CWE-822
242 CVEs • Abstraction: Base
Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
CVEs (242)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Apr 14, 2026 N/A· v4 5.7 MEDIUM· v3 N/A· v2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreJun 17, 2026 Mar 10, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. |
1Microsoft 5365 Apps ExcelOffice+2 moreJun 17, 2026 Mar 10, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter values from its own memory space allowing an attacker to infer the contents of the kernel memory leading...Show more |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows Server 2022 23h2+1 moreJun 17, 2026 Feb 10, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
1Microsoft 5Windows 11 23h2 Windows 11 24h2Windows 11 25h2+2 moreJun 17, 2026 Feb 10, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. |
1Juniper 2Junos Junos Os EvolvedJun 17, 2026 Jan 15, 2026 6.8 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Servic...Show more |
1Microsoft 2365 Apps Office Long Term Servicing ChannelJun 17, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreJun 17, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreJun 17, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 10Windows 10 1607 Windows 10 1809Windows 10 21h2+7 moreJul 30, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
1Microsoft 3Windows 11 23h2 Windows 11 24h2Windows 11 25h2Jul 30, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. |
1Microsoft 3Windows 11 23h2 Windows 11 24h2Windows 11 25h2Jul 30, 2026 Jan 13, 2026 N/A· v4 6.2 MEDIUM· v3 N/A· v2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally. |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreJul 30, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
1Microsoft 3Windows 11 23h2 Windows 11 24h2Windows 11 25h2Jul 30, 2026 Jan 13, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. |
1Microsoft 6Windows 11 23h2 Windows 11 24h2Windows 11 25h2+3 moreJul 30, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
1Qualcomm 14Fastconnect 7800 Firmware Qcc2072 FirmwareWcd9378c Firmware+11 moreJun 17, 2026 Jan 7, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while preprocessing IOCTLs in sensors. |
1Qualcomm 25Cologne Firmware Fastconnect 6700 FirmwareFastconnect 6900 Firmware+22 moreJun 17, 2026 Jan 7, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption while processing a video session to set video parameters. |
1Samsung 6Exynos 1330 Firmware Exynos 1380 FirmwareExynos 1480 Firmware+3 moreJun 17, 2026 Jan 5, 2026 N/A· v4 6.2 MEDIUM· v3 N/A· v2 An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. An invalid kernel address dereference in the issimian device driver leads to a denial of...Show more |
1Qualcomm 45Aqt1000 Firmware Fastconnect 6200 FirmwareFastconnect 6700 Firmware+42 moreJun 17, 2026 Dec 18, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption when processing IOCTLs for JPEG data without verification. |