Vulnerabilities (CVE)

Filtered by CWE-476
Total 5426 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-23357 1 Qualcomm 484 215 Mobile Platform, 215 Mobile Platform Firmware, Apq8017 and 481 more 2026-06-17 N/A 6.2 MEDIUM
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
CVE-2024-23327 1 Envoyproxy 1 Envoy 2026-06-17 N/A 7.5 HIGH
Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, the Envoy instance will segfault when attempting to craft the upstream PPv2 header. This occurs when the downstream request has a command type of LOCAL and does not have the protocol block. This issue has been addressed in releases 1.29.1, 1.28.1, 1.27.3, and 1.26.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-23196 1 Linux 1 Linux Kernel 2026-06-17 N/A 5.3 MEDIUM
A race condition was found in the Linux kernel's sound/hda device driver in snd_hdac_regmap_sync() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.
CVE-2024-22733 1 Tp-link 2 Mr200, Mr200 Firmware 2026-06-17 N/A 7.5 HIGH
TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or LoginStatus query parameters which could lead to a denial of service by a local or remote unauthenticated attacker.
CVE-2024-22653 1 Yasm Project 1 Yasm 2026-06-17 N/A 4.8 MEDIUM
yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c.
CVE-2024-22525 1 Dnspod 1 Dnspod Security Recursive 2026-06-17 N/A 5.5 MEDIUM
dnspod-sr 0dfbd37 contains a SEGV.
CVE-2024-22524 1 Dnspod 1 Dnspod Security Recursive 2026-06-17 N/A 5.5 MEDIUM
dnspod-sr 0dfbd37 is vulnerable to buffer overflow.
CVE-2024-22386 1 Linux 1 Linux Kernel 2026-06-17 N/A 5.3 MEDIUM
A race condition was found in the Linux kernel's drm/exynos device driver in exynos_drm_crtc_atomic_disable() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.
CVE-2024-22099 1 Linux 1 Linux Kernel 2026-06-17 N/A 6.3 MEDIUM
NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C. This issue affects Linux kernel: v2.6.12-rc2.
CVE-2024-22052 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 7.5 HIGH
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack
CVE-2024-22043 1 Siemens 1 Parasolid 2026-06-17 N/A 3.3 LOW
A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.251), Parasolid V35.1 (All versions < V35.1.170). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted XT files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.
CVE-2024-22023 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 5.3 MEDIUM
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a limited-time DoS.
CVE-2024-21664 1 Lestrrat-go 1 Jwx 2026-06-17 N/A 4.3 MEDIUM
jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. Calling `jws.Parse` with a JSON serialized payload where the `signature` field is present while `protected` is absent can lead to a nil pointer dereference. The vulnerability can be used to crash/DOS a system doing JWS verification. This vulnerability has been patched in versions 2.0.19 and 1.2.28.
CVE-2024-21602 1 Juniper 1 Junos Os Evolved 2026-06-17 N/A 7.5 HIGH
A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS Evolved on ACX7024, ACX7100-32C and ACX7100-48L allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). If a specific IPv4 UDP packet is received and sent to the Routing Engine (RE) packetio crashes and restarts which causes a momentary traffic interruption. Continued receipt of such packets will lead to a sustained DoS. This issue does not happen with IPv6 packets. This issue affects Juniper Networks Junos OS Evolved on ACX7024, ACX7100-32C and ACX7100-48L: * 21.4-EVO versions earlier than 21.4R3-S6-EVO; * 22.1-EVO versions earlier than 22.1R3-S5-EVO; * 22.2-EVO versions earlier than 22.2R2-S1-EVO, 22.2R3-EVO; * 22.3-EVO versions earlier than 22.3R2-EVO. This issue does not affect Juniper Networks Junos OS Evolved versions earlier than 21.4R1-EVO.
CVE-2024-21478 1 Qualcomm 24 Qam8255p, Qam8255p Firmware, Qam8650p and 21 more 2026-06-17 N/A 6.2 MEDIUM
transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.
CVE-2024-21404 1 Microsoft 2 Asp.net Core, Visual Studio 2022 2026-06-17 N/A 7.5 HIGH
.NET Denial of Service Vulnerability
CVE-2024-21356 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2026-06-17 N/A 6.5 MEDIUM
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
CVE-2024-20794 3 Adobe, Apple, Microsoft 3 Animate, Macos, Windows 2026-06-17 N/A 5.5 MEDIUM
Animate versions 23.0.4, 24.0.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service. An attacker could leverage this vulnerability to cause a system crash, resulting in a denial of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2024-20661 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2026-06-17 N/A 7.5 HIGH
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2024-20446 2026-06-17 N/A 8.6 HIGH
A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of specific fields in a DHCPv6 RELAY-REPLY message. An attacker could exploit this vulnerability by sending a crafted DHCPv6 packet to any IPv6 address that is configured on an affected device. A successful exploit could allow the attacker to cause the dhcp_snoop process to crash and restart multiple times, causing the affected device to reload and resulting in a DoS condition.