CWE-822
242 CVEs • Abstraction: Base
Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
CVEs (242)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. |
1Ni 2Instrumentstudio Ni Grpc Device ServerJun 25, 2026 Jun 19, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution. S...Show more |
1Microsoft 6365 Apps Microsoft 365Office 2016+3 moreJul 9, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. |
1Microsoft 4365 Apps Microsoft 365Office 2021+1 moreJun 19, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 7365 Apps Microsoft 365Office 2019+4 moreJun 19, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 3Windows Server 2019 Windows Server 2022Windows Server 2025Jun 17, 2026 Jun 9, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally. |
IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial...Show more |
An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentia...Show more |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows 11 26h1+1 moreJun 26, 2026 May 12, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreJun 17, 2026 May 12, 2026 N/A· v4 8.4 HIGH· v3 N/A· v2 Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
Untrusted pointer dereference for some Intel(R) QuickAssist Adapter 8960 software before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authent...Show more |
1Qualcomm 20Fastconnect 6200 Firmware Fastconnect 6900 FirmwareFastconnect 7800 Firmware+17 moreJun 17, 2026 May 4, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when another driver calls an IOCTL with invalid input/output buffer. |
1Qualcomm 16Fastconnect 6900 Firmware Fastconnect 7800 FirmwareIqx5121 Firmware+13 moreJun 17, 2026 May 4, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption when processing camera sensor input/output control codes with invalid output buffers. |
1Microsoft 5Sql Server 2016 Sql Server 2017Sql Server 2019+2 moreJul 24, 2026 Apr 14, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. |
1Microsoft 2365 Apps Office Long Term Servicing ChannelJul 24, 2026 Apr 14, 2026 N/A· v4 8.4 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows 11 26h1+1 moreJul 25, 2026 Apr 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 Apr 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 Apr 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 Apr 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. |
1Microsoft 11Windows 10 1809 Windows 10 21h2Windows 10 22h2+8 moreJun 17, 2026 Apr 14, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |