CWE-822Base5 in KEV

Untrusted Pointer Dereference

Incomplete in the CWE catalog · 224 CVEs mapped

224
CVEs mapped
5
In KEV
7.8
Median CVSS
What it is

The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Recent examples
5.5cvss
CVE-2026-10420

CVE-2026-10420 - MEDIUM Severity Vulnerability

Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.

MEDIUMno explanation yet
0%
epss
5.5cvss
CVE-2026-82927

CVE-2026-82927 - MEDIUM Severity Vulnerability

Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.

MEDIUMno explanation yet
0%
epss
8.2cvss
CVE-2026-19442

CVE-2026-19442 - HIGH Severity Vulnerability

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-822
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)