CWE-822

Untrusted Pointer Dereference

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

200 vulnerabilities with CWE-822
CVE-2024-43553 HIGH
NT OS Kernel - Privilege Escalation
CVSS 7.4
CVE-2024-43529 HIGH
Windows Print Spooler - Privilege Escalation
CVSS 7.3
CVE-2024-43516 HIGH
Windows Secure Kernel Mode - Privilege Escalation
CVSS 7.8
CVE-2024-37983 MEDIUM
Windows Resume Extensible Firmware Interface - Privilege Escalation
CVSS 6.7
CVE-2024-37982 MEDIUM
Windows Resume Extensible Firmware Interface - Privilege Escalation
CVSS 6.7
CVE-2024-37979 MEDIUM
Windows Kernel - Privilege Escalation
CVSS 6.7
CVE-2024-21455 HIGH
Qualcomm IOCTL Calls Firmware - Memory Corruption
CVSS 7.8
CVE-2024-37340 HIGH
Microsoft SQL Server 2016-2022 - Remote Code Execution via Native Scoring
CVSS 8.8
CVE-2024-37339 HIGH
Microsoft SQL Server 2016-2022 - Remote Code Execution via Native Scoring
CVSS 8.8
CVE-2024-33038 HIGH
Qualcomm Fastconnect 6700 Firmware - Out-of-Bounds Write
CVSS 7.8
CVE-2024-38187 HIGH
Windows Kernel-Mode Driver - Privilege Escalation
CVSS 7.8
CVE-2024-38185 HIGH
Windows Kernel-Mode Driver - Privilege Escalation
CVSS 7.8
CVE-2024-36461 CRITICAL
Zabbix 6.0.0-6.0.29 - Untrusted Pointer Dereference in JavaScript Engine
CVSS 9.1
CVE-2024-40872 HIGH
Absolute Secure Access <13.07 - Privilege Escalation
CVSS 8.4
CVE-2024-38104 HIGH
Windows Fax Service - Remote Code Execution
CVSS 8.8
CVE-2024-37969 HIGH
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2012-2022 - Secure Boot Security Feature Bypass
CVSS 8.0
CVE-2024-0091 HIGH
NVIDIA GPU Display Driver 550-552.55, 550-550.90.07 - Untrusted Pointer Dereference via Driver API
CVSS 7.8
CVE-2024-35250 HIGH KEV
Windows Kernel-Mode Driver - Privilege Escalation
CVSS 7.8
CVE-2024-30090 HIGH
Microsoft Streaming Service - Privilege Escalation
CVSS 7.0
CVE-2024-27353 HIGH
InsydeH2O <5.6 - Privilege Escalation
CVSS 7.4
CVE-2024-25078 HIGH
Insyde InsydeH2O < 5.29.07 - Untrusted Pointer Dereference in StorageSecurityCommandDxe
CVSS 7.4
CVE-2024-26254 HIGH
Windows 10 1809/21H2/22H2, Windows 11 21H2/22H2/23H2, Windows Server 2019/2022/2022 23H2 - Denial of Service via VMBus
CVSS 7.5
CVE-2024-26252 MEDIUM
Windows rndismp6.sys - Remote Code Execution via Untrusted Pointer Dereference
CVSS 6.8
CVE-2024-26213 HIGH
Windows Server 2022 23H2 < 10.0.25398.830 - Elevation of Privilege via Brokering File System
CVSS 7.0
CVE-2024-23136 HIGH
Autodesk AutoCAD and Related Products 2021-<2021.1.4 - Untrusted Pointer Dereference in ASMKERN228A.dll
CVSS 7.8
Details
Vulnerabilities 200