CVE-2025-59604
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVSS
7.8
Alto
EPSS
0.1%
p0
KEV
—
Exploit Today
0
0-100
Publicado: 1 jun 2026 · Última mod.: 22 jul 2026 · CWE-476
0.1%EPSS · 30 días0.1%
2026-08-202026-09-18
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-767815.5 MED5.6%
——2A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS).4hCVE-2026-924176.5 MED49.3%
——15A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack may be launched remotely. The patch is identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2. A patch should be applied to remediate this issue.2dCVE-2026-924134.3 MED37.2%
——11A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation can lead to null pointer dereference. The attack can be launched remotely. The exploit has been published and may be used. This patch is called 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e. Applying a patch is advised to resolve this issue.4hCVE-2026-926267.5 ALT30.3%
——9Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service.
The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that returns void, so it is not observed by a caller and can terminate the iDSecure process.4hCVE-2026-776927.5 ALT40.5%
——12An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely.
This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1.2dCVE-2026-768684.9 MED30.1%
——9Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a missing exit_port parameter. Attackers can send requests lacking the exit_port field to trigger the null pointer dereference, resulting in a denial of service.2d