CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,487 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 64 of 110
- CVE-2024-11650MEDIUMCVSS 6.5EG 6.52024-11-25
A vulnerability was found in Tenda i9 1.0.0.8(3828) and classified as critical. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation leads to null pointer dereference. The attack may be initiated remo…
- CVE-2024-11705CRITICALCVSS 9.1EG 9.12024-11-26
`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This behavior conflicted with the PKCS#11 v3.0 specification, which …
- CVE-2024-11706MEDIUMCVSS 6.5EG 6.52024-11-26
A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This vulnerability affects Firefox < 133 and…
- CVE-2024-12002MEDIUMCVSS 4.3EG 4.32024-11-30
A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV. The manipulation of the argument Conten…
- CVE-2024-12227MEDIUMCVSS 5.5EG 5.52024-12-05
A vulnerability, which was classified as problematic, was found in MSI Dragon Center up to 2.0.146.0. This affects the function MmUnMapIoSpace in the library NTIOLib_X64.sys of the component IOCTL Handler. The manipulation leads to null po…
- CVE-2024-1241MEDIUMCVSS 5.5EG 5.52024-04-23
Watchdog Antivirus v1.6.415 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002014 IOCTL code of the wsdk-driver.sys driver.
- CVE-2024-12653MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability classified as problematic has been found in FabulaTech USB over Network 6.0.6.1. Affected is the function 0x22040C in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereferen…
- CVE-2024-12654MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability classified as problematic was found in FabulaTech USB over Network 6.0.6.1. Affected by this vulnerability is the function 0x220408 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null …
- CVE-2024-12655MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability, which was classified as problematic, has been found in FabulaTech USB over Network 6.0.6.1. Affected by this issue is the function 0x220420 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads…
- CVE-2024-12656MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability, which was classified as problematic, was found in FabulaTech USB over Network 6.0.6.1. This affects the function 0x220448 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer d…
- CVE-2024-12657MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability has been found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This vulnerability affects the function 0x8001E000 in the library AscRegistryFilter.sys of the component IOCTL Handler. The man…
- CVE-2024-12658MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This issue affects the function 0x8001E01C in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation lea…
- CVE-2024-12659MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been classified as problematic. Affected is the function 0x8001E004 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation l…
- CVE-2024-12660MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been declared as problematic. Affected by this vulnerability is the function 0x8001E018 in the library AscRegistryFilter.sys of the component IOCTL Handler…
- CVE-2024-12661MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been rated as problematic. Affected by this issue is the function 0x8001E024 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manip…
- CVE-2024-12662MEDIUMCVSS 5.5EG 5.52024-12-16
A vulnerability classified as problematic has been found in IObit Advanced SystemCare Utimate up to 17.0.0. This affects the function 0x8001E040 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to…
- CVE-2024-13978LOWCVSS 2.5EG 2.52025-08-01
A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the file tools/tiff2pdf.c of the component fax2ps. The manipulation leads to null p…
- CVE-2024-1443MEDIUMCVSS 4.4EG 4.42024-03-07
MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code of the RTCore64.sys driver. The handle to the driver can only be obtained from a high integrity process.
- CVE-2024-1914MEDIUMCVSS 6.5EG 6.52024-05-14
An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible. The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vu…
- CVE-2024-20266MEDIUMCVSS 5.3EG 5.32024-03-13
A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to trigger a crash of the dhcpd process, resulting in a denial of service (DoS) condition. This vulne…
- CVE-2024-20312HIGHCVSS 7.4EG 7.42024-03-27
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affecte…
- CVE-2024-20339HIGHCVSS 8.6EG 8.62024-10-23
A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected devi…
- CVE-2024-20426HIGHCVSS 8.6EG 8.62024-10-23
A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol for VPN termination of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attack…
- CVE-2024-20436HIGHCVSS 8.6EG 8.62024-09-25
A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This v…
- CVE-2024-20446HIGHCVSS 8.6EG 8.62024-08-28
A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of spec…
- CVE-2024-20661HIGHCVSS 7.5EG 7.52024-01-09
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- CVE-2024-20794MEDIUMCVSS 5.5EG 5.52024-04-11
Animate versions 23.0.4, 24.0.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service. An attacker could leverage this vulnerability to cause a system crash, resulting in a…
- CVE-2024-21356MEDIUMCVSS 6.5EG 6.52024-02-13
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
- CVE-2024-21404HIGHCVSS 7.5EG 7.52024-02-13
.NET Denial of Service Vulnerability
- CVE-2024-21478MEDIUMCVSS 6.2EG 6.22024-06-03
transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.
- CVE-2024-21602HIGHCVSS 7.5EG 7.52024-01-12
A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS Evolved on ACX7024, ACX7100-32C and ACX7100-48L allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). If a specific IPv4 UDP packet is …
- CVE-2024-21664MEDIUMCVSS 4.3EG 4.32024-01-09
jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. Calling `jws.Parse` with a JSON serialized payload where the `signature` field is present while `protected` is absent can lead to a ni…
- CVE-2024-21763HIGHCVSS 7.5EG 7.52024-02-14
When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffic Management Microkernel (TMM) to terminate. NOTE: Software versions which have reache…
- CVE-2024-22023MEDIUMCVSS 5.3EG 5.32024-04-04
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource e…
- CVE-2024-2204MEDIUMCVSS 5.5EG 5.52024-03-15
Zemana AntiLogger v2.74.204.664 is vulnerable to a Denial of Service (DoS) vulnerability by triggering the 0x80002004 and 0x80002010 IOCTL codes of the zam64.sys and zamguard64.sys drivers.
- CVE-2024-22043LOWCVSS 3.3EG 3.32024-02-13
A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.251), Parasolid V35.1 (All versions < V35.1.170). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted XT fi…
- CVE-2024-22052HIGHCVSS 7.5EG 7.52024-04-04
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby cau…
- CVE-2024-22099MEDIUMCVSS 6.3EG 6.32024-01-25
NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C. This issue affects …
- CVE-2024-22386MEDIUMCVSS 5.3EG 5.32024-02-05
A race condition was found in the Linux kernel's drm/exynos device driver in exynos_drm_crtc_atomic_disable() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.
- CVE-2024-22524MEDIUMCVSS 5.5EG 5.52024-06-06
dnspod-sr 0dfbd37 is vulnerable to buffer overflow.
- CVE-2024-22525MEDIUMCVSS 5.5EG 5.52024-06-06
dnspod-sr 0dfbd37 contains a SEGV.
- CVE-2024-22653MEDIUMCVSS 4.8EG 4.82025-05-29
yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c.
- CVE-2024-22733HIGHCVSS 7.5EG 7.52024-11-01
TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or LoginStatus query parameters which could lead to a denial of service by a l…
- CVE-2024-23076HIGHCVSS 7.5EG 7.52024-04-10
JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /labels/BubbleXYItemLabelGenerator.java. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the e…
- CVE-2024-23078CRITICALCVSS 9.1EG 9.12024-04-08
JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there was not reas…
- CVE-2024-23080CRITICALCVSS 9.1EG 9.12024-04-10
Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::wordBased(Locale). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to de…
- CVE-2024-23081LOWCVSS 3.3EG 3.32024-04-08
ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate). NOTE: this is disputed by multiple third parties who believe there was not reasonable eviden…
- CVE-2024-23083MEDIUMCVSS 5.3EG 5.32024-04-10
Time4J Base v5.9.3 was discovered to contain a NullPointerException via the component net.time4j.format.internal.FormatUtils::useDefaultWeekmodel(Locale). NOTE: this is disputed by multiple third parties who believe there was not reasonabl…
- CVE-2024-23085HIGHCVSS 7.5EG 7.52024-04-08
Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.DoubleScramble::scramble(double[], int, int[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable e…
- CVE-2024-23196MEDIUMCVSS 5.3EG 5.32024-02-05
A race condition was found in the Linux kernel's sound/hda device driver in snd_hdac_regmap_sync() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →