CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,494 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 85 of 110
- CVE-2025-22921MEDIUMCVSS 6.5EG 6.52025-02-18
FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.
- CVE-2025-23100HIGHCVSS 7.5EG 7.52025-06-03
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. The absence of a NULL check leads to a Denial of Service.
- CVE-2025-23131MEDIUMCVSS 5.5EG 5.52025-04-16
In the Linux kernel, the following vulnerability has been resolved: dlm: prevent NPD when writing a positive value to event_done do_uevent returns the value written to event_done. In case it is a positive value, new_lockspace would undo …
- CVE-2025-23136MEDIUMCVSS 5.5EG 5.52025-04-16
In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: Add NULL check for adev Not all devices have an ACPI companion fwnode, so adev might be NULL. This is similar to the commit cd2fd6eab480 ("platform/x86…
- CVE-2025-23137MEDIUMCVSS 5.5EG 5.52025-04-16
In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update Check if policy is NULL before dereferencing it in amd_pstate_update.
- CVE-2025-23143MEDIUMCVSS 5.5EG 5.52025-05-01
In the Linux kernel, the following vulnerability has been resolved: net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. When I ran the repro [0] and waited a few seconds, I observed two LOCKDEP splats: a warning immedia…
- CVE-2025-23145MEDIUMCVSS 5.5EG 5.52025-05-01
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix NULL pointer in can_accept_new_subflow When testing valkey benchmark tool with MPTCP, the kernel panics in 'mptcp_can_accept_new_subflow' because subflow_req-…
- CVE-2025-23146MEDIUMCVSS 5.5EG 5.52025-05-01
In the Linux kernel, the following vulnerability has been resolved: mfd: ene-kb3930: Fix a potential NULL pointer dereference The off_gpios could be NULL. Add missing check in the kb3930_probe(). This is similar to the issue fixed in com…
- CVE-2025-23147MEDIUMCVSS 5.5EG 5.52025-05-01
In the Linux kernel, the following vulnerability has been resolved: i3c: Add NULL pointer check in i3c_master_queue_ibi() The I3C master driver may receive an IBI from a target device that has not been probed yet. In such cases, the mast…
- CVE-2025-23148MEDIUMCVSS 5.5EG 5.52025-05-01
In the Linux kernel, the following vulnerability has been resolved: soc: samsung: exynos-chipid: Add NULL pointer check in exynos_chipid_probe() soc_dev_attr->revision could be NULL, thus, a pointer check is added to prevent potential NU…
- CVE-2025-23300MEDIUMCVSS 5.5EG 5.52025-10-23
NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a specific memory resource. A successful exploit of this vulnerability might lead to denial of…
- CVE-2025-23330MEDIUMCVSS 5.5EG 5.52025-10-23
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to trigger a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.
- CVE-2025-23332MEDIUMCVSS 5.0EG 5.02025-10-23
NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger a null pointer deference. A successful exploit of this vulnerability might lead to denial of service.
- CVE-2025-23346LOWCVSS 3.3EG 3.32025-09-24
NVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to a limited denial of service.
- CVE-2025-24031MEDIUMCVSS 5.1EG 5.12025-02-10
PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. In versions 0.6.12 and prior, the pam_pkcs11 module segfaults when a user presses ctrl-c/ctrl-d when they are asked for a PIN. When a user enters no …
- CVE-2025-24177HIGHCVSS 7.5EG 7.52025-01-27
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker on the local network may be…
- CVE-2025-24179MEDIUMCVSS 5.7EG 5.72025-04-29
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on…
- CVE-2025-24251MEDIUMCVSS 6.5EG 6.52025-04-29
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An attacker on the local ne…
- CVE-2025-24483MEDIUMCVSS 5.5EG 6.52025-02-06
NULL pointer dereference vulnerability exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted data to the specific process of the Windows system where the product is running, the system …
- CVE-2025-24515MEDIUMCVSS 6.5EG 6.52025-08-12
NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2025-2487MEDIUMCVSS 4.9EG 4.92025-03-18
A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user per…
- CVE-2025-24997MEDIUMCVSS 4.4EG 4.42025-03-11
Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.
