CWE-822

Untrusted Pointer Dereference

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

200 vulnerabilities with CWE-822
CVE-2023-31023 MEDIUM
NVIDIA Display Driver - Memory Corruption
CVSS 5.5
CVE-2023-36596 HIGH
Product <Version> - Info Disclosure
CVSS 7.5
CVE-2023-36759 MEDIUM
Visual Studio - Privilege Escalation
CVSS 6.7
CVE-2023-21643 CRITICAL
Qualcomm Automotive Firmware - Memory Corruption
CVSS 9.1
CVE-2023-1437 CRITICAL
Advantech WebAccess/SCADA <9.1.4 - Memory Corruption
CVSS 9.8
CVE-2023-32040 MEDIUM
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
CVSS 5.5
CVE-2023-25515 HIGH
NVIDIA GPU Display Driver 470-474.44, 470-470.199.02 - Untrusted Pointer Dereference
CVSS 7.8
CVE-2023-29360 HIGH KEV
Microsoft Streaming Service - Privilege Escalation
CVSS 8.4
CVE-2023-0184 HIGH
NVIDIA GPU Display Driver - DoS/Esc Priv/Info Disclosure/Data Tampe...
CVSS 8.8
CVE-2023-0189 HIGH
NVIDIA Virtual GPU < 11.12 - Untrusted Pointer Dereference
CVSS 8.8
CVE-2023-23394 MEDIUM
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Information Disclosure via CSRSS Untrusted Pointer Dereference
CVSS 5.5
CVE-2023-21768 HIGH
Windows Ancillary Function Driver - Privilege Escalation
CVSS 7.8
CVE-2023-21677 HIGH
Windows Internet Key Exchange (IKE) Extension - Denial of Service via Untrusted Pointer Dereference
CVSS 7.5
CVE-2022-26942 HIGH
Motorola MTM5000 - Privilege Escalation
CVSS 8.2
CVE-2022-40533 MEDIUM
Qualcomm CSRA6620 Firmware - Denial of Service via Untrusted Pointer Dereference in USB QMI Request
CVSS 6.2
CVE-2022-42418 HIGH
PDF-XChange Editor < 9.5.366.0 - Remote Code Execution via TIF File Parsing
CVSS 7.8
CVE-2022-42396 HIGH
PDF-XChange Editor < 9.5.366.0 - Remote Code Execution via XPS File Parsing
CVSS 7.8
CVE-2022-2002 HIGH
GE CIMPICITY <2022 - RCE
CVSS 7.8
CVE-2022-2894 HIGH
Measuresoft ScadaPro Server - Buffer Overflow
CVSS 7.8
CVE-2022-34890 HIGH
Parallels Desktop 17.1.1 - Info Disclosure
CVSS 8.8
CVE-2022-20796 MEDIUM
ClamAV 0.103.4-0.103.5 and 0.104.1-0.104.2 - Authenticated Denial of Service via NULL Pointer Dereference
CVSS 6.5
CVE-2022-22514 HIGH
CODESYS Control Runtime SL < 4.5.0.0 - Authenticated Memory Corruption in CmpTraceMgr
CVSS 7.1
CVE-2021-26410 LOW
AMD Ryzen Processors - Untrusted Pointer Dereference via ASP Syscall Input Validation
CVE-2021-38401 HIGH
Fuji Electric V-Server Lite & Tellus Lite V-Simulator <4.0.12.0 - RCE
CVSS 7.8
CVE-2021-31504 HIGH
OpenText Brava! Desktop <16.6.3.84 - RCE
CVSS 7.8
Details
Vulnerabilities 200