CVE Vulnerabilities

CVE-2002-1912

NULL Pointer Dereference

Published: Dec 31, 2002 | Modified: Apr 03, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SkyStream EMR5000 1.16 through 1.18 does not drop packets or disable the Ethernet interface when the buffers are full, which allows remote attackers to cause a denial of service (null pointer exception and kernel panic) via a large number of packets.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Emr5000Skystream1.16 (including)1.16 (including)
Emr5000Skystream1.17 (including)1.17 (including)
Emr5000Skystream1.18 (including)1.18 (including)

Potential Mitigations

References