CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,484 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 42 of 110
- CVE-2022-21739MEDIUMCVSS 6.5EG 6.52022-02-03
Tensorflow is an Open Source Machine Learning Framework. The implementation of `QuantizedMaxPool` has an undefined behavior where user controlled inputs can trigger a reference binding to null pointer. The fix will be included in TensorFlo…
- CVE-2022-21815MEDIUMCVSS 5.5EG 5.52022-02-07
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of servic…
- CVE-2022-2208MEDIUMCVSS 5.5EG 5.52022-06-27
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.
- CVE-2022-22210MEDIUMCVSS 6.5EG 6.52022-07-20
A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX5000 Series and MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). On QFX5K Series and…
- CVE-2022-22231HIGHCVSS 7.5EG 7.52022-10-18
An Unchecked Return Value to NULL Pointer Dereference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On SRX Series if Unifi…
- CVE-2022-22232HIGHCVSS 7.5EG 7.52022-10-18
A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On SRX Series If Unified Threat Manag…
- CVE-2022-22233MEDIUMCVSS 5.5EG 5.52022-10-18
An Unchecked Return Value to NULL Pointer Dereference vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service…
- CVE-2022-2231MEDIUMCVSS 5.5EG 5.52022-06-28
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.
- CVE-2022-22510HIGHCVSS 7.5EG 7.52022-02-02
Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack of an unauthenticated user via SNMP.
- CVE-2022-22513MEDIUMCVSS 6.5EG 6.52022-04-07
An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
- CVE-2022-22638MEDIUMCVSS 6.5EG 6.52022-03-18
A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, Security Update 2022-003 Catalina, watchOS 8.5, macOS Monterey 12.3. An attacker in a priv…
- CVE-2022-2279MEDIUMCVSS 5.5EG 5.52022-07-01
NULL Pointer Dereference in GitHub repository bfabiszewski/libmobi prior to 0.11.
- CVE-2022-23016HIGHCVSS 7.5EG 7.52022-01-25
On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP SSL Forward Proxy with TLS 1.3 is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software…
- CVE-2022-23017HIGHCVSS 7.5EG 7.52022-01-25
On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when a virtual server is configured with a DNS profile with the Rapid Response Mode setting enabled and is configured on a BI…
- CVE-2022-23020HIGHCVSS 7.5EG 7.52022-01-25
On BIG-IP version 16.1.x before 16.1.2, when the 'Respond on Error' setting is enabled on the Request Logging profile and configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.…
- CVE-2022-23021HIGHCVSS 7.5EG 7.52022-01-25
On BIG-IP version 16.1.x before 16.1.2, when any of the following configurations are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate: HTTP redirect rule in an LTM policy,…
- CVE-2022-23022HIGHCVSS 7.5EG 7.52022-01-25
On BIG-IP version 16.1.x before 16.1.2, when an HTTP profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technic…
- CVE-2022-23025HIGHCVSS 7.5EG 7.52022-01-25
On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (…
- CVE-2022-2309HIGHCVSS 7.5EG 7.52022-07-05
NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggerin…
- CVE-2022-23094HIGHCVSS 7.5EG 7.52022-01-15
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.
- CVE-2022-23189MEDIUMCVSS 5.5EG 5.52022-02-16
Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in…
- CVE-2022-23198MEDIUMCVSS 5.5EG 5.52022-02-16
Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in…
- CVE-2022-23199MEDIUMCVSS 5.5EG 5.52022-02-16
Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in…
- CVE-2022-23222HIGHCVSS 7.8EG 7.82022-01-14
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
- CVE-2022-2337HIGHCVSS 7.5EG 7.52022-08-17
A crafted HTTP packet with a missing HTTP URI can create a denial-of-service condition in Softing Secure Integration Server V1.22.
