There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an a
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USE
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t
The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges o
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper val
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initi
Memory corruption while processing a video session to set video parameters.
Memory corruption while preprocessing IOCTLs in sensors.
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to
Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privile
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to el
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally
Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to ele
Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to ele
Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to ele
Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to e
Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privilege
Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in th
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference
Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause G
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a networ
IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Admin
An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400,
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to by
Frequently Asked Questions
What is CWE-822?
CWE-822 (CWE-822) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-822?
There are 63 CVE records associated with CWE-822 in our database. Of these, 1 are critical severity, 46 are high severity, and 10 are medium severity.
How can I protect against CWE-822 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-822 using AI-powered security agents.
Detect CWE-822 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-822 vulnerabilities across your infrastructure.
Get Started