CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,484 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 45 of 110
- CVE-2022-36011MEDIUMCVSS 5.9EG 5.92022-09-16
TensorFlow is an open source platform for machine learning. When `mlir::tfg::ConvertGenericFunctionToFunctionDef` is given empty function attributes, it gives a null dereference. We have patched the issue in GitHub commit 1cf45b831eeb0cab8…
- CVE-2022-36013MEDIUMCVSS 5.9EG 5.92022-09-16
TensorFlow is an open source platform for machine learning. When `mlir::tfg::GraphDefImporter::ConvertNodeDef` tries to convert NodeDefs without an op name, it crashes. We have patched the issue in GitHub commit a0f0b9a21c9270930457095092f…
- CVE-2022-36014MEDIUMCVSS 5.9EG 5.92022-09-16
TensorFlow is an open source platform for machine learning. When `mlir::tfg::TFOp::nameAttr` receives null type list attributes, it crashes. We have patched the issue in GitHub commits 3a754740d5414e362512ee981eefba41561a63a6 and a0f0b9a21…
- CVE-2022-3606MEDIUMCVSS 3.5EG 5.52022-10-19
A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by_sec_insn of the file tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null pointer dereference. …
- CVE-2022-36151MEDIUMCVSS 5.5EG 5.52022-08-16
tifig v0.2.2 was discovered to contain a segmentation violation via getType() at /common/bbox.cpp.
- CVE-2022-36153MEDIUMCVSS 5.5EG 5.52022-08-16
tifig v0.2.2 was discovered to contain a segmentation violation via std::vector<unsigned int, std::allocator<unsigned int> >::size() const at /bits/stl_vector.h.
- CVE-2022-36186HIGHCVSS 7.5EG 7.52022-08-17
A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in …
- CVE-2022-3621HIGHCVSS 4.3EG 7.52022-10-20
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_bmap_lookup_at_level of the file fs/nilfs2/inode.c of the component nilfs2. The manipulation leads to null pointer dereference…
- CVE-2022-36227CRITICALCVSS 9.8EG 9.82022-11-22
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites t…
- CVE-2022-36621HIGHCVSS 7.5EG 7.52022-09-01
Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_AllocateTransientObject.
- CVE-2022-36622HIGHCVSS 7.5EG 7.52022-09-01
Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1.
- CVE-2022-3663MEDIUMCVSS 5.3EG 5.52022-10-26
A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. This issue affects the function AP4_StsdAtom of the file Ap4StsdAtom.cpp of the component MP4fragment. The manipulation leads to null pointer dereference. The…
- CVE-2022-36648CRITICALCVSS 10.0EG 10.02023-08-22
The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in …
- CVE-2022-36659MEDIUMCVSS 6.5EG 6.52022-09-07
xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_write(). This vulnerability allows attackers to cause a Denial of Service via unspecified vectors.
- CVE-2022-36661MEDIUMCVSS 6.5EG 6.52022-09-07
xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_read(). This vulnerability allows attackers to cause a Denial of Service via unspecified vectors.
- CVE-2022-37290MEDIUMCVSS 5.5EG 5.52022-11-14
GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.
- CVE-2022-37797HIGHCVSS 7.5EG 7.52022-09-12
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external at…
- CVE-2022-38096MEDIUMCVSS 6.3EG 6.32022-09-09
A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user acc…
- CVE-2022-38307MEDIUMCVSS 5.5EG 5.52022-09-13
LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::file_offset() at /MachO/SegmentCommand.cpp.
- CVE-2022-38497MEDIUMCVSS 5.5EG 5.52022-09-13
LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69.
- CVE-2022-38928HIGHCVSS 7.8EG 7.82022-09-21
XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
- CVE-2022-39028HIGHCVSS 7.5EG 7.52022-08-30
telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would …
- CVE-2022-39381HIGHCVSS 7.5EG 7.52022-11-02
Muhammara is a node module with c/cpp bindings to modify PDF with js for node or electron (based/replacement on/of galkhana/hummusjs). The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (…
- CVE-2022-39829HIGHCVSS 7.5EG 7.52022-09-05
There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_new.
- CVE-2022-39837MEDIUMCVSS 5.5EG 5.52022-10-25
An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can be created. This is due to missing validation checks. There …
- CVE-2022-40476MEDIUMCVSS 5.5EG 5.52022-09-14
A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service.
- CVE-2022-40732MEDIUMCVSS 5.0EG 5.02024-12-18
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.64…
- CVE-2022-40733MEDIUMCVSS 5.0EG 5.02024-12-18
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.64…
- CVE-2022-40738MEDIUMCVSS 6.5EG 6.52022-09-15
An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, called from AP4_EsDescriptor::WriteFields and AP4_Expandable::Write.
- CVE-2022-40759HIGHCVSS 7.5EG 7.52022-09-16
A NULL pointer dereference issue in the TEE_MACCompareFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_MACCompareFinal with a NULL pointer for the…
- CVE-2022-40774MEDIUMCVSS 5.5EG 5.52022-09-18
An issue was discovered in Bento4 through 1.6.0-639. There is a NULL pointer dereference in AP4_StszAtom::GetSampleSize.
- CVE-2022-40775MEDIUMCVSS 5.5EG 5.52022-09-18
An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_StszAtom::WriteFields.
- CVE-2022-4121MEDIUMCVSS 5.5EG 5.52023-01-17
In libetpan a null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c was found that could lead to a remote denial of service or other potential consequences.
- CVE-2022-4127MEDIUMCVSS 5.5EG 5.52022-11-28
A NULL pointer dereference issue was discovered in the Linux kernel in io_files_update_with_index_alloc. A local user could use this flaw to potentially crash the system causing a denial of service.
- CVE-2022-41278MEDIUMCVSS 3.3EG 5.52022-12-13
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < …
- CVE-2022-41279MEDIUMCVSS 3.3EG 5.52022-12-13
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < …
- CVE-2022-4128MEDIUMCVSS 5.5EG 5.52022-11-28
A NULL pointer dereference issue was discovered in the Linux kernel in the MPTCP protocol when traversing the subflow list at disconnect time. A local user could use this flaw to potentially crash the system causing a denial of service.
- CVE-2022-41280MEDIUMCVSS 3.3EG 5.52022-12-13
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < …
- CVE-2022-41592LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41593LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41594LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41595LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41597LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41598LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41600LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41601LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41602LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41603LOWCVSS 3.4EG 3.42022-10-14
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
- CVE-2022-41787HIGHCVSS 7.5EG 7.52022-10-19
In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when DNS profile is configured on a virtual server with DNS Express enabled, undisclosed DNS que…
- CVE-2022-41841MEDIUMCVSS 5.5EG 5.52022-09-30
An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_File::ParseStream in Core/Ap4File.cpp, which is called from AP4_File::AP4_File.
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →