CWE-822

Untrusted Pointer Dereference

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

200 vulnerabilities with CWE-822
CVE-2024-21346 HIGH
Windows 11/Server 2022 Elevation of Privilege via Win32k Untrusted Pointer Dereference
CVSS 7.8
CVE-2024-21338 HIGH KEV
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2024-20682 HIGH
Microsoft Windows Cryptographic Services - Remote Code Execution
CVSS 7.8
CVE-2024-20680 MEDIUM
Windows 10 1507-22H2 - Information Disclosure via Message Queuing Client
CVSS 6.5
CVE-2024-20664 MEDIUM
Microsoft Message Queuing - Info Disclosure
CVSS 6.5
CVE-2024-20663 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Information Disclosure via MSMQC
CVSS 6.5
CVE-2023-32277 MEDIUM
Intel(R) QAT software < 2.0.5 - Authenticated Information Disclosure via Untrusted Pointer Dereference
CVSS 6.1
CVE-2023-42772 HIGH
Intel Reference Processor - Privilege Escalation
CVSS 8.2
CVE-2023-40472 HIGH
PDF-XChange Editor - Remote Code Execution via JavaScript String Untrusted Pointer Dereference
CVSS 7.8
CVE-2023-40471 HIGH
PDF-XChange Editor - Remote Code Execution via Untrusted Pointer Dereference in App Object Handling
CVSS 7.8
CVE-2023-39501 HIGH
PDF-XChange Editor - Untrusted Pointer Dereference in OXPS File Parser
CVSS 7.8
CVE-2023-35711 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via XE File Parsing
CVSS 7.8
CVE-2023-34311 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via CO File Parsing
CVSS 7.8
CVE-2023-34309 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via CO File Parsing
CVSS 7.8
CVE-2023-34301 HIGH
Ashlar-Vellum Cobalt < 12.4.1204.200 - Remote Code Execution via CO File Parsing
CVSS 7.8
CVE-2023-34300 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via XE File Parsing
CVSS 7.8
CVE-2023-27342 HIGH
PDF-XChange Editor - Remote Code Execution via EMF File Parsing
CVSS 7.8
CVE-2023-43532 HIGH
Qualcomm FastConnect and Snapdragon Firmware - Memory Corruption via ACPI Config
CVSS 8.4
CVE-2023-43518 HIGH
Product <Version - Memory Corruption
CVSS 7.3
CVE-2023-34333 HIGH
AMI MegaRAC SP-X 12-12.7 - Unauthenticated Memory Corruption via Untrusted Pointer Dereference
CVSS 7.8
CVE-2023-34332 HIGH
AMI MegaRAC SP-X 12-12.7 - Unauthenticated Memory Corruption via Untrusted Pointer Dereference
CVSS 7.8
CVE-2023-36011 HIGH
Windows 10 1507-23H2 and Windows Server 2012-2022 - Elevation of Privilege via Win32k Untrusted Pointer Dereference
CVSS 7.8
CVE-2023-41139 HIGH
Autodesk AutoCAD <2024 - Code Injection
CVSS 7.8
CVE-2023-36045 HIGH
Microsoft 365 Apps and Office - Remote Code Execution via Graphics Component
CVSS 7.8
CVE-2023-36033 HIGH KEV
Windows DWM Core Library - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 200