CWE-822
212 CVEs • Abstraction: Base
Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
CVEs (212)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
GE CIMPICITY versions 2022 and prior is
vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code.
|
Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. The controls may allow seven untrusted pointer deference instances while processing a specific project file. |
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execute low-privileged code on the t...Show more |
4Cisco ClamavDebian+1 more4Clamav Debian LinuxFedora+1 moreJun 17, 2026 May 4, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1...Show more |
1Codesys 20Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.1 HIGH· v3 4.9 MEDIUM· v2 An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither g...Show more |
1Fujielectric 2V Server V SimulatorJun 17, 2026 Dec 20, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an untrusted pointer dereference, which may allow an attacker to execute arbitrary code and cause the application to crash. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.3.84 (package 16.6.3.134). User interaction is required to exploit this vulnerability i...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visi...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visi...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 May 28, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vuln...Show more |
3Datakit LuxionSiemens4Crosscadware KeyshotSolid Edge Se2020 Firmware+1 moreJun 17, 2026 May 27, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied data when parsing PRT files. This could...Show more |
1Siemens 2Solid Edge Se2020 Solid Edge Se2021Jun 17, 2026 Apr 22, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2020 (All versions < SE2020MP14), Solid Edge SE2021 (All Versions < SE2021MP4). Affected applications lack proper validat...Show more |
The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arbitrary memory addresses to be accessed as if they were static StringData object...Show more |
2Luxion Siemens6Keyshot Keyshot Network RenderingKeyshot Viewer+3 moreJun 17, 2026 Feb 23, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 have multiple NULL pointer dereference...Show more |
1Siemens 2Jt2go Teamcenter VisualizationJun 17, 2026 Feb 9, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing TIFF files. Th...Show more |
1Omron 4Cx One Cx PositionCx Protocol+1 moreJun 17, 2026 Feb 9, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code. |
An untrusted pointer dereference has been identified in the way TPEditor(v1.98 and prior) processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution. |
1Siemens 2Jt2go Teamcenter VisualizationJun 17, 2026 Jan 12, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2). Affected applications lack proper validation of user-supplied data when parsing ASM files. Thi...Show more |
Delta Electronics CNCSoft-B Versions 1.0.0.2 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code. |
Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code. |