CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,494 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 86 of 110
- CVE-2025-29876HIGHCVSS 7.5EG 7.52025-06-06
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…
- CVE-2025-29877HIGHCVSS 7.5EG 7.52025-06-06
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…
- CVE-2025-29878MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the …
- CVE-2025-29879MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the …
- CVE-2025-29882MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We…
- CVE-2025-29886MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the …
- CVE-2025-29888MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the …
- CVE-2025-29889MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the …
- CVE-2025-29901MEDIUMCVSS 6.5EG 6.52025-08-26
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the …
- CVE-2025-3010LOWCVSS 3.3EG 3.32025-03-31
A vulnerability, which was classified as problematic, has been found in Khronos Group glslang 15.1.0. Affected by this issue is the function glslang::TIntermediate::isConversionAllowed of the file glslang/MachineIndependent/Intermediate.cp…
- CVE-2025-30195HIGHCVSS 7.5EG 7.52025-04-07
An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service. The remedy is: upgrade t…
- CVE-2025-30262MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the v…
- CVE-2025-30263MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the v…
- CVE-2025-30266MEDIUMCVSS 6.5EG 6.52026-02-11
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the v…
- CVE-2025-30267MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We…
- CVE-2025-30268MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We…
- CVE-2025-30272MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the…
- CVE-2025-30274MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the…
- CVE-2025-30275MEDIUMCVSS 6.5EG 6.52025-08-29
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the v…
- CVE-2025-30300MEDIUMCVSS 5.5EG 5.52025-04-08
Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, lea…
- CVE-2025-30301MEDIUMCVSS 5.5EG 5.52025-04-08
Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, lea…
- CVE-2025-30319MEDIUMCVSS 5.5EG 5.52025-05-13
InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causin…
- CVE-2025-30320MEDIUMCVSS 5.5EG 5.52025-05-13
InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causin…
- CVE-2025-30321MEDIUMCVSS 5.5EG 5.52025-06-10
InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causin…
- CVE-2025-30329MEDIUMCVSS 5.5EG 5.52025-05-13
Animate versions 24.0.8, 23.0.11 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disrupti…
- CVE-2025-30645HIGHCVSS 7.5EG 7.52025-04-09
A NULL Pointer Dereference vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker causing specific, valid control traffic to be sent out of a Dual-Stack (DS) Lite tunnel to crash the flowd pr…
- CVE-2025-30665MEDIUMCVSS 6.5EG 6.52025-05-14
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
- CVE-2025-30666MEDIUMCVSS 6.5EG 6.52025-05-14
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
- CVE-2025-30667MEDIUMCVSS 6.5EG 6.52025-05-14
NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
- CVE-2025-30668MEDIUMCVSS 6.5EG 6.52025-05-14
Integer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct a denial of service via network access.
- CVE-2025-30670MEDIUMCVSS 6.5EG 6.52025-04-08
Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
- CVE-2025-30671MEDIUMCVSS 6.5EG 6.52025-04-08
Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.
- CVE-2025-31115HIGHCVSS 8.7EG 8.72025-04-03
XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where invalid input can at least result in a crash. The effects includ…
- CVE-2025-31163MEDIUMCVSS 6.6EG 6.62025-03-28
Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function.
- CVE-2025-31176MEDIUMCVSS 6.2EG 6.22025-03-27
A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.
- CVE-2025-31178MEDIUMCVSS 6.2EG 6.22025-03-27
A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.
- CVE-2025-31179MEDIUMCVSS 6.2EG 6.22025-03-27
A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.
- CVE-2025-31180MEDIUMCVSS 6.2EG 6.22025-03-27
A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.
- CVE-2025-31181MEDIUMCVSS 6.2EG 6.22025-03-27
A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.
- CVE-2025-31202MEDIUMCVSS 5.5EG 5.52025-04-29
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to cause a denial-of-servic…
- CVE-2025-3122LOWCVSS 3.1EG 3.12025-04-02
A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file src/interp/binary-reader-interp.cc. The manipulation leads to …
- CVE-2025-31711MEDIUMCVSS 5.1EG 5.12025-06-03
In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with no additional execution privileges needed.
- CVE-2025-32398HIGHCVSS 7.5EG 7.52025-05-07
A NULL Pointer Dereference in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet.
- CVE-2025-32787LOWCVSS 3.1EG 3.12025-04-16
SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. Versions 5.02.5184 to 5.02.5187 are vulnerable to NULL dereference in `DeleteIPv6DefaultRouterInRA` called by `StorePacket`. Before dereferencing, `DeleteIPv6Defau…
- CVE-2025-32818HIGHCVSS 7.5EG 7.52025-04-23
A Null Pointer Dereference vulnerability in the SonicOS SSLVPN Virtual office interface allows a remote, unauthenticated attacker to crash the firewall, potentially leading to a Denial-of-Service (DoS) condition.
- CVE-2025-32909MEDIUMCVSS 5.3EG 5.32025-04-14
A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.
- CVE-2025-32910MEDIUMCVSS 6.5EG 6.52025-04-14
A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.
- CVE-2025-32912MEDIUMCVSS 6.5EG 6.52025-04-14
A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.
- CVE-2025-32913HIGHCVSS 7.5EG 7.52025-04-14
A flaw was found in libsoup, where the soup_message_headers_get_content_disposition() function is vulnerable to a NULL pointer dereference. This flaw allows a malicious HTTP peer to crash a libsoup client or server that uses this function.
- CVE-2025-33057MEDIUMCVSS 6.5EG 6.52025-06-10
Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →