← Back
CWE-822

242 CVEs • Abstraction: Base

Untrusted Pointer Dereference

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

JSON object

Loading...

CVEs (242)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
5365 Apps
ExcelOffice+2 more
Jun 17, 2026
May 13, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
1Microsoft
6Windows 11 22h2
Windows 11 23h2Windows 11 24h2+3 more
Jun 17, 2026
Apr 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.
1Microsoft
6365 Apps
OfficeOffice Long Term Servicing Channel+3 more
Jun 17, 2026
Apr 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
1Microsoft
10Windows 10 1809
Windows 10 21h2Windows 10 22h2+7 more
Jun 17, 2026
Apr 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Apr 8, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-se...Show more
An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition.Show less
1Microsoft
6Windows 11 22h2
Windows 11 23h2Windows 11 24h2+3 more
Jun 17, 2026
Mar 11, 2025
N/A· v4
8.4 HIGH· v3
N/A· v2
Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.
1Microsoft
3365 Apps
OfficeOffice Long Term Servicing Channel
Jun 17, 2026
Mar 11, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
-
-
Jun 17, 2026
Mar 7, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger a crash of the FW running on the GPU freezing graphics output.
1Qualcomm
8Fastconnect 6900 Firmware
Fastconnect 7800 FirmwareSc8380xp Firmware+5 more
Jun 17, 2026
Mar 3, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag reset.
1Qualcomm
8Fastconnect 6900 Firmware
Fastconnect 7800 FirmwareSc8380xp Firmware+5 more
Jun 17, 2026
Mar 3, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address.
-
-
Jun 17, 2026
Feb 12, 2025
4.3 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Untrusted Pointer Dereference in I/O subsystem for some Intel(R) QAT software before version 2.0.5 may allow authenticated user to potentially enable information disclosure via local operating system access.
1Microsoft
5365 Apps
ExcelOffice+2 more
Jun 17, 2026
Feb 11, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Excel Remote Code Execution Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jun 17, 2026
Feb 11, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Core Messaging Elevation of Privileges Vulnerability
1Qualcomm
122Ar8035 Firmware
Fastconnect 6200 FirmwareFastconnect 6900 Firmware+119 more
Jun 17, 2026
Feb 3, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace.
1Microsoft
2365 Apps
Office Long Term Servicing Channel
Jun 17, 2026
Jan 14, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Word Remote Code Execution Vulnerability
1Microsoft
4365 Apps
OfficeOffice Long Term Servicing Channel+1 more
Jun 17, 2026
Jan 14, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Excel Remote Code Execution Vulnerability
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Jun 17, 2026
Dec 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Common Log File System Driver Elevation of Privilege Vulnerability
1Qualcomm
22Qam8255p Firmware
Qam8650p FirmwareQam8775p Firmware+19 more
Jun 17, 2026
Dec 2, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.
-
-
Jun 17, 2026
Nov 13, 2024
6.9 MEDIUM· v4
8.4 HIGH· v3
N/A· v2
Untrusted pointer dereference in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.
1Microsoft
12Windows 10 1607
Windows 10 1809Windows 10 21h2+9 more
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Secure Kernel Mode Elevation of Privilege Vulnerability