CWE-476
5,447 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
CVEs (5,447)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2. |
A null pointer dereference bug in Hermes prior to commit 5cae9f72975cf0e5a62b27fdd8b01f103e198708 could have been used by an attacker to crash an Hermes runtime where the EnableHermesInternal config option was set to tru...Show more |
3Fedoraproject LibtiffRedhat3Enterprise Linux FedoraLibtiffJun 17, 2026 May 17, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL p...Show more |
1Intel 2Oneapi Hpc Toolkit Trace Analyzer And CollectorJun 17, 2026 May 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Null pointer dereference for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access. |
Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access. |
A vulnerability classified as problematic was found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this vulnerability is the function DecodedBitStreamParser::decodeByteSegment of the file qrcode/decoder/decoded_...Show more |
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531. |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Pragmatic General Multicast (PGM) Denial of Service Vulnerability |
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. |
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. |
The Contiki-NG operating system versions 4.8 and prior can be triggered to dereference a NULL pointer in the message handling code for IPv6 router solicitiations. Contiki-NG contains an implementation of IPv6 Neighbor Di...Show more |
In NanoMQ v0.15.0-0, segment fault with Null Pointer Dereference occurs in the process of decoding subinfo_decode and unsubinfo_decode. |
1Qualcomm 81315 5g Iot Modem Firmware Ar8035 FirmwareCsra6620 Firmware+78 moreJun 17, 2026 May 2, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH. |
1Qualcomm 409205 Lte Modem Firmware 9206 Lte Modem Firmware9207 Lte Modem Firmware+37 moreJun 17, 2026 May 2, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet. |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Apr 26, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to le...Show more |
x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Due to...Show more |
2Debian Xmlsoft2Debian Linux Libxml2Jun 17, 2026 Apr 24, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c. |
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device res...Show more |
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device res...Show more |
An issue was discovered in drivers/bluetooth/hci_ldisc.c in the Linux kernel 6.2. In hci_uart_tty_ioctl, there is a race condition between HCIUARTSETPROTO and HCIUARTGETPROTO. HCI_UART_PROTO_SET is set before hu->proto i...Show more |