CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,487 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 57 of 110
- CVE-2023-38670MEDIUMCVSS 4.7EG 4.72023-07-26
Null pointer dereference in paddle.flip in PaddlePaddle before 2.5.0. This resulted in a runtime crash and denial of service.
- CVE-2023-38676MEDIUMCVSS 4.7EG 4.72024-01-03
Nullptr in paddle.dot in PaddlePaddle before 2.6.0. This flaw can cause a runtime crash and a denial of service.
- CVE-2023-38711HIGHCVSS 6.5EG 7.52023-08-25
An issue was discovered in Libreswan before 4.12. When an IKEv1 Quick Mode connection configured with ID_IPV4_ADDR or ID_IPV6_ADDR receives an IDcr payload with ID_FQDN, a NULL pointer dereference causes a crash and restart of the pluto da…
- CVE-2023-38712HIGHCVSS 6.5EG 7.52023-08-25
An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload followed by further Notifies that act on the ISAKMP SA, such as a duplicated Delete/Notify…
- CVE-2023-39351MEDIUMCVSS 5.3EG 5.32023-08-31
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions of FreeRDP are subject to a Null Pointer Dereference leading a crash in the RemoteFX (rfx) handling. Inside the `r…
- CVE-2023-39397HIGHCVSS 7.5EG 7.52023-08-13
Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability may affect availability.
- CVE-2023-39669HIGHCVSS 7.5EG 7.52023-08-18
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a NULL pointer dereference in the function FUN_00010824.
- CVE-2023-40032MEDIUMCVSS 5.5EG 5.52023-09-11
libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade t…
- CVE-2023-40308HIGHCVSS 7.5EG 7.52023-09-12
SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There …
- CVE-2023-40360MEDIUMCVSS 5.5EG 5.52023-08-14
QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whether an endurance group is configured before checking whether Flexible Data Placement is enabled.
- CVE-2023-40459HIGHCVSS 7.5EG 7.52023-12-04
The ACEManager component of ALEOS 4.16 and earlier does not adequately perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other …
- CVE-2023-40546MEDIUMCVSS 6.2EG 6.22024-01-29
A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doe…
- CVE-2023-41234MEDIUMCVSS 5.0EG 5.02024-05-16
NULL pointer dereference in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-41274MEDIUMCVSS 5.5EG 5.52024-02-02
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network.…
- CVE-2023-41358HIGHCVSS 7.5EG 7.52023-08-29
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
- CVE-2023-41633MEDIUMCVSS 5.5EG 5.52023-09-01
Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/fileutil.c.
- CVE-2023-41909HIGHCVSS 7.5EG 7.52023-09-05
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
- CVE-2023-42754MEDIUMCVSS 5.5EG 5.52023-10-05
A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The socket buffer (skb) was assumed to be associated with a device before calling __ip_options_compile, which is not always the case if the skb is re-routed by ipvs.…
- CVE-2023-42785MEDIUMCVSS 6.5EG 6.52025-01-14
A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.
- CVE-2023-42786MEDIUMCVSS 6.5EG 6.52025-01-14
A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.
- CVE-2023-43279MEDIUMCVSS 6.5EG 6.52024-03-12
Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command.
- CVE-2023-43522HIGHCVSS 7.5EG 7.52024-02-06
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
- CVE-2023-43541HIGHCVSS 8.4EG 8.42024-03-04
Memory corruption while invoking the SubmitCommands call on Gfx engine during the graphics render.
- CVE-2023-4385MEDIUMCVSS 5.5EG 5.52023-08-16
A NULL pointer dereference flaw was found in dbFree in fs/jfs/jfs_dmap.c in the journaling file system (JFS) in the Linux Kernel. This issue may allow a local attacker to crash the system due to a missing sanity check.
- CVE-2023-43898MEDIUMCVSS 5.5EG 5.52023-10-03
Nothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted pic file.
