CWE-822
242 CVEs • Abstraction: Base
Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
CVEs (242)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qualcomm 18Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQcc2072 Firmware+15 moreJun 17, 2026 Oct 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing escape commands from userspace. |
1Qualcomm 25Immersive Home 214 Platform Firmware Immersive Home 216 Platform FirmwareImmersive Home 316 Platform Firmware+22 moreJun 17, 2026 Oct 9, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Memory corruption while performing SCM call with malformed inputs. |
1Qualcomm 18Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQcc2072 Firmware+15 moreJun 17, 2026 Oct 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing camera platform driver IOCTL calls. |
Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.10, from 6.1....Show more |
Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.2.0 before 7.3.0.9. |
1Bytecodealliance 1Webassembly Micro Runtime Jun 17, 2026 Sep 16, 2025 2.1 LOW· v4 5.3 MEDIUM· v3 N/A· v2 WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2, when running in LLVM-JIT mode, the runtime cannot exit normally when executing WebAssembly program...Show more |
1Microsoft 6365 Apps OfficeOffice Long Term Servicing Channel+3 moreJun 17, 2026 Sep 9, 2025 N/A· v4 7.1 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
1Microsoft 10Windows 10 1607 Windows 10 21h2Windows 10 22h2+7 moreJun 17, 2026 Sep 9, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. |
1Microsoft 11Windows 10 1507 Windows 10 1607Windows 10 1809+8 moreJun 17, 2026 Sep 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally. |
Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary writes or denial of service. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Aug 21, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. |
1Microsoft 2Windows 11 24h2 Windows Server 2025Jun 17, 2026 Aug 12, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
1Intel 1Quickassist Technology Jun 17, 2026 Aug 12, 2025 6.8 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 Untrusted Pointer Dereference for some Intel(R) QuickAssist Technology software before version 2.5.0 may allow an authenticated user to potentially enable denial of service via local access. |
1Qualcomm 8Fastconnect 6900 Firmware Fastconnect 7800 FirmwareSc8380xp Firmware+5 moreJun 17, 2026 Aug 6, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing DDI command calls. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Jul 8, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Jul 8, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Jul 8, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJun 17, 2026 Jul 8, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. |
1Qualcomm 31Fastconnect 6900 Firmware Fastconnect 7800 FirmwareQmp1000 Firmware+28 moreJun 17, 2026 Jun 3, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption during dynamic process creation call when client is only passing address and length of shell binary. |
Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access. |