CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,484 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 44 of 110
- CVE-2022-3115MEDIUMCVSS 5.5EG 5.52022-12-14
An issue was discovered in the Linux kernel through 5.16-rc6. malidp_crtc_reset in drivers/gpu/drm/arm/malidp_crtc.c lacks check of the return value of kzalloc() and will cause the null pointer dereference.
- CVE-2022-3116HIGHCVSS 7.5EG 7.52023-03-27
The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network access to an application that depends on the vulnerable code path can cause the application to crash.
- CVE-2022-31213HIGHCVSS 7.5EG 7.52022-07-17
An issue was discovered in dbus-broker before 31. Multiple NULL pointer dereferences can be found when supplying a malformed XML config file.
- CVE-2022-3153MEDIUMCVSS 5.5EG 5.52022-09-08
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0404.
- CVE-2022-31613HIGHCVSS 7.1EG 7.12022-11-19
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where any local user can cause a null-pointer dereference, which may lead to a kernel panic.
- CVE-2022-31615MEDIUMCVSS 5.5EG 5.52022-11-19
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null-pointer dereference, which may lead to denial of service.
- CVE-2022-31618MEDIUMCVSS 5.5EG 5.52022-08-05
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a null pointer, which may lead to denial of service.
- CVE-2022-31681MEDIUMCVSS 6.5EG 6.52022-10-07
VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host.
- CVE-2022-31763MEDIUMCVSS 5.5EG 5.52022-06-13
The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitation of this vulnerability may affect system availability.
- CVE-2022-3202HIGHCVSS 7.1EG 7.12022-09-14
A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information.
- CVE-2022-32201MEDIUMCVSS 5.5EG 5.52022-06-02
In libjpeg 1.63, there is a NULL pointer dereference in Component::SubXOf in component.hpp.
- CVE-2022-32202MEDIUMCVSS 5.5EG 5.52022-06-02
In libjpeg 1.63, there is a NULL pointer dereference in LineBuffer::FetchRegion in linebuffer.cpp.
- CVE-2022-32230HIGHCVSS 7.5EG 7.52022-06-14
Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the April, 2022 patch set. By sending a malformed FileNormalizedNameInformation SMBv3 request over a named pipe, an attacker can cause a Blue S…
- CVE-2022-32298HIGHCVSS 7.5EG 7.52022-07-14
Toybox v0.8.7 was discovered to contain a NULL pointer dereference via the component httpd.c. This vulnerability can lead to a Denial of Service (DoS) via unspecified vectors.
- CVE-2022-32455HIGHCVSS 7.5EG 7.52022-08-04
In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when a BIG-IP LTM Client SSL profile is configured on a virtual server to perform client certificate authentication with s…
- CVE-2022-32663HIGHCVSS 7.5EG 7.52023-02-06
In Wi-Fi driver, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN202…
- CVE-2022-3278MEDIUMCVSS 5.5EG 5.52022-09-23
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.
- CVE-2022-32785MEDIUMCVSS 5.5EG 5.52022-09-23
A null pointer dereference was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. Processing an image may lead to a denial-of-s…
- CVE-2022-33223HIGHCVSS 7.5EG 7.52023-04-13
Transient DOS in Modem due to null pointer dereference while processing the incoming packet with http chunked encoding.
- CVE-2022-33290HIGHCVSS 7.5EG 7.52023-01-09
Transient DOS in Bluetooth HOST due to null pointer dereference when a mismatched argument is passed.
- CVE-2022-33294HIGHCVSS 7.5EG 7.52023-04-13
Transient DOS in Modem due to NULL pointer dereference while receiving response of lwm2m registration/update/bootstrap request message.
- CVE-2022-33299HIGHCVSS 7.5EG 7.52023-01-09
Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data.
- CVE-2022-33304HIGHCVSS 7.5EG 7.52023-05-02
Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet.
- CVE-2022-33305HIGHCVSS 7.5EG 7.52023-05-02
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH.
