CWE-822: Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
238 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-36461 — Direct access to memory pointers within the JS engine for modification
- CVE-2025-27060 — Untrusted Pointer Dereference in TZ Firmware
- CVE-2025-20018 — Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable e
- CVE-2024-36352 — Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, pote
- CVE-2024-34023 — Untrusted pointer dereference in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable es
- CVE-2025-4993 — Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.
- CVE-2025-1255 — Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.
- CVE-2025-47387 — Untrusted Pointer Dereference in Camera
- CVE-2025-47380 — Untrusted Pointer Dereference in Camera
- CVE-2025-47343 — Untrusted Pointer Dereference in Video
- CVE-2025-47338 — Untrusted Pointer Dereference in DSP Service
- CVE-2025-27069 — Untrusted Pointer Dereference in DSP Service
- CVE-2025-27048 — Untrusted Pointer Dereference in Camera
- CVE-2025-21486 — Untrusted Pointer Dereference in DSP Service
- CVE-2024-53034 — Untrusted Pointer Dereference in DSP_Services
- CVE-2024-53033 — Untrusted Pointer Dereference in DSP_Services
- CVE-2024-33038 — Untrusted Pointer Dereference in Computer Vision
- CVE-2024-23136 — Multiple Vulnerabilities in the Autodesk AutoCAD Desktop Software
- CVE-2024-0091 — CVE
- CVE-2026-48137 — Untrusted pointer dereference in NI grpc-device sideband streaming API
Recently published
- CVE-2026-10420 — Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affec
- CVE-2026-82927 — Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affec
- CVE-2026-19442 — Vulnerabilities in IBM AIX and PowerVM VIOS
- CVE-2026-18840 — Vulnerabilities in IBM AIX and PowerVM VIOS
- CVE-2026-9771 — Missing device-pointer validation in flash_copy() syscall allows userspace privilege escalation
- CVE-2026-12364 — Missing user-space pointer validation in logging syscall z_log_msg_static_create allows kernel memory disclosure and denial of service
- CVE-2026-8917 — Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a
- CVE-2026-45198 — GPU DDK - RGXFWIF_SYSINIT::sCorememDataStore is untrusted
- CVE-2026-7406 — BMP File Parsing Untrusted Pointer Dereference in certain Autodesk products
- CVE-2026-19023 — HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets
- CVE-2026-24083 — Untrusted Pointer Dereference in Automotive Security
- CVE-2026-15029 — Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Mana
- CVE-2026-48340 — Bridge | Untrusted Pointer Dereference (CWE-822)
- CVE-2026-48137 — Untrusted pointer dereference in NI grpc-device sideband streaming API
- CVE-2026-8835 — IBM HTTP Server is affected by multiple vulnerabilities
- CVE-2025-62627 — An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged
- CVE-2026-20738 — Untrusted pointer dereference for some Intel(R) QuickAssist Adapter 8960 software before version 1.13 within Ring 3: Use
- CVE-2025-47408 — Untrusted Pointer Dereference in Power Optimization Firmware
- CVE-2025-47405 — Untrusted Pointer Dereference in Camera
- CVE-2025-59959 — Junos OS and Junos OS Evolved: Executing a specific show command leads to an rpd crash