CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,484 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 35 of 110
- CVE-2021-39554MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function Lexer::Lexer() located in Lexer.cc. It allows an attacker to cause Denial of Service.
- CVE-2021-39555MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D0() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service.
- CVE-2021-39556MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D1() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service.
- CVE-2021-39557MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function copyString() located in gmem.cc. It allows an attacker to cause Denial of Service.
- CVE-2021-39559MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function GString::~GString() located in GString.cc. It allows an attacker to cause Denial of Service.
- CVE-2021-39562MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function FileStream::makeSubStream() located in Stream.cc. It allows an attacker to cause Denial of Service.
- CVE-2021-39563MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpActions() located in swfaction.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39575MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function dump_method() located in abc.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39583MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_string2() located in pool.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39584MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function namespace_set_hash() located in pool.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39585MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function traits_dump() located in abc.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39587MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpABC() located in abc.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39588MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_ReadABC() located in abc.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39589MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function parse_metadata() located in abc.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39590MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function params_dump() located in abc.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39591MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_GetShapeBoundingBox() located in swfshape.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39592MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_uint() located in pool.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39593MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_FontExtract_DefineFontInfo() located in swftext.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39594MEDIUMCVSS 5.5EG 5.52021-09-20
Other An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function updateusage() located in swftext.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39596MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function code_parse() located in code.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39597MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function code_dump2() located in code.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39598MEDIUMCVSS 5.5EG 5.52021-09-20
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function callcode() located in code.c. It allows an attacker to cause Denial of Service.
- CVE-2021-39804MEDIUMCVSS 6.5EG 6.52022-04-12
In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could lead to remote persistent denial of service in the file picker with no additional execution privileges needed. User interaction is needed f…
- CVE-2021-39849MEDIUMCVSS 5.5EG 5.52021-09-29
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …
- CVE-2021-39850MEDIUMCVSS 5.5EG 5.52021-09-29
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …
- CVE-2021-39851MEDIUMCVSS 5.5EG 5.52021-09-29
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …
- CVE-2021-39852MEDIUMCVSS 5.5EG 5.52021-09-29
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …
- CVE-2021-39853MEDIUMCVSS 5.5EG 5.52021-09-29
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …
- CVE-2021-39854MEDIUMCVSS 5.5EG 5.52021-09-29
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …
- CVE-2021-39860MEDIUMCVSS 5.5EG 5.52021-09-29
Acrobat Pro DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to …
- CVE-2021-39920HIGHCVSS 7.5EG 7.52021-11-18
NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
- CVE-2021-39921HIGHCVSS 7.5EG 7.52021-11-19
NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- CVE-2021-39923HIGHCVSS 7.5EG 7.52021-11-19
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- CVE-2021-39928HIGHCVSS 7.5EG 7.52021-11-18
NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- CVE-2021-39973HIGHCVSS 7.5EG 7.52022-01-03
There is a Null pointer dereference in Smartphones.Successful exploitation of this vulnerability may cause the kernel to break down.
- CVE-2021-39977HIGHCVSS 7.5EG 7.52022-01-03
The HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may cause a process to restart.
- CVE-2021-39988HIGHCVSS 7.5EG 7.52022-01-03
The HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may cause a process to restart.
- CVE-2021-40018HIGHCVSS 7.5EG 7.52022-01-10
The eID module has a null pointer reference vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2021-40027HIGHCVSS 7.5EG 7.52022-01-10
The bone voice ID TA has a vulnerability in calculating the buffer length,Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2021-40031HIGHCVSS 7.5EG 7.52022-01-10
There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.
- CVE-2021-40039HIGHCVSS 7.5EG 7.52022-01-10
There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.
- CVE-2021-40157HIGHCVSS 7.8EG 7.82021-09-15
A user may be tricked into opening a malicious FBX file which may exploit an Untrusted Pointer Dereference vulnerability in FBX’s Review version 1.5.0 and prior causing it to run arbitrary code on the system.
- CVE-2021-40264MEDIUMCVSS 6.5EG 6.52023-08-22
NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag function inFreeImageTag.cpp.
- CVE-2021-40266MEDIUMCVSS 6.5EG 6.52023-08-22
FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference.
- CVE-2021-4043MEDIUMCVSS 5.5EG 5.52022-02-04
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.
- CVE-2021-40559MEDIUMCVSS 5.5EG 5.52022-01-12
A null pointer deference vulnerability exists in gpac through 1.0.1 via the naludmx_parse_nal_avc function in reframe_nalu, which allows a denail of service.
- CVE-2021-40563MEDIUMCVSS 5.5EG 5.52022-01-12
A Segmentation fault exists casued by null pointer dereference exists in Gpac through 1.0.1 via the naludmx_create_avc_decoder_config function in reframe_nalu.c when using mp4box, which causes a denial of service.
- CVE-2021-40564MEDIUMCVSS 5.5EG 5.52022-01-12
A Segmentation fault caused by null pointer dereference vulnerability eists in Gpac through 1.0.2 via the avc_parse_slice function in av_parsers.c when using mp4box, which causes a denial of service.
- CVE-2021-40565MEDIUMCVSS 5.5EG 5.52022-01-12
A Segmentation fault caused by a null pointer dereference vulnerability exists in Gpac through 1.0.1 via the gf_avc_parse_nalu function in av_parsers.c when using mp4box, which causes a denial of service.
- CVE-2021-40575MEDIUMCVSS 5.5EG 5.52022-01-13
The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the mpgviddmx_process function in reframe_mpgvid.c, which allows attackers to cause a denial of service. This vulnerability is possibly due to an incomplete fi…
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →