CWE-822

Total CVEs
122
Vulnerabilities
Avg CVSS v3
7.6
High
Avg CVSS v2
6.2
Medium
Latest CVE
2025
Most Recent

Severity Distribution

Critical 6
4.9%
High 96
78.7%
Medium 19
15.6%
Low 1
0.8%

External References

All CVEs (122)

Page 1 of 6
CVSS:9.8(Critical)

Memory corruption in video while parsing invalid mp2 clip.

CVSS:9.8(Critical)

All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. T...

CVSS:9.8(Critical)

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAcce...

CVSS:9.8(Critical)

LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.

CVSS:9.8(Critical)

Fuji Electric V-Server 4.0.3.0 and prior, Multiple untrusted pointer dereference vulnerabilities have been identified, which may allow remote code execution.

CVSS:9.8(Critical)

In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept pointer values that are dereferenced in the native c...

CVSS:8.8(High)

Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability

CVSS:8.8(High)

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

CVSS:8.8(High)

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

CVSS:8.8(High)

Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.

CVSS:8.8(High)

The Omron CX-One Version 4.60 and prior may allow an attacker to supply a pointer to arbitrary memory locations, which may allow an attacker to remotely execute arbitrary code.

CVSS:8.8(High)

A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2). Affected applications lack proper validation of user-supplied data when pa...

CVSS:8.8(High)

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.3-47255. An attacker must first obtain the ability to execute low-privileged code o...

CVSS:8.4(High)

Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.

CVSS:8.4(High)

Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS:8.4(High)

There is an elevation of privilege vulnerability in server and client components of Absolute Secure Access prior to version 13.07. Attackers with local access and valid desktop user credentials can el...

CVSS:8.4(High)

Untrusted pointer dereference in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS:8.4(High)

Microsoft Streaming Service Elevation of Privilege Vulnerability

CVSS:8.2(High)

Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS:8.2(High)

The Motorola MTM5000 series firmwares lack pointer validation on arguments passed to trusted execution environment (TEE) modules. Two modules are used, one responsible for KVL key management and the o...

CVSS:7.8(High)

Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

CVSS:7.8(High)

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.