CWE-822

Untrusted Pointer Dereference

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

212 vulnerabilities with CWE-822
CVE-2024-40872 HIGH
Absolute Secure Access <13.07 - Privilege Escalation
CVSS 8.4
CVE-2024-38104 HIGH
Windows Fax Service - Remote Code Execution
CVSS 8.8
CVE-2024-37969 HIGH
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2012-2022 - Secure Boot Security Feature Bypass
CVSS 8.0
CVE-2024-0091 HIGH
NVIDIA GPU Display Driver 550-552.55, 550-550.90.07 - Untrusted Pointer Dereference via Driver API
CVSS 7.8
CVE-2024-35250 HIGH KEV
Windows Kernel-Mode Driver - Privilege Escalation
CVSS 7.8
CVE-2024-30090 HIGH
Microsoft Streaming Service - Privilege Escalation
CVSS 7.0
CVE-2024-27353 HIGH
InsydeH2O <5.6 - Privilege Escalation
CVSS 7.4
CVE-2024-25078 HIGH
Insyde InsydeH2O < 5.29.07 - Untrusted Pointer Dereference in StorageSecurityCommandDxe
CVSS 7.4
CVE-2024-26254 HIGH
Windows 10 1809/21H2/22H2, Windows 11 21H2/22H2/23H2, Windows Server 2019/2022/2022 23H2 - Denial of Service via VMBus
CVSS 7.5
CVE-2024-26252 MEDIUM
Windows rndismp6.sys - Remote Code Execution via Untrusted Pointer Dereference
CVSS 6.8
CVE-2024-26213 HIGH
Windows Server 2022 23H2 < 10.0.25398.830 - Elevation of Privilege via Brokering File System
CVSS 7.0
CVE-2024-23136 HIGH
Autodesk AutoCAD and Related Products 2021-<2021.1.4 - Untrusted Pointer Dereference in ASMKERN228A.dll
CVSS 7.8
CVE-2024-21346 HIGH
Windows 11/Server 2022 Elevation of Privilege via Win32k Untrusted Pointer Dereference
CVSS 7.8
CVE-2024-21338 HIGH KEV
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2024-20682 HIGH
Microsoft Windows Cryptographic Services - Remote Code Execution
CVSS 7.8
CVE-2024-20680 MEDIUM
Windows 10 1507-22H2 - Information Disclosure via Message Queuing Client
CVSS 6.5
CVE-2024-20664 MEDIUM
Microsoft Message Queuing - Info Disclosure
CVSS 6.5
CVE-2024-20663 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Information Disclosure via MSMQC
CVSS 6.5
CVE-2023-32277 MEDIUM
Intel(R) QAT software < 2.0.5 - Authenticated Information Disclosure via Untrusted Pointer Dereference
CVSS 6.1
CVE-2023-42772 HIGH
Intel Reference Processor - Privilege Escalation
CVSS 8.2
CVE-2023-40472 HIGH
PDF-XChange Editor - Remote Code Execution via JavaScript String Untrusted Pointer Dereference
CVSS 7.8
CVE-2023-40471 HIGH
PDF-XChange Editor - Remote Code Execution via Untrusted Pointer Dereference in App Object Handling
CVSS 7.8
CVE-2023-39501 HIGH
PDF-XChange Editor - Untrusted Pointer Dereference in OXPS File Parser
CVSS 7.8
CVE-2023-35711 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via XE File Parsing
CVSS 7.8
CVE-2023-34311 HIGH
Ashlar-Vellum Cobalt - Remote Code Execution via CO File Parsing
CVSS 7.8
Details
Vulnerabilities 212