CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,487 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 56 of 110
- CVE-2023-33307MEDIUMCVSS 6.5EG 6.52023-06-16
A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter.
- CVE-2023-3338HIGHCVSS 6.5EG 7.52023-06-30
A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system.
- CVE-2023-33461MEDIUMCVSS 5.5EG 5.52023-06-01
iniparser v4.1 is vulnerable to NULL Pointer Dereference in function iniparser_getlongint which misses check NULL for function iniparser_getstring's return.
- CVE-2023-3354HIGHCVSS 7.5EG 7.52023-07-11
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous con…
- CVE-2023-3355MEDIUMCVSS 4.7EG 5.52023-06-28
A NULL pointer dereference flaw was found in the Linux kernel's drivers/gpu/drm/msm/msm_gem_submit.c code in the submit_lookup_cmds function, which fails because it lacks a check of the return value of kmalloc(). This issue allows a local …
- CVE-2023-3357MEDIUMCVSS 5.5EG 5.52023-06-28
A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local user to crash the system.
- CVE-2023-3358MEDIUMCVSS 5.5EG 5.52023-06-28
A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a local user to crash the system.
- CVE-2023-3359MEDIUMCVSS 5.5EG 5.52023-06-28
An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the return value of kzalloc() can cause the NULL Pointer Dereference.
- CVE-2023-33973HIGHCVSS 7.5EG 7.52023-05-30
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In versions 2023.01 and prior, an attacker can send a crafted frame which is forwarded by the device. D…
- CVE-2023-34164HIGHCVSS 7.5EG 7.52023-07-06
Vulnerability of incomplete input parameter verification in the communication framework module. Successful exploitation of this vulnerability may affect availability.
- CVE-2023-34323MEDIUMCVSS 5.5EG 5.52024-01-05
When a transaction is committed, C Xenstored will first check the quota is correct before attempting to commit any nodes. It would be possible that accounting is temporarily negative if a node has been removed outside of the transaction. …
- CVE-2023-34398HIGHCVSS 7.5EG 7.52025-02-13
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The boost library contains a vulnerability/null pointer dereference.
- CVE-2023-34400HIGHCVSS 7.5EG 7.52025-02-13
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. In case of parsing file, service try to define header inside the file and convert it to null-terminated string. If character is missed, will ret…
- CVE-2023-35338HIGHCVSS 7.5EG 7.52023-07-11
Windows Peer Name Resolution Protocol Denial of Service Vulnerability
- CVE-2023-3603LOWCVSS 3.1EG 3.12023-07-21
A missing allocation check in sftp server processing read requests may cause a NULL dereference on low-memory conditions. The malicious client can request up to 4GB SFTP reads, causing allocation of up to 4GB buffers, which was not being c…
- CVE-2023-36199HIGHCVSS 7.5EG 7.52023-08-25
An issue in skalenetwork sgxwallet v.1.9.0 and below allows an attacker to cause a denial of service via the trustedGenerateEcdsaKey component.
- CVE-2023-36602HIGHCVSS 7.5EG 7.52023-10-10
Windows TCP/IP Denial of Service Vulnerability
- CVE-2023-36603HIGHCVSS 7.5EG 7.52023-10-10
Windows TCP/IP Denial of Service Vulnerability
- CVE-2023-36709HIGHCVSS 7.5EG 7.52023-10-10
Microsoft AllJoyn API Denial of Service Vulnerability
- CVE-2023-37025MEDIUMCVSS 6.5EG 6.52025-01-21
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Reset` packet …
- CVE-2023-37026MEDIUMCVSS 6.5EG 6.52025-01-21
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Release …
- CVE-2023-37027MEDIUMCVSS 6.5EG 6.52025-01-21
Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Modificati…
- CVE-2023-37028MEDIUMCVSS 6.5EG 6.52025-01-21
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Modifica…
- CVE-2023-37030MEDIUMCVSS 6.5EG 6.52025-01-21
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Mes…
- CVE-2023-37031MEDIUMCVSS 6.5EG 6.52025-01-21
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `eNB Configurat…
- CVE-2023-37033MEDIUMCVSS 6.5EG 6.52025-01-21
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Mes…
- CVE-2023-37034MEDIUMCVSS 6.5EG 6.52025-01-21
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Mes…
- CVE-2023-37035MEDIUMCVSS 6.5EG 6.52025-01-21
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Reques…
- CVE-2023-37036MEDIUMCVSS 6.5EG 6.52025-01-21
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Uplink NAS Tra…
- CVE-2023-37037MEDIUMCVSS 6.5EG 6.52025-01-21
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Reques…
- CVE-2023-37038MEDIUMCVSS 6.5EG 6.52025-01-21
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Uplink NAS Tra…
- CVE-2023-37039MEDIUMCVSS 6.5EG 6.52025-01-22
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allow network-adjacent attackers to crash the MME via an S1AP `Initial UE Mess…
- CVE-2023-37185HIGHCVSS 7.5EG 7.52023-12-25
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_prec_decompress at zfp/blosc2-zfp.c.
- CVE-2023-37186HIGHCVSS 7.5EG 7.52023-12-25
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference in ndlz/ndlz8x8.c via a NULL pointer to memset.
- CVE-2023-37187HIGHCVSS 7.5EG 7.52023-12-25
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the zfp/blosc2-zfp.c zfp_acc_decompress. function.
- CVE-2023-37188HIGHCVSS 7.5EG 7.52023-12-25
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_rate_decompress at zfp/blosc2-zfp.c.
- CVE-2023-37368MEDIUMCVSS 5.9EG 5.92023-09-08
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos Mobile Processor, Automotive Processor, and Modem - Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100…
- CVE-2023-37456MEDIUMCVSS 6.5EG 6.52023-07-12
The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.
- CVE-2023-3772MEDIUMCVSS 5.5EG 5.52023-07-25
A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading…
- CVE-2023-37732MEDIUMCVSS 5.5EG 5.52023-07-26
Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacker to cause a denial of service via a crafted file.
- CVE-2023-38171HIGHCVSS 7.5EG 8.62023-10-10
Microsoft QUIC Denial of Service Vulnerability
- CVE-2023-38313HIGHCVSS 7.5EG 7.52023-11-17
An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GET HTTP request with a missing client redirect query string parameter. Triggering this issu…
- CVE-2023-38314MEDIUMCVSS 6.5EG 6.52023-11-17
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthenticated() that can be triggered with a crafted GET HTTP request with a missing redirect query string parameter. Triggeri…
- CVE-2023-38315HIGHCVSS 7.5EG 7.52023-11-17
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing client token query string parameter. Triggering thi…
- CVE-2023-38320HIGHCVSS 7.5EG 7.52023-11-17
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing User-Agent header. Triggering this issue results in cr…
- CVE-2023-38321HIGHCVSS 7.5EG 7.52023-12-25
OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ tha…
- CVE-2023-38322HIGHCVSS 7.5EG 7.52023-11-17
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafted GET HTTP request with a missing User-Agent HTTP header. Triggering this issue results in…
- CVE-2023-38524LOWCVSS 3.3EG 3.32023-08-08
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35.1 (All versions < V35.1.171), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcent…
- CVE-2023-3866MEDIUMCVSS 5.5EG 5.52025-08-16
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in the compound request This patch validate session id and tree id in compound request. If first operation in the compound is SMB2…
- CVE-2023-38665MEDIUMCVSS 5.5EG 5.52023-08-22
Null pointer dereference in ieee_write_file in nasm 2.16rc0 allows attackers to cause a denial of service (crash).
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →