«
Expand/Collapse
348 items tagged "null pointer"
Related tags:
poc [+],
libzip [+],
notice [+],
grapheme [+],
denial of service [+],
zip [+],
subversion [+],
mandriva [+],
gss api [+],
ziparchive [+],
version [+],
service [+],
server versions [+],
server [+],
reset [+],
proof of concept [+],
name [+],
license [+],
getarchivecomment [+],
denial [+],
data [+],
null [+],
vulnerabilities [+],
type [+],
regsets [+],
reader [+],
quagga [+],
protector [+],
multiple [+],
ghostscript [+],
function [+],
firefox [+],
extract [+],
data protector [+],
asterisk [+],
linux [+],
linux kernel [+],
kernel [+],
wireshark [+],
remote [+],
proxy [+],
microsoft [+],
kernel 2 [+],
init [+],
gre [+],
emc [+],
daemon [+],
bugtraq [+],
bgp [+],
bcm [+],
xitami [+],
webmi [+],
system [+],
symantec [+],
siemens automation [+],
siemens [+],
resource consumption [+],
refractor [+],
red hat security [+],
red [+],
putty [+],
psftp [+],
proxy ftp [+],
protocol driver [+],
project security [+],
project [+],
privilege [+],
pidgin [+],
php 5 [+],
pdf [+],
optima [+],
opera version [+],
opera [+],
openssl [+],
nelson elhage [+],
msn code [+],
mozilla firefox [+],
mozilla [+],
mime messages [+],
mime header [+],
mime [+],
messenger protocol [+],
license server [+],
kernel version [+],
kernel stack [+],
irm [+],
internet explorer [+],
internet [+],
integer overflow [+],
index [+],
imatix [+],
iedvtool [+],
heap corruption [+],
hat [+],
freebsd [+],
filter [+],
explorer [+],
expert [+],
exec [+],
engine versions [+],
engine [+],
endless loop [+],
econet [+],
dos [+],
distribution center [+],
dissector [+],
directory [+],
cyrus imap server [+],
cyrus imap [+],
cups [+],
crash proof [+],
code execution [+],
code [+],
buffer overflow [+],
backup exec system [+],
automation [+],
atvise [+],
attackers [+],
attacker [+],
apiftp [+],
apache httpd server [+],
apache [+],
adobe [+],
zip name [+],
yahoo [+],
txt [+],
tls [+],
tcp [+],
tavis ormandy [+],
safer use [+],
realplayer [+],
protocol [+],
ntlmssp [+],
network [+],
memory corruption [+],
memory [+],
libpurple [+],
kvm [+],
icmp [+],
header [+],
freebsd versions [+],
exploit [+],
exp [+],
device server [+],
device [+],
call [+],
block [+],
adobe reader version [+],
php [+],
word [+],
win [+],
tty [+],
tivoli storage manager [+],
tivoli [+],
stripbytecount [+],
string [+],
storage [+],
squid [+],
solaris [+],
race [+],
protection [+],
php versions [+],
oracle [+],
multicast [+],
mount null [+],
monochrome [+],
microsoft word [+],
memcg [+],
media [+],
manager fastback [+],
manager [+],
local [+],
little [+],
libtiff [+],
ibm [+],
gfs [+],
flash [+],
event [+],
diagnose [+],
cve [+],
condition [+],
cms [+],
cifs [+],
c bridge [+],
bip bip [+],
bip [+],
bgpd [+],
avi [+],
asn [+],
mit [+],
kerberos [+],
security [+],
vulnerability [+],
mod [+],
service vulnerability [+],
pointer [+],
kdc [+],
ubuntu [+],
mit kerberos [+],
mandriva linux [+],
dav [+],
znc,
zabbix,
xml rpc,
wrv,
windows,
usn,
update,
trap,
tkadv,
tgz,
sun microsystems,
sun,
sslv,
ssl,
solaris x86,
smb,
slplink,
slk,
sendpage,
selinux,
pseudofs,
process,
privilege escalation vulnerability,
pppol,
player,
openoffice,
openbsd,
ntop,
network traffic analyzer,
nameidata,
mso,
msn,
mplayer,
mitkrb,
mdvsa,
mateusz kocielski,
manager. authentication,
local privilege escalation,
linux security,
linux kernel drivers,
libnids,
lib,
keyctl,
kernel panic,
kernel memory,
jinais,
irssi,
irda,
irc server,
irc proxy,
irc,
ipv,
intel based system,
hypertext preprocessor,
http,
htcp,
hash algorithm,
gnutls,
ftpd,
fragment c,
fragment,
fixed,
firewire,
file,
exploits,
encrypted communications,
dsa,
driver,
dplay,
dos vulnerability,
directplay8,
directplay,
directory service manager,
dereference,
debian,
corporate desktop,
cisco,
buffer overflows,
basic,
application crash,
application,
adobe flash player,
acrobat,
access violation
-
-
18:18
»
Packet Storm Security Advisories
