CWE-476
5,447 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
CVEs (5,447)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in boo...Show more |
1Microsoft 10Windows 10 1507 Windows 10 1607Windows 10 1809+7 moreJun 17, 2026 Jun 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
1Microsoft 7Windows 10 1809 Windows 10 21h2Windows 10 22h2+4 moreJun 17, 2026 Jun 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Windows CryptoAPI Denial of Service Vulnerability |
1Siemens 2Jt2go Teamcenter VisualizationJun 17, 2026 Jun 13, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V1...Show more |
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. |
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. |
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. |
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. |
1Mozilla 4Firefox Firefox EsrFocus+1 moreJun 17, 2026 Jun 2, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially trick...Show more |
iniparser v4.1 is vulnerable to NULL Pointer Dereference in function iniparser_getlongint which misses check NULL for function iniparser_getstring's return. |
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2. |
4Apple NetappOpenldap+1 more11Active Iq Unified Manager Clustered Data OntapEnterprise Linux+8 moreJun 17, 2026 May 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. |
At the most basic level, an invalid pointer can be input that crashes the device, but with more knowledge of the device’s memory layout, further exploitation is possible. |
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In versions 2023.01 and prior, an attacker can send a crafted frame which is forward...Show more |
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2023.04, an attacker can send a crafted frame to the device to trig...Show more |
3Debian LinuxNetapp7Debian Linux H300s FirmwareH410c Firmware+4 moreJun 17, 2026 May 26, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem. |
4Debian FedoraprojectLibssh+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 May 26, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service. |
A vulnerability, which was classified as problematic, was found in eScan Antivirus 22.0.1400.2443. Affected is the function 0x22E008u in the library PROCOBSRVESX.SYS of the component IoControlCode Handler. The manipulati...Show more |
A vulnerability classified as problematic has been found in FlexiHub 5.5.14691.0. This affects the function 0x220088 in the library fusbhub.sys of the component IoControlCode Handler. The manipulation leads to null point...Show more |
1Fabulatech 1Usb For Remote Desktop Jun 17, 2026 May 24, 2023 N/A· v4 5.5 MEDIUM· v3 1.7 LOW· v2 A vulnerability was found in FabulaTech USB for Remote Desktop 6.1.0.0. It has been rated as problematic. Affected by this issue is the function 0x220448/0x220420/0x22040c/0x220408 of the component IoControlCode Handler....Show more |