- CVE-2022-23476HIGHCVSS 7.5EG 7.52022-12-08
Nokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from `xmlTextReaderExpand` in the method `Nokogiri::XML::Reader#attribute_hash`. This can lead…
- CVE-2022-23525MEDIUMCVSS 5.3EG 5.32022-12-15
Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the _repo_package. The _repo_ package contains a handler that processes the index file of a reposi…
- CVE-2022-23526MEDIUMCVSS 5.3EG 5.32022-12-15
Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that can cause a segmentation violation. The _chartutil_ package contains a…
- CVE-2022-23570MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, TensorFlow might do a null-dereference if attributes of some mutable arguments to some operations are missing from the proto. This is guarded by…
- CVE-2022-23577MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. The implementation of `GetInitOp` is vulnerable to a crash caused by dereferencing a null pointer. The fix will be included in TensorFlow 2.8.0. We will also cherrypick this commit o…
- CVE-2022-23589MEDIUMCVSS 6.5EG 6.52022-02-04
Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow can trigger a null pointer dereference. There are 2 places where this can occur, for the same malicious alteration of a `Sav…
- CVE-2022-23595MEDIUMCVSS 5.3EG 5.32022-02-04
Tensorflow is an Open Source Machine Learning Framework. When building an XLA compilation cache, if default settings are used, TensorFlow triggers a null pointer dereference. In the default scenario, all devices are allowed, so `flr->confi…
- CVE-2022-24249MEDIUMCVSS 5.5EG 5.52022-02-04
A Null Pointer Dereference vulnerability exists in GPAC 1.1.0 via the xtra_box_write function in /box_code_base.c, which causes a Denial of Service. This vulnerability was fixed in commit 71f9871.
- CVE-2022-24574MEDIUMCVSS 5.5EG 5.52022-03-14
GPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra ().
- CVE-2022-24577HIGHCVSS 7.8EG 7.82022-03-14
GPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8_wcslen is a renamed Unicode utf8_wcslen function.)
- CVE-2022-24736LOWCVSS 3.3EG 3.32022-04-27
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server pr…
- CVE-2022-2476MEDIUMCVSS 5.5EG 5.52022-07-19
A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL ===================================================================84257==ERROR: AddressSanitizer: SEGV on unknown addre…
- CVE-2022-24808MEDIUMCVSS 6.5EG 6.52024-04-16
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL p…
- CVE-2022-24809MEDIUMCVSS 6.5EG 6.52024-04-16
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer derefe…
- CVE-2022-24810MEDIUMCVSS 6.5EG 6.52024-04-16
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. V…
- CVE-2022-25108MEDIUMCVSS 5.5EG 5.52022-03-10
Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer dereference during PDF parsing because the pointer is used without proper validation.
- CVE-2022-25258MEDIUMCVSS 4.6EG 4.62022-02-16
An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NUL…
- CVE-2022-25310MEDIUMCVSS 5.5EG 5.52022-09-06
A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. This flaw allows an attacker to pass a specially crafted file to Fribidi, leading to a crash …
- CVE-2022-2547HIGHCVSS 7.5EG 7.52022-08-17
A crafted HTTP packet without a content-type header can create a denial-of-service condition in Softing Secure Integration Server V1.22.
- CVE-2022-2549MEDIUMCVSS 5.5EG 5.52022-07-27
NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV.
- CVE-2022-25710HIGHCVSS 7.5EG 7.52022-11-15
Denial of service due to null pointer dereference when GATT is disconnected in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
- CVE-2022-25733HIGHCVSS 7.5EG 7.52023-02-12
Denial of service in modem due to null pointer dereference while processing DNS packets
- CVE-2022-25735HIGHCVSS 7.5EG 7.52023-02-12
Denial of service in modem due to missing null check while processing TCP or UDP packets from server
- CVE-2022-25739HIGHCVSS 7.5EG 7.52023-04-13
Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call
- CVE-2022-25741HIGHCVSS 7.5EG 7.52022-11-15
Denial of service in WLAN due to potential null pointer dereference while accessing the memory location in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →