CWE-476
5,440 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
CVEs (5,440)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a CONNECT request is sent to JWT filter configured with regex match. This...Show more |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Feb 22, 2022 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4. |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Feb 21, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428. |
NULL Pointer Dereference in Homebrew mruby prior to 3.2. |
4Debian FedoraprojectLinux+1 more9Active Iq Unified Manager Debian LinuxFedora+6 moreJun 17, 2026 Feb 16, 2022 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones...Show more |
Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application d...Show more |
Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application d...Show more |
Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application d...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Feb 16, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the...Show more |
In SVGPP SVG++ library 1.3.0, the XMLDocument::getRoot function in the renderDocument function handled the XMLDocument object improperly, returning a null pointer in advance at the second if, resulting in a null pointer...Show more |
3Debian FedoraprojectWireshark3Debian Linux FedoraWiresharkJun 17, 2026 Feb 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file |
In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. |
4Debian FedoraprojectLibtiff+1 more4Debian Linux FedoraLibtiff+1 moreJun 17, 2026 Feb 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compi...Show more |
5Debian FedoraprojectLibtiff+2 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Feb 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that c...Show more |
A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information in metadata of the bmp is out of range, it returns without assign memory buffer to `pb->pdata` and di...Show more |
1Qualcomm 49Ar8035 Firmware Qca6174a FirmwareQca6391 Firmware+46 moreJun 17, 2026 Feb 11, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Possible null pointer dereference due to lack of WDOG structure validation during registration in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile |
1Qualcomm 100Apq8009w Firmware Aqt1000 FirmwareAr8031 Firmware+97 moreJun 17, 2026 Feb 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Lack of null check while freeing the device information buffer in the Bluetooth HFP protocol can lead to a NULL pointer dereference in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT...Show more |
2Intel Netapp2Active Management Technology Firmware Cloud BackupJun 17, 2026 Feb 9, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Null pointer dereference in subsystem for Intel(R) AMT before versions 15.0.35 may allow an authenticated user to potentially enable denial of service via network access. |
2Intel Netapp681Atom C3308 Atom C3336Atom C3338+678 moreJun 17, 2026 Feb 9, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 NULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. |
1Nvidia 9Cloud Gaming Guest GeforceGpu Display Driver+6 moreJun 17, 2026 Feb 7, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs where a NULL pointer dereference in the kernel, created within user mode code, may lead to...Show more |