← Back
CWE-822

242 CVEs • Abstraction: Base

Untrusted Pointer Dereference

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

JSON object

Loading...

CVEs (242)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Win32k Elevation of Privilege Vulnerability
1Microsoft
8Windows 10 21h2
Windows 10 22h2Windows 11 22h2+5 more
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
1Microsoft
10Windows 10 1809
Windows 10 21h2Windows 10 22h2+7 more
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows DWM Core Library Elevation of Privilege Vulnerability
1Microsoft
10Windows 10 1809
Windows 10 21h2Windows 10 22h2+7 more
Jun 17, 2026
Nov 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.0 HIGH· v3
N/A· v2
NT OS Kernel Elevation of Privilege Vulnerability
1Microsoft
8Windows 10 21h2
Windows 10 22h2Windows 11 21h2+5 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Windows Print Spooler Elevation of Privilege Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
1Microsoft
4Windows Server 2012
Windows Server 2016Windows Server 2019+1 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Kernel Elevation of Privilege Vulnerability
1Qualcomm
20Qam8295p Firmware
Qca6584au FirmwareQca6595 Firmware+17 more
Jun 17, 2026
Oct 7, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.
-
-
Jun 17, 2026
Sep 16, 2024
8.7 HIGH· v4
8.2 HIGH· v3
N/A· v2
Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to potentially enable escalation of privilege via local access.
1Microsoft
5Sql 2016 Azure Connect Feature Pack
Sql Server 2016Sql Server 2017+2 more
Aug 10, 2026
Sep 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
1Microsoft
5Sql 2016 Azure Connect Feature Pack
Sql Server 2016Sql Server 2017+2 more
Aug 10, 2026
Sep 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
1Qualcomm
43Fastconnect 6700 Firmware
Fastconnect 6900 FirmwareFastconnect 7800 Firmware+40 more
Jun 17, 2026
Sep 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
1Microsoft
11Windows 10 1607
Windows 10 1809Windows 10 21h2+8 more
Jun 17, 2026
Aug 13, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
1Microsoft
11Windows 10 1607
Windows 10 1809Windows 10 21h2+8 more
Jun 17, 2026
Aug 13, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
1Zabbix
1Zabbix
Jun 17, 2026
Aug 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
-
-
Jun 17, 2026
Jul 25, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
There is an elevation of privilege vulnerability in server and client components of Absolute Secure Access prior to version 13.07. Attackers with local access and valid desktop user credentials can elevate their privileg...Show more
There is an elevation of privilege vulnerability in server and client components of Absolute Secure Access prior to version 13.07. Attackers with local access and valid desktop user credentials can elevate their privilege to system level by passing invalid address data to the vulnerable component. This could be used to manipulate process tokens to elevate the privilege of a normal process to System. The scope is changed, the impact to system confidentiality and integrity is high, the impact to the availability of the effected component is none.Show less
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Jul 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Windows Fax Service Remote Code Execution Vulnerability