CWE-822

Untrusted Pointer Dereference

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

212 vulnerabilities with CWE-822
CVE-2024-12576 MEDIUM
Imagination Technologies Graphics DDK 1.15 RTM-24.2 RTM and >=25.1 RTM - Denial of Service via GPU System Calls
CVSS 5.5
CVE-2024-53034 HIGH
Qualcomm FastConnect 6900/7800, SC8380XP, WCD9380/9385, WSA8840/8845/8845H Firmware Memory Corruption
CVSS 7.8
CVE-2024-53033 HIGH
Qualcomm FastConnect and Related Firmware - Memory Corruption via Escape Call
CVSS 7.8
CVE-2024-45584 HIGH
Qualcomm FastConnect and AR8035/QAM8255P/QAM8295P Firmware - Memory Corruption
CVSS 7.8
CVE-2024-49090 HIGH
Windows Common Log File System Driver - Privilege Escalation
CVSS 7.8
CVE-2024-33039 MEDIUM
Qualcomm PAL Service Firmware - Memory Corruption
CVSS 6.7
CVE-2024-34023 HIGH
Intel(R) Graphics Drivers - Privilege Escalation
CVSS 8.4
CVE-2024-43646 MEDIUM
Windows Secure Kernel Mode - Privilege Escalation
CVSS 6.7
CVE-2024-43636 HIGH
Windows 10 1507-22H2 and Windows 11 22H2 - Elevation of Privilege via Win32k Untrusted Pointer Dereference
CVSS 7.8
CVE-2024-43631 MEDIUM
Windows Secure Kernel Mode - Privilege Escalation
CVSS 6.7
CVE-2024-43629 HIGH
Windows DWM Core Library - Privilege Escalation
CVSS 7.8
CVE-2024-43624 HIGH
Windows Hyper-V < - Privilege Escalation
CVSS 8.8
CVE-2024-43553 HIGH
NT OS Kernel - Privilege Escalation
CVSS 7.4
CVE-2024-43529 HIGH
Windows Print Spooler - Privilege Escalation
CVSS 7.3
CVE-2024-43516 HIGH
Windows Secure Kernel Mode - Privilege Escalation
CVSS 7.8
CVE-2024-37983 MEDIUM
Windows Resume Extensible Firmware Interface - Privilege Escalation
CVSS 6.7
CVE-2024-37982 MEDIUM
Windows Resume Extensible Firmware Interface - Privilege Escalation
CVSS 6.7
CVE-2024-37979 MEDIUM
Windows Kernel - Privilege Escalation
CVSS 6.7
CVE-2024-21455 HIGH
Qualcomm IOCTL Calls Firmware - Memory Corruption
CVSS 7.8
CVE-2024-37340 HIGH
Microsoft SQL Server 2016-2022 - Remote Code Execution via Native Scoring
CVSS 8.8
CVE-2024-37339 HIGH
Microsoft SQL Server 2016-2022 - Remote Code Execution via Native Scoring
CVSS 8.8
CVE-2024-33038 HIGH
Qualcomm Fastconnect 6700 Firmware - Out-of-Bounds Write
CVSS 7.8
CVE-2024-38187 HIGH
Windows Kernel-Mode Driver - Privilege Escalation
CVSS 7.8
CVE-2024-38185 HIGH
Windows Kernel-Mode Driver - Privilege Escalation
CVSS 7.8
CVE-2024-36461 CRITICAL
Zabbix 6.0.0-6.0.29 - Untrusted Pointer Dereference in JavaScript Engine
CVSS 9.1
Details
Vulnerabilities 212