Vulnerabilities (CVE)

Filtered by CWE-476
Total 3817 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-5980 1 Gdraheim 1 Zziplib 2025-07-10 4.3 MEDIUM 5.5 MEDIUM
The zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted ZIP file.
CVE-2025-7209 2025-07-10 1.7 LOW 3.3 LOW
A vulnerability has been found in 9fans plan9port up to 9da5b44 and classified as problematic. Affected by this vulnerability is the function value_decode in the library src/libsec/port/x509.c. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The identifier of the patch is deae8939583d83fd798fca97665e0e94656c3ee8. It is recommended to apply a patch to fix this issue.
CVE-2025-53184 1 Huawei 1 Harmonyos 2025-07-09 N/A 6.5 MEDIUM
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
CVE-2025-53183 1 Huawei 1 Harmonyos 2025-07-09 N/A 6.5 MEDIUM
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
CVE-2025-53182 1 Huawei 1 Harmonyos 2025-07-09 N/A 6.5 MEDIUM
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
CVE-2025-53181 1 Huawei 1 Harmonyos 2025-07-09 N/A 6.5 MEDIUM
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
CVE-2025-53179 1 Huawei 1 Harmonyos 2025-07-09 N/A 6.5 MEDIUM
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
CVE-2025-53180 1 Huawei 1 Harmonyos 2025-07-09 N/A 6.5 MEDIUM
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
CVE-2025-45332 1 Vkoskiv 1 C-ray 2025-07-09 N/A 7.5 HIGH
vkoskiv c-ray 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the parse_mtllib function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.
CVE-2025-45333 1 Berkeley-abc 1 Abc 2025-07-09 N/A 7.5 HIGH
berkeley-abc abc 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the Abc_NtkCecFraigPart function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.
CVE-2025-45835 1 Netis-systems 2 Wf2880, Wf2880 Firmware 2025-07-09 N/A 7.5 HIGH
A null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_004904c8 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the environment variable value CONTENT_LENGTH, causing the program to crash and potentially leading to a denial-of-service (DoS) attack.
CVE-2025-53603 2025-07-08 N/A 7.5 HIGH
In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the query string is a duplicate of a parameter in the POST body.
CVE-2025-6858 1 Hdfgroup 1 Hdf5 2025-07-08 1.7 LOW 3.3 LOW
A vulnerability was found in HDF5 1.14.6 and classified as problematic. Affected by this issue is the function H5C__flush_single_entry of the file src/H5Centry.c. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
CVE-2025-48705 1 Yftech 2 Coros Pace 3, Coros Pace 3 Firmware 2025-07-08 N/A 7.5 HIGH
An issue was discovered in COROS PACE 3 through 3.0808.0. Due to a NULL pointer dereference vulnerability, sending a crafted BLE message forces the device to reboot.
CVE-2025-40576 1 Siemens 2 Scalance Lpe9403, Scalance Lpe9403 Firmware 2025-07-08 N/A 4.3 MEDIUM
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.
CVE-2025-24997 1 Microsoft 8 Windows 10 21h2, Windows 10 22h2, Windows 11 22h2 and 5 more 2025-07-03 N/A 4.4 MEDIUM
Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.
CVE-2024-12661 1 Iobit 1 Advanced Systemcare Ultimate 2025-07-02 4.6 MEDIUM 5.5 MEDIUM
A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been rated as problematic. Affected by this issue is the function 0x8001E024 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-20673 1 Mediatek 10 Mt7902, Mt7902 Firmware, Mt7921 and 7 more 2025-07-02 N/A 5.5 MEDIUM
In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413200; Issue ID: MSV-3304.
CVE-2025-20675 1 Mediatek 10 Mt7902, Mt7902 Firmware, Mt7921 and 7 more 2025-07-02 N/A 5.5 MEDIUM
In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413201; Issue ID: MSV-3302.
CVE-2023-47466 1 Taglib 1 Taglib 2025-07-02 N/A 2.9 LOW
TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the only valid chunk.