- CVE-2022-3341MEDIUMCVSS 5.3EG 5.32023-01-12
A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c file. The flaw occurs because the function lacks check of the return value of avformat_new_stream() and triggers the null …
- CVE-2022-3358HIGHCVSS 7.5EG 7.52022-10-11
OpenSSL supports creating a custom cipher via the legacy EVP_CIPHER_meth_new() function and associated function calls. This function was deprecated in OpenSSL 3.0 and application authors are instead encouraged to use the new provider mecha…
- CVE-2022-34520MEDIUMCVSS 5.5EG 5.52022-07-22
Radare2 v5.7.2 was discovered to contain a NULL pointer dereference via the function r_bin_file_xtr_load_buffer at bin/bfile.c. This vulnerability allows attackers to cause a Denial of Service (DOS) via a crafted binary file.
- CVE-2022-34556MEDIUMCVSS 5.5EG 5.52022-07-28
PicoC v3.2.2 was discovered to contain a NULL pointer dereference at variable.c.
- CVE-2022-34651HIGHCVSS 7.5EG 7.52022-08-04
In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, when an LTM Client or Server SSL profile with TLS 1.3 enabled is configured on a virtual server, along with an iRule that calls HTTP::respond, undisclosed requests can c…
- CVE-2022-34665MEDIUMCVSS 6.5EG 6.52022-11-19
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null-pointer dereference, which may lead to denial of service.
- CVE-2022-34666MEDIUMCVSS 6.5EG 6.52022-11-10
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null-pointer dereference, which may lead to denial of service.
- CVE-2022-34675MEDIUMCVSS 5.5EG 5.52022-12-30
NVIDIA Display Driver for Linux contains a vulnerability in the Virtual GPU Manager, where it does not check the return value from a null-pointer dereference, which may lead to denial of service.
- CVE-2022-34678MEDIUMCVSS 6.5EG 6.52022-12-30
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause a null-pointer dereference, which may lead to denial of service.
- CVE-2022-34679MEDIUMCVSS 5.5EG 5.52022-12-30
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unhandled return value can lead to a null-pointer dereference, which may lead to denial of service.
- CVE-2022-34682MEDIUMCVSS 5.5EG 5.52022-12-30
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a null-pointer dereference, which may lead to denial of service.
- CVE-2022-34683MEDIUMCVSS 5.5EG 5.52022-12-30
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a null-pointer dereference occurs, which may lead to denial of service.
- CVE-2022-34735HIGHCVSS 7.5EG 7.52022-07-12
The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
- CVE-2022-34736HIGHCVSS 7.5EG 7.52022-07-12
The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.
- CVE-2022-34761HIGHCVSS 7.5EG 7.52022-07-13
A CWE-476: NULL Pointer Dereference vulnerability exists that could cause a denial of service of the webserver when parsing JSON content type. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA…
- CVE-2022-34969HIGHCVSS 7.5EG 7.52022-08-03
PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.
- CVE-2022-35087MEDIUMCVSS 5.5EG 5.52022-09-21
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c.
- CVE-2022-35108MEDIUMCVSS 5.5EG 5.52022-08-16
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via DCTStream::getChar() at /xpdf/Stream.cc.
- CVE-2022-35206MEDIUMCVSS 5.5EG 5.52023-08-22
Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c.
- CVE-2022-35245HIGHCVSS 7.5EG 7.52022-08-04
In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5.1, when a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to ter…
- CVE-2022-35484MEDIUMCVSS 6.5EG 6.52022-08-16
OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6b6a8f.
- CVE-2022-3563MEDIUMCVSS 3.5EG 5.72022-10-17
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function read_50_controller_cap_complete of the file tools/mgmt-tester.c of the component BlueZ. The manipulation of the argument cap_len leads to nu…
- CVE-2022-35691MEDIUMCVSS 5.5EG 5.52022-10-14
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denia…
- CVE-2022-35883MEDIUMCVSS 2.2EG 5.52023-02-16
NULL pointer dereference in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-35965MEDIUMCVSS 5.9EG 5.92022-09-16
TensorFlow is an open source platform for machine learning. If `LowerBound` or `UpperBound` is given an empty`sorted_inputs` input, it results in a `nullptr` dereference, leading to a segfault that can be used to trigger a denial of servic…
- CVE-2022-36000MEDIUMCVSS 5.9EG 5.92022-09-16
TensorFlow is an open source platform for machine learning. When `mlir::tfg::ConvertGenericFunctionToFunctionDef` is given empty function attributes, it gives a null dereference. We have patched the issue in GitHub commit aed36912609fc0722…
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →