CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,484 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 36 of 110
- CVE-2021-40576MEDIUMCVSS 5.5EG 5.52022-01-13
The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the gf_isom_get_payt_count function in hint_track.c, which allows attackers to cause a denial of service.
- CVE-2021-40732MEDIUMCVSS 6.1EG 6.12021-10-13
XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in leaking data from certain memory locations and causing a local denial of service in the context of the current user. User…
- CVE-2021-40737MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Audition version 14.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-serv…
- CVE-2021-40742MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Audition version 14.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-serv…
- CVE-2021-40750MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Bridge version 11.1.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-serv…
- CVE-2021-40756MEDIUMCVSS 5.5EG 5.52021-11-18
Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-…
- CVE-2021-40761MEDIUMCVSS 5.5EG 5.52021-11-18
Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-…
- CVE-2021-40762MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Character Animator version 4.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denia…
- CVE-2021-40768MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Character Animator version 4.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denia…
- CVE-2021-40773MEDIUMCVSS 5.5EG 5.52021-11-22
Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-servi…
- CVE-2021-40774MEDIUMCVSS 5.5EG 5.52021-11-22
Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-servi…
- CVE-2021-40778MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Media Encoder 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-servi…
- CVE-2021-40781MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Media Encoder 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-servi…
- CVE-2021-40782MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Media Encoder 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-servi…
- CVE-2021-40785MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Premiere Elements 20210809.daily.2242976 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an applica…
- CVE-2021-40788MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Premiere Elements 20210809.daily.2242976 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an applica…
- CVE-2021-40789MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Premiere Elements 20210809.daily.2242976 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an applica…
- CVE-2021-40796MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-servic…
- CVE-2021-40826HIGHCVSS 7.8EG 7.82021-12-15
Clementine Music Player through 1.3.1 is vulnerable to a User Mode Write Access Violation, affecting the MP3 file parsing functionality at clementine+0x3aa207. The vulnerability is triggered when the user opens a crafted MP3 file or loads …
- CVE-2021-40943MEDIUMCVSS 5.5EG 5.52022-06-28
In Bento4 1.6.0-638, there is a null pointer reference in the function AP4_DescriptorListInspector::Action function in Ap4Descriptor.h:124 , as demonstrated by GPAC. This can cause a denial of service (DOS).
- CVE-2021-40944MEDIUMCVSS 5.5EG 5.52022-06-28
In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filter_pid_get_packet function in src/filter_core/filter_pid.c:5394, as demonstrated by GPAC. This can cause a denial of service (DOS).
- CVE-2021-4095MEDIUMCVSS 5.5EG 5.52022-03-10
A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring logging is enabled without an active vCPU context. An unprivileged local attacker on the host may use this flaw to cause a kernel oops condition and thus a deni…
- CVE-2021-4110HIGHCVSS 7.5EG 7.52021-12-15
mruby is vulnerable to NULL Pointer Dereference
- CVE-2021-41208HIGHCVSS 8.8EG 8.82021-11-05
TensorFlow is an open source platform for machine learning. In affected versions the code for boosted trees in TensorFlow is still missing validation. As a result, attackers can trigger denial of service (via dereferencing `nullptr`s or vi…
- CVE-2021-41215MEDIUMCVSS 5.5EG 5.52021-11-05
TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `DeserializeSparse` can trigger a null pointer dereference. This is because the shape inference function assumes that the `serial…
- CVE-2021-41217MEDIUMCVSS 5.5EG 5.52021-11-05
TensorFlow is an open source platform for machine learning. In affected versions the process of building the control flow graph for a TensorFlow model is vulnerable to a null pointer exception when nodes that should be paired are not. This…
- CVE-2021-4145MEDIUMCVSS 6.5EG 6.52022-01-25
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user wi…
- CVE-2021-41495MEDIUMCVSS 5.3EG 5.32021-12-17
Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacks by repetitively creating sort arrays. …
- CVE-2021-41497HIGHCVSS 7.5EG 7.52021-12-17
Null pointer reference in CMS_Conservative_increment_obj in RaRe-Technologies bounter version 1.01 and 1.10, allows attackers to conduct Denial of Service attacks by inputting a huge width of hash bucket.
- CVE-2021-41524HIGHCVSS 7.5EG 7.52021-10-05
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduc…
- CVE-2021-4158MEDIUMCVSS 6.0EG 6.02022-08-24
A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.
- CVE-2021-41689HIGHCVSS 7.5EG 7.52022-06-28
DCMTK through 3.6.6 does not handle string copy properly. Sending specific requests to the dcmqrdb program, it would query its database and copy the result even if the result is null, which can incur a head-based overflow. An attacker can …
- CVE-2021-41839HIGHCVSS 8.2EG 8.22022-02-03
An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM.…
- CVE-2021-4186HIGHCVSS 6.3EG 7.52021-12-30
Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
- CVE-2021-4188HIGHCVSS 7.5EG 7.52021-12-30
mruby is vulnerable to NULL Pointer Dereference
- CVE-2021-4198MEDIUMCVSS 6.1EG 6.12022-03-07
A NULL Pointer Dereference vulnerability in the messaging_ipc.dll component as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools, VPN Standalone allows an attacker to arbitrarily crash product p…
- CVE-2021-4209MEDIUMCVSS 6.5EG 6.52022-08-24
A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare ci…
- CVE-2021-4217HIGHCVSS 3.3EG 7.82022-08-24
A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code e…
- CVE-2021-42196MEDIUMCVSS 5.5EG 5.52022-06-02
An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function traits_parse() located in abc.c. It allows an attacker to cause Denial of Service.
- CVE-2021-42198MEDIUMCVSS 5.5EG 5.52022-06-02
An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_GetBits() located in rfxswf.c. It allows an attacker to cause Denial of Service.
- CVE-2021-42200MEDIUMCVSS 5.5EG 5.52022-06-02
An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function main() located in swfdump.c. It allows an attacker to cause Denial of Service.
- CVE-2021-42202MEDIUMCVSS 5.5EG 5.52022-06-02
An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_DeleteFilter() located in swffilter.c. It allows an attacker to cause Denial of Service.
- CVE-2021-42263MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-servic…
- CVE-2021-42264MEDIUMCVSS 5.5EG 5.52022-03-16
Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-servic…
- CVE-2021-42268MEDIUMCVSS 5.5EG 5.52021-11-18
Adobe Animate version 21.0.9 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted FLA file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of…
- CVE-2021-4236CRITICALCVSS 9.8EG 9.82022-12-27
Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with a…
- CVE-2021-42373MEDIUMCVSS 5.5EG 5.52021-11-15
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
- CVE-2021-42376MEDIUMCVSS 5.5EG 5.52021-11-15
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filt…
- CVE-2021-42521HIGHCVSS 7.5EG 7.52022-08-25
There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe …
- CVE-2021-42528MEDIUMCVSS 5.5EG 5.52022-05-02
XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in t…
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →