CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,494 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 82 of 110
- CVE-2025-11848MEDIUMCVSS 4.9EG 4.92026-02-24
A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated a…
- CVE-2025-12206LOWCVSS 3.3EG 3.32025-10-27
A flaw has been found in Kamailio 5.5. The impacted element is the function rve_is_constant of the file src/core/rvalue.c. This manipulation causes null pointer dereference. The attack needs to be launched locally. The exploit has been pub…
- CVE-2025-12207LOWCVSS 3.3EG 3.32025-10-27
A vulnerability has been found in Kamailio 5.5. This affects the function yyerror_at of the file src/core/cfg.y of the component Grammar Rule Handler. Such manipulation leads to null pointer dereference. The attack needs to be performed lo…
- CVE-2025-13397LOWCVSS 3.3EG 3.32025-11-19
A security vulnerability has been detected in mrubyc up to 3.4. This impacts the function mrbc_raw_realloc of the file src/alloc.c. Such manipulation of the argument ptr leads to null pointer dereference. An attack has to be approached loc…
- CVE-2025-13406MEDIUMCVSS 6.8EG 6.82026-03-17
NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows HTTP DoS.This issue affects smartLink SW-HT: 1.43.
- CVE-2025-13425LOWCVSS 1.9EG 1.92025-11-20
A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice when ReadDir returns nil for an empty directory, resulting in a panic (index out of range) and an application crash (deni…
- CVE-2025-1371LOWCVSS 3.3EG 3.32025-02-17
A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer derefe…
- CVE-2025-1373LOWCVSS 3.3EG 3.32025-02-17
A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic. Affected by this issue is the function mov_read_trak of the file libavformat/mov.c of the component MOV Parser. The manipulation leads to null pointer derefer…
- CVE-2025-14180HIGHCVSS 7.5EG 7.52025-12-27
In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES enabled, an invalid character sequence (such as \x9…
- CVE-2025-14309HIGHCVSS 7.5EG 7.52025-12-09
NULL Pointer Dereference vulnerability in ravynsoft ravynos.This issue affects ravynos: through 0.5.2.
- CVE-2025-14501HIGHCVSS 7.5EG 7.52025-12-23
Sante PACS Server HTTP Content-Length Header Handling NULL Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Serv…
- CVE-2025-14631MEDIUMCVSS 6.5EG 6.52026-01-07
A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows an adjacent attacker to cause a denial-of-service (DoS) by triggering a device reboot. This issue affects Archer BE400: xi 1.1.0 Build 20250710 …
- CVE-2025-1470MEDIUMCVSS 5.5EG 5.52025-02-21
In Eclipse OMR, from the initial contribution to version 0.4.0, some OMR internal port library and utilities consumers of z/OS atoe functions do not check their return values for NULL memory pointers or for memory allocation failures. Thi…
- CVE-2025-14769HIGHCVSS 7.5EG 7.52026-03-09
In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing engine. A subsequent rule can then allow the traffic after the packet data is gone, resulting in a NULL pointer derefe…
- CVE-2025-14841LOWCVSS 3.3EG 3.32025-12-18
A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in the library dcmqrdb/libsrc/dcmqrdbi.cc of…
- CVE-2025-14953LOWCVSS 3.1EG 3.12025-12-19
A flaw has been found in Open5GS up to 2.7.5. This impacts the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component FAR-ID Handler. Executing a manipulation can lead to null pointer dereference. The attack…
- CVE-2025-14957LOWCVSS 3.3EG 3.32025-12-19
A vulnerability was identified in WebAssembly Binaryen up to 125. This affects the function IRBuilder::makeLocalGet/IRBuilder::makeLocalSet/IRBuilder::makeLocalTee of the file src/wasm/wasm-ir-builder.cpp of the component IRBuilder. Such m…
- CVE-2025-15156MEDIUMCVSS 4.3EG 4.32025-12-28
A flaw has been found in omec-project UPF up to 2.1.3-dev. This affects the function handleSessionEstablishmentRequest of the file /pfcpiface/pfcpiface/messages_session.go of the component PFCP Session Establishment Request Handler. This m…
- CVE-2025-15468MEDIUMCVSS 5.9EG 5.92026-01-27
Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs. Impact summary: A NULL pointer dereference leads to abnor…
- CVE-2025-15504LOWCVSS 5.5EG 3.32026-01-10
A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::parse_binary of the file src/ELF/Parser.tcc of the component ELF Binary Parser. The manipulation results in null pointer …
- CVE-2025-15535LOWCVSS 3.3EG 3.32026-01-18
A security flaw has been discovered in nicbarker clay up to 0.14. This affects the function Clay__MeasureTextCached in the library clay.h. The manipulation results in null pointer dereference. The attack is only possible with local access.…
- CVE-2025-15571LOWCVSS 5.5EG 3.32026-02-10
A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from …
- CVE-2025-1632LOWCVSS 3.3EG 3.32025-02-24
A vulnerability was found in libarchive up to 3.7.7. It has been classified as problematic. This affects the function list of the file bsdunzip.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on t…
- CVE-2025-1698LOWCVSS 2.8EG 2.82025-06-11
Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker to cause a denial of service.
- CVE-2025-1735MEDIUMCVSS 5.9EG 5.92025-07-13
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres server reje…
- CVE-2025-1877MEDIUMCVSS 6.5EG 6.52025-03-03
A vulnerability, which was classified as critical, was found in D-Link DAP-1562 1.10. This affects the function pure_auth_check of the component HTTP POST Request Handler. The manipulation of the argument a1 leads to null pointer dereferen…
- CVE-2025-20045HIGHCVSS 7.5EG 7.52025-02-05
When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (…
- CVE-2025-20071MEDIUMCVSS 6.5EG 6.52025-05-13
NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2025-20080MEDIUMCVSS 6.8EG 6.82026-02-10
Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel may allow a denial of service. Network adversary with an unauthenticated user combined with a high complexity attack m…
- CVE-2025-20165HIGHCVSS 7.5EG 7.52025-01-22
A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP requests, resulting in a denial of service (DoS) condition. This vulnerability is…
- CVE-2025-20262MEDIUMCVSS 5.0EG 5.02025-08-27
A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, low-privileged, remote attacker …
- CVE-2025-20647HIGHCVSS 6.5EG 7.52025-03-03
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed…
- CVE-2025-20673MEDIUMCVSS 5.5EG 5.52025-06-02
In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413200; …
- CVE-2025-20675MEDIUMCVSS 5.5EG 5.52025-06-02
In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413201; …
- CVE-2025-20676MEDIUMCVSS 5.5EG 5.52025-06-02
In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00412240; …
- CVE-2025-20677MEDIUMCVSS 5.5EG 5.52025-06-02
In Bluetooth driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00412256;…
- CVE-2025-20750MEDIUMCVSS 6.5EG 6.52025-12-02
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges nee…
- CVE-2025-20755MEDIUMCVSS 5.3EG 5.32025-12-02
In Modem, there is a possible application crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privilege…
- CVE-2025-20790MEDIUMCVSS 5.3EG 5.32025-12-02
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges nee…
- CVE-2025-20793HIGHCVSS 6.5EG 7.52026-01-06
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges need…
- CVE-2025-21084LOWCVSS 3.8EG 3.82025-03-04
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through through NULL pointer dereference.. This vulnerability can be exploited only in restricted scenarios.
- CVE-2025-21097LOWCVSS 3.3EG 3.32025-03-04
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through NULL pointer dereference.
- CVE-2025-21125MEDIUMCVSS 5.5EG 5.52025-02-11
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, l…
- CVE-2025-21155MEDIUMCVSS 5.5EG 5.52025-02-11
Substance3D - Stager versions 3.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading …
- CVE-2025-21170MEDIUMCVSS 5.5EG 5.52025-03-11
Substance3D - Modeler versions 1.15.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leadin…
- CVE-2025-21285HIGHCVSS 7.5EG 8.22025-01-14
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- CVE-2025-21433MEDIUMCVSS 6.2EG 6.22025-07-08
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
- CVE-2025-21632MEDIUMCVSS 5.5EG 5.52025-01-19
In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Ensure shadow stack is active before "getting" registers The x86 shadow stack support has its own set of registers. Those registers are XSAVE-managed, but they …
- CVE-2025-21635MEDIUMCVSS 5.5EG 5.52025-01-19
In the Linux kernel, the following vulnerability has been resolved: rds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy As mentioned in a previous commit of this series, using the 'net' structure via 'current' is not recommen…
- CVE-2025-21636MEDIUMCVSS 5.5EG 5.52025-01-19
In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: plpmtud_probe_interval: avoid using current->nsproxy As mentioned in a previous commit of this series, using the 'net' structure via 'current' is not recom…
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →