← Back
CWE-476

5,440 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

JSON object

Loading...

CVEs (5,440)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mruby
1Mruby
Jun 17, 2026
Dec 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mruby is vulnerable to NULL Pointer Dereference
1Apple
5Icloud
Iphone OsItunes+2 more
Nov 21, 2024
Dec 23, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML ma...Show more
A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.Show less
1Gpac
1Gpac
Jun 17, 2026
Dec 22, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An invalid memory address dereference vulnerability exists in gpac 1.1.0 via the svg_node_start function, which causes a segmentation fault and application crash.
1Gpac
1Gpac
Jun 17, 2026
Dec 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A null pointer dereference vulnerability exists in gpac 1.1.0 via the lsr_read_anim_values_ex function, which causes a segmentation fault and application crash.
1Gpac
1Gpac
Jun 17, 2026
Dec 22, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A null pointer dereference vulnerability exists in gpac 1.1.0 in the lsr_read_id.part function, which causes a segmentation fault and application crash.
1Gpac
1Gpac
Jun 17, 2026
Dec 22, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An Invalid pointer reference vulnerability exists in gpac 1.1.0 via the gf_svg_node_del function, which causes a segmentation fault and application crash.
1Nasm
1Netwide Assembler
Jun 17, 2026
Dec 22, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A Null Pointer Dereference vulnerability existfs in nasm 2.16rc0 via asm/preproc.c.
1Gpac
1Gpac
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_sg_vrml_mf_append function, which causes a segmentation fault and application crash.
1Gpac
1Gpac
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A null pointer dereference vulnerability exists in gpac 1.1.0-DEV in the gf_node_get_tag function, which causes a segmentation fault and application crash.
1Gpac
1Gpac
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_svg_get_attribute_name function, which causes a segmentation fault and application crash.
1Gpac
1Gpac
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_dump_vrml_dyn_field.isra function, which causes a segmentation fault and application crash.
1Gpac
1Gpac
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A null pointer dereference vulnerability exists in gpac 1.1.0 in the BD_CheckSFTimeOffset function, which causes a segmentation fault and application crash.
1Gpac
1Gpac
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_isom_parse_movie_boxes_internal function, which causes a segmentation fault and application crash.
1Gpac
1Gpac
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A Null Pointer Dereference vulnerability exists in the gf_sg_vrml_mf_alloc function in gpac 1.1.0-DEV, which causes a segmentation fault and application crash.
1Gpac
1Gpac
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A Null Pointer Dereference vulnerability exists in gpac 1.1.0 in the gf_node_get_field function, which can cause a segmentation fault and application crash.
1Gpac
1Gpac
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The gf_isom_hint_rtp_read function in GPAC 1.0.1 allows attackers to cause a denial of service (Invalid memory address dereference) via a crafted file in the MP4Box command.
1Adobe
1Premiere Rush
Jun 17, 2026
Dec 20, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the...Show more
Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Adobe
1Premiere Rush
Jun 17, 2026
Dec 20, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the...Show more
Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
1Adobe
1Premiere Rush
Jun 17, 2026
Dec 20, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the...Show more
Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.Show less
6Apache
AppleDebian+3 more
12Communications Element Manager
Communications Operations MonitorCommunications Session Report Manager+9 more
Jun 17, 2026
Dec 20, 2021
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be...Show more
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).Show less