- CVE-2025-25217LOWCVSS 3.3EG 3.32025-06-08
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
- CVE-2025-25218LOWCVSS 3.3EG 3.32025-05-06
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
- CVE-2025-25471MEDIUMCVSS 4.3EG 4.32025-02-18
FFmpeg git master before commit fd1772 was discovered to contain a NULL pointer dereference via the component libavformat/mov.c.
- CVE-2025-25473MEDIUMCVSS 5.3EG 5.32025-02-18
FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in libavutil/mem.c.
- CVE-2025-25475HIGHCVSS 7.5EG 7.52025-02-18
A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.
- CVE-2025-2588LOWCVSS 3.3EG 3.32025-03-21
A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulation of the argument re leads to null pointer dereference. Att…
- CVE-2025-26690LOWCVSS 3.3EG 3.32025-08-11
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
- CVE-2025-26694MEDIUMCVSS 5.5EG 5.52025-11-11
Null pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity attac…
- CVE-2025-27113LOWCVSS 2.9EG 2.92025-02-18
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.
- CVE-2025-27170MEDIUMCVSS 5.5EG 5.52025-03-11
Illustrator versions 29.2.1, 28.7.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading …
- CVE-2025-27176MEDIUMCVSS 5.5EG 5.52025-03-11
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, l…
- CVE-2025-27179MEDIUMCVSS 5.5EG 5.52025-03-11
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, l…
- CVE-2025-27185MEDIUMCVSS 5.5EG 5.52025-04-08
After Effects versions 25.1, 24.6.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading …
- CVE-2025-27241LOWCVSS 3.3EG 3.32025-05-06
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
- CVE-2025-27248LOWCVSS 3.3EG 3.32025-05-06
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
- CVE-2025-27701MEDIUMCVSS 5.5EG 5.52025-05-27
In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_array(). Later this values will be derefenced without prior NULL check, which can lead to local Tempora…
- CVE-2025-27917HIGHCVSS 7.5EG 7.52025-11-06
An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. Remote Denial of Service can occur because of …
- CVE-2025-2926LOWCVSS 3.3EG 3.32025-03-28
A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be appr…
- CVE-2025-29547HIGHCVSS 7.0EG 7.02025-04-22
In Rollback Rx Professional 12.8.0.0, the driver file shieldm.sys allows local users to cause a denial of service because of a null pointer dereference from IOCtl 0x96202000.
- CVE-2025-2956MEDIUMCVSS 6.5EG 6.52025-03-30
A vulnerability was found in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ and classified as problematic. This issue affects the function plugins_call_handle_uri_raw of the file /usr/sbin/lighttpd of the component HTTP Request Handler. The manipu…
- CVE-2025-2957MEDIUMCVSS 6.5EG 6.52025-03-30
A vulnerability was found in TRENDnet TEW-411BRP+ 2.07. It has been classified as problematic. Affected is the function sub_401DB0 of the file /usr/sbin/httpd of the component HTTP Request Handler. The manipulation leads to null pointer de…
- CVE-2025-2959MEDIUMCVSS 6.5EG 6.52025-03-30
A vulnerability was found in TRENDnet TEW-410APB 1.3.06b. It has been rated as problematic. Affected by this issue is the function sub_4019A0 of the file /usr/sbin/httpd of the component HTTP Request Handler. The manipulation leads to null…
- CVE-2025-2960MEDIUMCVSS 6.5EG 6.52025-03-30
A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106. This affects the function sub_41DED0 of the file /bin/goahead of the component HTTP Request Handler. The manipulation leads to n…
- CVE-2025-29835MEDIUMCVSS 6.5EG 6.52025-05-13
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- CVE-2025-29838HIGHCVSS 7.4EG 7.42025-05-13
Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally.
- CVE-2025-29873HIGHCVSS 7.5EG 7.52025-06-06
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…
- CVE-2025-29874MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the …
- CVE-2025-29875MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the …
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →