelMicrosoft 365+4 moreJul 15, 2026 Jul 14, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
1Microsoft 7365 Apps ExcelMicrosoft 365+4 moreJul 15, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
1Microsoft 6Windows 10 1809 Windows 10 21h2Windows 10 22h2+3 moreJul 21, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally. |
1Microsoft 11Windows 10 1607 Windows 10 1809Windows 10 21h2+8 moreJul 22, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows 11 26h1+1 moreJul 22, 2026 Jul 14, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network. |
1Microsoft 9Windows 10 1809 Windows 10 21h2Windows 10 22h2+6 moreJul 22, 2026 Jul 14, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. |
1Microsoft 9Windows 10 1809 Windows 10 21h2Windows 10 22h2+6 moreJul 22, 2026 Jul 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |
1Microsoft 7365 Apps ExcelMicrosoft 365+4 moreJul 15, 2026 Jul 14, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. |
1Ni 2Instrumentstudio Ni Grpc Device ServerJun 25, 2026 Jun 19, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution. S...Show more |
1Microsoft 6365 Apps Microsoft 365Office 2016+3 moreJul 9, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. |
1Microsoft 4365 Apps Microsoft 365Office 2021+1 moreJun 19, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 7365 Apps Microsoft 365Office 2019+4 moreJun 19, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 3Windows Server 2019 Windows Server 2022Windows Server 2025Jun 17, 2026 Jun 9, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally. |
IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial...Show more |
An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentia...Show more |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows 11 26h1+1 moreJun 26, 2026 May 12, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreJun 17, 2026 May 12, 2026 N/A· v4 8.4 HIGH· v3 N/A· v2 Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |