CWE-822
242 CVEs • Abstraction: Base
Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
CVEs (242)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Nvidia 3Cloud Gaming Gpu Display DriverVirtual GpuJun 17, 2026 Jun 23, 2023 N/A· v4 7.6 HIGH· v3 N/A· v2 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where unexpected untrusted data is parsed, which may lead to code execution, denial of service, escalation of privileges, data tampering, or inf...Show more |
1Microsoft 9Windows 10 1607 Windows 10 1809Windows 10 21h2+6 moreJun 17, 2026 Jun 14, 2023 N/A· v4 8.4 HIGH· v3 N/A· v2 Microsoft Streaming Service Elevation of Privilege Vulnerability |
1Qualcomm 110Csra6620 Firmware Csra6640 FirmwareFlight Rb5 5g Platform Firmware+107 moreJun 17, 2026 Jun 6, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request. |
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler which may lead to denial of service, escalation of privileges, information disclosure, and data tampering. |
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Mar 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious p...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious p...Show more |
1Microsoft 2Windows 11 Windows Server 2022Jun 17, 2026 Jan 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
1Microsoft 11Windows 10 1607 Windows 10 1809Windows 10 20h2+8 moreJun 17, 2026 Jan 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability |
GE CIMPICITY versions 2022 and prior is
vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code.
|
Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. The controls may allow seven untrusted pointer deference instances while processing a specific project file. |
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execute low-privileged code on the t...Show more |
4Cisco ClamavDebian+1 more4Clamav Debian LinuxFedora+1 moreJun 17, 2026 May 4, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1...Show more |
1Codesys 20Control For Beaglebone Sl Control For Beckhoff Cx9020Control For Empc A/imx6 Sl+17 moreJun 17, 2026 Apr 7, 2022 N/A· v4 7.1 HIGH· v3 4.9 MEDIUM· v2 An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither g...Show more |
1Fujielectric 2V Server V SimulatorJun 17, 2026 Dec 20, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an untrusted pointer dereference, which may allow an attacker to execute arbitrary code and cause the application to crash. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.3.84 (package 16.6.3.134). User interaction is required to exploit this vulnerability i...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visi...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visi...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 May 28, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vuln...Show more |