Ubuntu Security Notice 1424-1 - It was discovered that OpenSSL could be made to dereference a NULL pointer when processing S/MIME messages. A remote attacker could use this to cause a denial of service. These issues did not affect Ubuntu 8.04 LTS. Tavis Ormandy discovered that OpenSSL did not properly perform bounds checking when processing DER data via BIO or FILE functions. A remote attacker could trigger this flaw in services that used SSL to cause a denial of service or possibly execute arbitrary code with application privileges. Various other issues were also addressed.
-
18:18
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1424-1 - It was discovered that OpenSSL could be made to dereference a NULL pointer when processing S/MIME messages. A remote attacker could use this to cause a denial of service. These issues did not affect Ubuntu 8.04 LTS. Tavis Ormandy discovered that OpenSSL did not properly perform bounds checking when processing DER data via BIO or FILE functions. A remote attacker could trigger this flaw in services that used SSL to cause a denial of service or possibly execute arbitrary code with application privileges. Various other issues were also addressed.
-
18:18
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1424-1 - It was discovered that OpenSSL could be made to dereference a NULL pointer when processing S/MIME messages. A remote attacker could use this to cause a denial of service. These issues did not affect Ubuntu 8.04 LTS. Tavis Ormandy discovered that OpenSSL did not properly perform bounds checking when processing DER data via BIO or FILE functions. A remote attacker could trigger this flaw in services that used SSL to cause a denial of service or possibly execute arbitrary code with application privileges. Various other issues were also addressed.
-
5:33
»
Packet Storm Security Exploits
Wireshark suffers from a call_dissector() NULL pointer dereference denial of service vulnerability. Proof of concept pcap included.
-
-
19:43
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-042 - Multiple vulnerabilities was found and corrected in Wireshark. The ANSI A dissector could dereference a NULL pointer and crash. The IEEE 802.11 dissector could go into an infinite loop. The pcap and pcap-ng file parsers could crash trying to read ERF data. The MP2T dissector could try to allocate too much memory and crash. This advisory provides the latest version of Wireshark which is not vulnerable to these issues.
-
-
14:17
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-015 - Multiple file parser and NULL pointer vulnerabilities including a RLC dissector buffer overflow was found and corrected in Wireshark. This advisory provides the latest version of Wireshark which is not vulnerable to these issues.
-
14:17
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-015 - Multiple file parser and NULL pointer vulnerabilities including a RLC dissector buffer overflow was found and corrected in Wireshark. This advisory provides the latest version of Wireshark which is not vulnerable to these issues.
-
14:17
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-015 - Multiple file parser and NULL pointer vulnerabilities including a RLC dissector buffer overflow was found and corrected in Wireshark. This advisory provides the latest version of Wireshark which is not vulnerable to these issues.
-
-
16:11
»
Packet Storm Security Advisories
Asterisk Project Security Advisory - Asterisk suffers from a denial of service vulnerability. When the "automon" feature is enabled in features.conf, it is possible to send a sequence of SIP requests that cause Asterisk to dereference a NULL pointer and crash.
-
16:11
»
Packet Storm Security Recent Files
Asterisk Project Security Advisory - Asterisk suffers from a denial of service vulnerability. When the "automon" feature is enabled in features.conf, it is possible to send a sequence of SIP requests that cause Asterisk to dereference a NULL pointer and crash.
-
16:11
»
Packet Storm Security Misc. Files
Asterisk Project Security Advisory - Asterisk suffers from a denial of service vulnerability. When the "automon" feature is enabled in features.conf, it is possible to send a sequence of SIP requests that cause Asterisk to dereference a NULL pointer and crash.
-
-
20:10
»
Packet Storm Security Advisories
Ubuntu Security Notice 1290-1 - Simo Sorce discovered that a NULL pointer dereference existed in the Kerberos Key Distribution Center (KDC). An authenticated remote attacker could use this to cause a denial of service.
-
20:10
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1290-1 - Simo Sorce discovered that a NULL pointer dereference existed in the Kerberos Key Distribution Center (KDC). An authenticated remote attacker could use this to cause a denial of service.
-
20:10
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1290-1 - Simo Sorce discovered that a NULL pointer dereference existed in the Kerberos Key Distribution Center (KDC). An authenticated remote attacker could use this to cause a denial of service.
-
-
15:52
»
Packet Storm Security Exploits
Siemens Automation License Manager versions 500.0.122.1 and below suffer from code execution, exceptions, NULL pointer and file overwriting vulnerabilities.
-
15:52
»
Packet Storm Security Recent Files
Siemens Automation License Manager versions 500.0.122.1 and below suffer from code execution, exceptions, NULL pointer and file overwriting vulnerabilities.
-
15:52
»
Packet Storm Security Misc. Files
Siemens Automation License Manager versions 500.0.122.1 and below suffer from code execution, exceptions, NULL pointer and file overwriting vulnerabilities.
-
-
23:03
»
Packet Storm Security Advisories
Red Hat Security Advisory 2011-1371-01 - Pidgin is an instant messaging program which can log in to multiple accounts on multiple instant messaging networks simultaneously. An input sanitization flaw was found in the way the Pidgin SILC protocol plug-in escaped certain UTF-8 characters. A remote attacker could use this flaw to crash Pidgin via a specially-crafted SILC message. Multiple NULL pointer dereference flaws were found in the way the Pidgin Yahoo! Messenger Protocol plug-in handled malformed YMSG packets. A remote attacker could use these flaws to crash Pidgin via a specially-crafted notification message.
-
23:03
»
Packet Storm Security Recent Files
Red Hat Security Advisory 2011-1371-01 - Pidgin is an instant messaging program which can log in to multiple accounts on multiple instant messaging networks simultaneously. An input sanitization flaw was found in the way the Pidgin SILC protocol plug-in escaped certain UTF-8 characters. A remote attacker could use this flaw to crash Pidgin via a specially-crafted SILC message. Multiple NULL pointer dereference flaws were found in the way the Pidgin Yahoo! Messenger Protocol plug-in handled malformed YMSG packets. A remote attacker could use these flaws to crash Pidgin via a specially-crafted notification message.
-
23:03
»
Packet Storm Security Misc. Files
Red Hat Security Advisory 2011-1371-01 - Pidgin is an instant messaging program which can log in to multiple accounts on multiple instant messaging networks simultaneously. An input sanitization flaw was found in the way the Pidgin SILC protocol plug-in escaped certain UTF-8 characters. A remote attacker could use this flaw to crash Pidgin via a specially-crafted SILC message. Multiple NULL pointer dereference flaws were found in the way the Pidgin Yahoo! Messenger Protocol plug-in handled malformed YMSG packets. A remote attacker could use these flaws to crash Pidgin via a specially-crafted notification message.
-
-
17:51
»
Packet Storm Security Exploits
atvise webMI2ADS versions 1.0 and below suffer from directory traversal, NULL pointer, termination, and resource consumption vulnerabilities.
-
17:51
»
Packet Storm Security Misc. Files
atvise webMI2ADS versions 1.0 and below suffer from directory traversal, NULL pointer, termination, and resource consumption vulnerabilities.