- CVE-2023-44341MEDIUMCVSS 5.5EG 5.52024-02-29
Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in …
- CVE-2023-44347MEDIUMCVSS 5.5EG 5.52024-02-29
Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in …
- CVE-2023-4459MEDIUMCVSS 5.5EG 6.52023-08-21
A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking sub-component in vmxnet3 in the Linux Kernel. This issue may allow a local attacker with normal user privilege to cause …
- CVE-2023-45667HIGHCVSS 7.5EG 7.52023-10-21
stb_image is a single file MIT licensed library for processing images. If `stbi__load_gif_main` in `stbi_load_gif_from_memory` fails it returns a null pointer and may keep the `z` variable uninitialized. In case the caller also sets the f…
- CVE-2023-45680MEDIUMCVSS 5.5EG 5.52023-10-21
stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in `start_decoder`. In that case the function returns early, the `f->comment_list` is set to `NULL`, but…
- CVE-2023-45913MEDIUMCVSS 6.2EG 6.22024-03-27
Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete event unexpectedly when the applic…
- CVE-2023-45920MEDIUMCVSS 4.2EG 4.22024-03-27
Xfig v3.2.8 was discovered to contain a NULL pointer dereference when calling XGetWMHints(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the…
- CVE-2023-45924CRITICALCVSS 9.8EG 9.82024-03-27
libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no common situations in which users require uninterrupted operat…
- CVE-2023-45925UnratedEG 0.02024-03-27
GNU Midnight Commander 4.8.29-146-g299d9a2fb was discovered to contain a NULL pointer dereference via the function x_error_handler() at tty/x11conn.c. NOTE: this is disputed because it should be categorized as a usability problem (an X ope…
- CVE-2023-45931HIGHCVSS 7.5EG 7.52024-03-27
Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario in which the vulnerability was demonstrated.
- CVE-2023-45935MEDIUMCVSS 4.2EG 4.22024-03-27
Qt 6 through 6.6 was discovered to contain a NULL pointer dereference via the function QXcbConnection::initializeAllAtoms(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbit…
- CVE-2023-46046MEDIUMCVSS 5.5EG 5.52024-03-27
An issue in MiniZinc before 2.8.0 allows a NULL pointer dereference via ti_expr in a crafted .mzn file. NOTE: this is disputed because there is no common libminizinc use case in which an unattended process is supposed to run forever to pro…
- CVE-2023-46048MEDIUMCVSS 6.2EG 6.22024-03-27
Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c. NOTE: this is disputed because it should be categorized as a usability problem.
- CVE-2023-46049MEDIUMCVSS 5.3EG 5.32024-03-27
LLVM 15.0.0 has a NULL pointer dereference in the parseOneMetadata() function via a crafted pdflatex.fmt file (or perhaps a crafted .o file) to llvm-lto. NOTE: this is disputed because the relationship between pdflatex.fmt and any LLVM lan…
- CVE-2023-46051LOWCVSS 3.3EG 3.32024-03-27
TeX Live 944e257 allows a NULL pointer dereference in texk/web2c/pdftexdir/tounicode.c. NOTE: this is disputed because it should be categorized as a usability problem.
- CVE-2023-46239HIGHCVSS 7.5EG 7.52023-10-31
quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by serializing an ACK frame after the CRYTPO that allows a node to complete the handshake, a remote node could trigger a nil p…
- CVE-2023-46343MEDIUMCVSS 5.5EG 5.52024-01-23
In the Linux kernel before 6.5.9, there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c.
- CVE-2023-46345HIGHCVSS 7.5EG 7.52023-10-26
Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c.
- CVE-2023-46427CRITICALCVSS 9.8EG 9.82024-03-09
An issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via null pointer deference in gf_dash_setup_peri…
- CVE-2023-46728HIGHCVSS 7.5EG 7.52023-11-06
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and…
- CVE-2023-4681MEDIUMCVSS 5.5EG 5.52023-08-31
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.
- CVE-2023-4683MEDIUMCVSS 5.5EG 5.52023-08-31
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.
- CVE-2023-46838HIGHCVSS 7.5EG 7.52024-01-29
Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of th…
- CVE-2023-46862MEDIUMCVSS 4.7EG 4.72023-10-29
An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit, an io_uring/fdinfo.c io_uring_show_fdinfo NULL pointer dereference can occur.
- CVE-2023-46867MEDIUMCVSS 6.5EG 6.52023-10-30
In International Color Consortium DemoIccMAX 79ecb74, CIccXformMatrixTRC::GetCurve in IccCmm.cpp in libSampleICC.a has a NULL pointer dereference.
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →