← Back
CWE-476

5,440 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

JSON object

Loading...

CVEs (5,440)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1F5
11Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+8 more
Jun 17, 2026
Jan 25, 2022
N/A· v4
7.5 HIGH· v3
7.1 HIGH· v2
On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP SSL Forward Proxy with TLS 1.3 is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to termin...Show more
On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP SSL Forward Proxy with TLS 1.3 is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less
2Qemu
Redhat
2Enterprise Linux
Qemu
Jun 17, 2026
Jan 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious u...Show more
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious unprivileged user within the guest could use this flaw to crash the QEMU process on the host when writing data reaches the threshold of mirroring node.Show less
1Slic3r
1Slic3r
Jun 17, 2026
Jan 25, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Several missing input validations in the 3MF parser component of Slic3r libslic3r 1.3.0 can each allow an attacker to cause an application crash using a crafted 3MF input file.
1Slic3r
1Slic3r
Jun 17, 2026
Jan 25, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A flaw in the AMF parser of Slic3r libslic3r 1.3.0 allows an attacker to cause an application crash using a crafted AMF document, where a metadata tag lacks a "type" attribute.
3Debian
FedoraprojectLibrecad
3Debian Linux
FedoraLibrecad
Jun 17, 2026
Jan 25, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.
2Libsixel
Libsixel Project
2Libsixel
Libsixel
Jun 17, 2026
Jan 25, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.
1Gpac
1Gpac
Jun 17, 2026
Jan 21, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_sg_destroy_routes () at scenegraph/vrml_route.c. This vulnerability can lead to a Denial of Service (DoS).
1Hdfgroup
1Hdf5
Jun 17, 2026
Jan 21, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at hdf5/src/H5Odtype.c. This vulnerability can lead to a Denial of Service (DoS).
1Gpac
1Gpac
Jun 17, 2026
Jan 21, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager/scene_dump.c. This vulnerability can lead to a Denial of Service (DoS).
1Gpac
1Gpac
Jun 17, 2026
Jan 21, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An untrusted pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_node_unregister () at scenegraph/base_scenegraph.c. This vulnerability can lead to a Denial of Service (DoS).
1Gpac
1Gpac
Jun 17, 2026
Jan 21, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_sg_vrml_field_pointer_del () at scenegraph/vrml_tools.c. This vulnerability can lead to a Denial of Service (DoS).
1Gpac
1Gpac
Jun 17, 2026
Jan 21, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_node_unregister () at scenegraph/base_scenegraph.c. This vulnerability can lead to a Denial of Service (DoS).
1Mruby
1Mruby
Jun 17, 2026
Jan 21, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
NULL Pointer Dereference in Homebrew mruby prior to 3.2.
1Moddable
1Moddable Sdk
Jun 17, 2026
Jan 20, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Moddable SDK v11.5.0 was discovered to contain a NULL pointer dereference in the component fx_Function_prototype_hasInstance.
1Allwinnertech
1Android Q Sdk
Jun 17, 2026
Jan 19, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a NULL pointer dereference in media/libcedarc/vdecoder of Allwinner R818 SoC Android Q SDK V1.0, which could cause a media crash (denial of service).
1Nvidia
1Shield Experience
Jun 17, 2026
Jan 18, 2022
N/A· v4
4.7 MEDIUM· v3
4.7 MEDIUM· v2
NVIDIA Tegra kernel driver contains a vulnerability in NVHost, where a specific race condition can lead to a null pointer dereference, which may lead to a system reboot.
1Allwinnertech
1Android Q Sdk
Jun 17, 2026
Jan 18, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
There is a NULL pointer deference in the Allwinner R818 SoC Android Q SDK V1.0 camera driver /dev/cedar_dev that could use the ioctl cmd IOCTL_GET_IOMMU_ADDR to cause a system crash.
1Allwinnertech
1Android Q Sdk
Jun 17, 2026
Jan 18, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that could executable a malicious file to cause a system crash.
1Mruby
1Mruby
Jun 17, 2026
Jan 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mruby is vulnerable to NULL Pointer Dereference
3Debian
FedoraprojectLibreswan
3Debian Linux
FedoraLibreswan
Jun 17, 2026
Jan 15, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This...Show more
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.Show less