-
-
9:01
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2011-106 - The mod_dav_svn Apache HTTPD server module will dereference a NULL pointer if asked to deliver baselined WebDAV resources which can lead to a denial of service. The mod_dav_svn Apache HTTPD server module may in certain scenarios enter a logic loop which does not exit and which allocates emory in each iteration, ultimately exhausting all the available emory on the server which can lead to a denial of service. The mod_dav_svn Apache HTTPD server module may leak to remote users the file contents of files configured to be unreadable by those users.
-
9:01
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2011-106 - The mod_dav_svn Apache HTTPD server module will dereference a NULL pointer if asked to deliver baselined WebDAV resources which can lead to a denial of service. The mod_dav_svn Apache HTTPD server module may in certain scenarios enter a logic loop which does not exit and which allocates emory in each iteration, ultimately exhausting all the available emory on the server which can lead to a denial of service. The mod_dav_svn Apache HTTPD server module may leak to remote users the file contents of files configured to be unreadable by those users.
-
9:01
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2011-106 - The mod_dav_svn Apache HTTPD server module will dereference a NULL pointer if asked to deliver baselined WebDAV resources which can lead to a denial of service. The mod_dav_svn Apache HTTPD server module may in certain scenarios enter a logic loop which does not exit and which allocates emory in each iteration, ultimately exhausting all the available emory on the server which can lead to a denial of service. The mod_dav_svn Apache HTTPD server module may leak to remote users the file contents of files configured to be unreadable by those users.
-
8:54
»
Packet Storm Security Exploits
libzip version 0.9.3 allows remote and local attackers to trigger a denial of service condition via a null pointer dereference if ZIP_FL_UNCHANGED flag is set.
-
8:54
»
Packet Storm Security Recent Files
libzip version 0.9.3 allows remote and local attackers to trigger a denial of service condition via a null pointer dereference if ZIP_FL_UNCHANGED flag is set.
-
8:54
»
Packet Storm Security Misc. Files
libzip version 0.9.3 allows remote and local attackers to trigger a denial of service condition via a null pointer dereference if ZIP_FL_UNCHANGED flag is set.
-
-
8:37
»
Packet Storm Security Exploits
The Refractor 2 engine versions 1.50 and below suffer from a NULL pointer dereference vulnerability. Games such as Battlefield 2 and Battlefield 2142 are affected. Proof of concept code included.
-
8:37
»
Packet Storm Security Recent Files
The Refractor 2 engine versions 1.50 and below suffer from a NULL pointer dereference vulnerability. Games such as Battlefield 2 and Battlefield 2142 are affected. Proof of concept code included.
-
8:37
»
Packet Storm Security Misc. Files
The Refractor 2 engine versions 1.50 and below suffer from a NULL pointer dereference vulnerability. Games such as Battlefield 2 and Battlefield 2142 are affected. Proof of concept code included.
-
-
17:50
»
Packet Storm Security Advisories
Ubuntu Security Notice 1042-1 - Various issues have been addressed with php5. It was discovered that an integer overflow in the XML UTF-8 decoding code could allow an attacker to bypass cross-site scripting (XSS) protections. It was discovered that the XML UTF-8 decoding code did not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which could allow an attacker to bypass cross-site scripting (XSS) protections. It was discovered that attackers might be able to bypass open_basedir() restrictions by passing a specially crafted filename. Other issues Maksymilian Arciemowicz discovered that a NULL pointer derefence in the ZIP archive handling code could allow an attacker to cause a denial of service through a specially crafted ZIP archive.
-
17:50
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1042-1 - Various issues have been addressed with php5. It was discovered that an integer overflow in the XML UTF-8 decoding code could allow an attacker to bypass cross-site scripting (XSS) protections. It was discovered that the XML UTF-8 decoding code did not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which could allow an attacker to bypass cross-site scripting (XSS) protections. It was discovered that attackers might be able to bypass open_basedir() restrictions by passing a specially crafted filename. Other issues Maksymilian Arciemowicz discovered that a NULL pointer derefence in the ZIP archive handling code could allow an attacker to cause a denial of service through a specially crafted ZIP archive.
-
17:50
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1042-1 - Various issues have been addressed with php5. It was discovered that an integer overflow in the XML UTF-8 decoding code could allow an attacker to bypass cross-site scripting (XSS) protections. It was discovered that the XML UTF-8 decoding code did not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which could allow an attacker to bypass cross-site scripting (XSS) protections. It was discovered that attackers might be able to bypass open_basedir() restrictions by passing a specially crafted filename. Other issues Maksymilian Arciemowicz discovered that a NULL pointer derefence in the ZIP archive handling code could allow an attacker to cause a denial of service through a specially crafted ZIP archive.
-
-
9:28
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2010-259 - A null pointer dereference due to receiving a short packet for a direct connection in the MSN code could potentially cause a denial of service.
-
9:28
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2010-259 - A null pointer dereference due to receiving a short packet for a direct connection in the MSN code could potentially cause a denial of service.
-
9:28
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2010-259 - A null pointer dereference due to receiving a short packet for a direct connection in the MSN code could potentially cause a denial of service.
-
-
11:18
»
Packet Storm Security Exploits
Linux kernel local privilege escalation exploit for versions 2.6.37 and below. It leverages three separate vulnerabilities to achieve root including a NULL pointer dereference, being able to assign arbitrary Econet addresses to arbitrary interfaces, and the ability to write a NULL word to an arbitrary kernel address.
-
11:18
»
Packet Storm Security Recent Files
Linux kernel local privilege escalation exploit for versions 2.6.37 and below. It leverages three separate vulnerabilities to achieve root including a NULL pointer dereference, being able to assign arbitrary Econet addresses to arbitrary interfaces, and the ability to write a NULL word to an arbitrary kernel address.
-
11:18
»
Packet Storm Security Misc. Files
Linux kernel local privilege escalation exploit for versions 2.6.37 and below. It leverages three separate vulnerabilities to achieve root including a NULL pointer dereference, being able to assign arbitrary Econet addresses to arbitrary interfaces, and the ability to write a NULL word to an arbitrary kernel address.
-
-
18:25
»
Packet Storm Security Advisories
Ubuntu Security Notice 1023-1 - Nelson Elhage discovered several problems with the Acorn Econet protocol driver. A local user could cause a denial of service via a NULL pointer dereference, escalate privileges by overflowing the kernel stack, and assign Econet addresses to arbitrary interfaces.
-
18:25
»
Packet Storm Security Recent Files
Ubuntu Security Notice 1023-1 - Nelson Elhage discovered several problems with the Acorn Econet protocol driver. A local user could cause a denial of service via a NULL pointer dereference, escalate privileges by overflowing the kernel stack, and assign Econet addresses to arbitrary interfaces.
-
18:25
»
Packet Storm Security Misc. Files
Ubuntu Security Notice 1023-1 - Nelson Elhage discovered several problems with the Acorn Econet protocol driver. A local user could cause a denial of service via a NULL pointer dereference, escalate privileges by overflowing the kernel stack, and assign Econet addresses to arbitrary interfaces.
-
-
19:27
»
SecuriTeam
This vulnerability allows remote attackers to deny service to clients on vulnerable installations of IBM Tivoli FastBack Storage Manager.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
10:41
»
SecuriTeam
A null pointer dereference vulnerability has been noticed in Microsoft Word 2003.
-
Make your website safer. Use external penetration testing service. First report ready in one hour!
-
-
18:01
»
Packet Storm Security Recent Files
Adobe Reader version 9.3.4 is vulnerable to multiple memory corruption vulnerabilities. By sending specially crafted PDF files it is possible to cause memory corruption in the 3difr and AcroRd32.dll modules. Both issues trigger a null pointer condition which results in an access violation. The issue in AcroRd32.dll is triggered when Adobe Reader is closed.
-
18:00
»
Packet Storm Security Advisories
Adobe Reader version 9.3.4 is vulnerable to multiple memory corruption vulnerabilities. By sending specially crafted PDF files it is possible to cause memory corruption in the 3difr and AcroRd32.dll modules. Both issues trigger a null pointer condition which results in an access violation. The issue in AcroRd32.dll is triggered when Adobe Reader is closed.