CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,484 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 46 of 110
- CVE-2022-41843MEDIUMCVSS 5.5EG 5.52022-09-30
An issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerability than CVE-2022-38928.
- CVE-2022-41858HIGHCVSS 7.1EG 7.12023-01-17
A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach in sl_tx_timeout in drivers/net/slip/slip.c. This issue could allow an attacker to crash the system or leak internal ke…
- CVE-2022-41860HIGHCVSS 7.5EG 7.52023-01-17
In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will deref…
- CVE-2022-41889MEDIUMCVSS 5.5EG 5.52022-11-18
TensorFlow is an open source platform for machine learning. If a list of quantized tensors is assigned to an attribute, the pywrap code fails to parse the tensor and returns a `nullptr`, which is not caught. An example can be seen in `tf.c…
- CVE-2022-41909MEDIUMCVSS 4.8EG 4.82022-11-18
TensorFlow is an open source platform for machine learning. An input `encoded` that is not a valid `CompositeTensorVariant` tensor will trigger a segfault in `tf.raw_ops.CompositeTensorVariantToComponents`. We have patched the issue in Git…
- CVE-2022-41972LOWCVSS 2.9EG 2.92022-12-16
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to 4.9 contain a NULL Pointer Dereference in BLE L2CAP module. The Contiki-NG operating system for IoT devices contains a Bluetoo…
- CVE-2022-41999HIGHCVSS 7.5EG 7.52022-12-22
A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2. A specially-crafted .dds can lead to denial of service. An attacker can provide a malicious fi…
- CVE-2022-42306MEDIUMCVSS 6.5EG 6.52022-10-03
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can send a crafted packet to pbx_exchange during registration and cause a NULL pointer exception, effectively crashing the…
- CVE-2022-42335HIGHCVSS 7.8EG 7.82023-04-25
x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Due to too lax a check in…
- CVE-2022-42527HIGHCVSS 7.5EG 7.52022-12-16
In cd_SsParseMsg of cd_SsCodec.c, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A…
- CVE-2022-42722MEDIUMCVSS 5.5EG 5.52022-10-14
In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices.
- CVE-2022-4285MEDIUMCVSS 5.5EG 5.52023-01-27
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
- CVE-2022-42878LOWCVSS 2.8EG 2.82023-05-10
Null pointer dereference for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2022-42879MEDIUMCVSS 6.1EG 6.12023-11-14
NULL pointer dereference in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-42928HIGHCVSS 8.8EG 8.82022-12-22
Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 106, Firefox ESR <…
- CVE-2022-43495HIGHCVSS 6.5EG 7.52022-11-03
OpenHarmony-v3.1.2 and prior versions had a DOS vulnerability in distributedhardware_device_manager when joining a network. Network attakcers can send an abonormal packet when joining a network, cause a nullptr reference and device reboot.
- CVE-2022-43588MEDIUMCVSS 5.5EG 5.52022-11-28
A null pointer dereference vulnerability exists in the handle_ioctl_83150 functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an io…
- CVE-2022-43589MEDIUMCVSS 5.5EG 5.52022-11-28
A null pointer dereference vulnerability exists in the handle_ioctl_8314C functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an io…
- CVE-2022-43590MEDIUMCVSS 5.5EG 5.52022-11-28
A null pointer dereference vulnerability exists in the handle_ioctl_0x830a0_systembuffer functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker …
- CVE-2022-43593MEDIUMCVSS 5.9EG 5.92022-12-22
A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to null pointer dereference. An attacker can provide malicious in…
- CVE-2022-43594MEDIUMCVSS 5.9EG 5.92022-12-22
Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can p…
- CVE-2022-43595MEDIUMCVSS 5.9EG 5.92022-12-22
Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially crafted ImageOutput Objects can lead to multiple null pointer dereferences. An attacker can p…
- CVE-2022-43603MEDIUMCVSS 5.9EG 5.92022-12-22
A denial of service vulnerability exists in the ZfileOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to denial of service. An attacker can provide a malicious file …
- CVE-2022-43972HIGHCVSS 6.5EG 7.52023-01-09
A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A null pointer dereference in the soap_action function within the upnp binary can be triggered by an unauthenticat…
- CVE-2022-44018HIGHCVSS 7.5EG 7.52023-01-26
In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer dereference or out-of-bounds memory access in the subscriber application.
- CVE-2022-44368MEDIUMCVSS 5.5EG 5.52023-03-29
NASM v2.16 was discovered to contain a null pointer deference in the NASM component
- CVE-2022-44369MEDIUMCVSS 5.5EG 5.52023-03-29
NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.
- CVE-2022-44447MEDIUMCVSS 5.5EG 5.52023-02-12
In wlan driver, there is a possible null pointer dereference issue due to a missing bounds check. This could lead to local denial of service in wlan services.
- CVE-2022-44792HIGHCVSS 6.5EG 7.52022-11-07
handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, …
- CVE-2022-44793HIGHCVSS 6.5EG 7.62022-11-07
handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Deni…
- CVE-2022-47015HIGHCVSS 6.5EG 7.52023-01-20
MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.
- CVE-2022-47021HIGHCVSS 7.8EG 7.82023-01-20
A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or other unspecified impacts.
- CVE-2022-47022CRITICALCVSS 4.7EG 9.82023-08-22
An issue was discovered in open-mpi hwloc 2.1.0 allows attackers to cause a denial of service or other unspecified impacts via glibc-cpuset in topology-linux.c.
- CVE-2022-47024HIGHCVSS 7.8EG 7.82023-01-20
A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts.
- CVE-2022-47094HIGHCVSS 7.8EG 7.82023-01-05
GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Null pointer dereference via filters/dmx_m2ts.c:343 in m2tsdmx_declare_pid
- CVE-2022-47359MEDIUMCVSS 5.5EG 5.52023-02-12
In log service, there is a missing permission check. This could lead to local denial of service in log service.
- CVE-2022-47360MEDIUMCVSS 5.5EG 5.52023-02-12
In log service, there is a missing permission check. This could lead to local denial of service in log service.
- CVE-2022-47465MEDIUMCVSS 5.5EG 5.52023-04-11
In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.
- CVE-2022-47466MEDIUMCVSS 5.5EG 5.52023-04-11
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- CVE-2022-47467MEDIUMCVSS 5.5EG 5.52023-04-11
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- CVE-2022-47468MEDIUMCVSS 5.5EG 5.52023-04-11
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
- CVE-2022-47929MEDIUMCVSS 5.5EG 5.52023-01-17
In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with "tc…
- CVE-2022-48231MEDIUMCVSS 5.5EG 5.52023-05-09
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- CVE-2022-48241MEDIUMCVSS 5.5EG 5.52023-05-09
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- CVE-2022-4842MEDIUMCVSS 5.5EG 5.52023-01-12
A flaw NULL Pointer Dereference in the Linux kernel NTFS3 driver function attr_punch_hole() was found. A local user could use this flaw to crash the system.
- CVE-2022-4843HIGHCVSS 7.5EG 7.52022-12-29
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.8.2.
- CVE-2022-48442MEDIUMCVSS 5.5EG 5.52023-06-06
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- CVE-2022-48443MEDIUMCVSS 5.5EG 5.52023-06-06
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- CVE-2022-48444MEDIUMCVSS 5.5EG 5.52023-06-06
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- CVE-2022-48445MEDIUMCVSS 5.5EG 5.52023-06-06
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →