CWE-476
5,437 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
CVEs (5,437)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer dereference in ftpd/popen.c may lead to remote denial of service of the ftpd service. |
In RenderStruct of protostream_objectsource.cc, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not n...Show more |
1F Secure 4Cloud Protection For Salesforce Elements For Microsoft 365Endpoint Protection+1 moreJun 17, 2026 Jun 21, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be tr...Show more |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restri...Show more |
2Debian Long Range Zip Project2Debian Linux Long Range ZipJun 17, 2026 Jun 10, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service (DOS) via a crafted compressed file. |
2Debian Long Range Zip Project2Debian Linux Long Range ZipJun 17, 2026 Jun 10, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) via a crafted compressed file. |
2Fedoraproject Trusteddomain2Fedora OpendmarcJun 17, 2026 Jun 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a multi-value From header field. |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service |
4Apache DebianFedoraproject+1 more6Debian Linux Enterprise Manager Ops CenterFedora+3 moreJun 17, 2026 Jun 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of...Show more |
SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an...Show more |
SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an...Show more |
SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an...Show more |
SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher), versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,...Show more |
Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access. |
4Debian FedoraprojectQemu+1 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null. |
A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0. This issue occurs in the megasas_command_cancelled() callback function while dro...Show more |
3Fedoraproject Nitro Enclaves ProjectRedhat3Enterprise Linux FedoraNitro EnclavesJun 17, 2026 Jun 1, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the s...Show more |
A NULL-pointer deference issue was discovered in GNU_gama::set() in ellipsoid.h in Gama 2.04 which can lead to a denial of service (DOS) via segment faults caused by crafted inputs. |
1Redhat 1389 Directory Server Jun 17, 2026 May 28, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash. |
A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileg...Show more |