CWE-476
5,437 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
CVEs (5,437)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference. |
3Artifex CanonicalDebian3Debian Linux GhostscriptUbuntu LinuxJun 17, 2026 Aug 13, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fi...Show more |
3Artifex CanonicalDebian3Debian Linux GhostscriptUbuntu LinuxJun 17, 2026 Aug 13, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51. |
3Artifex CanonicalDebian3Debian Linux GhostscriptUbuntu LinuxJun 17, 2026 Aug 13, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51...Show more |
3Artifex CanonicalDebian3Debian Linux GhostscriptUbuntu LinuxJun 17, 2026 Aug 13, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a...Show more |
5Canonical DebianFedoraproject+2 more5Communications Cloud Native Core Policy Debian LinuxFedora+2 moreJun 17, 2026 Jul 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL. |
1Grandstream 6Ht801 Firmware Ht802 FirmwareHt812 Firmware+3 moreJun 17, 2026 Jul 29, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereferen...Show more |
2Gnome Opensuse3Backports Sle BalsaLeapJun 17, 2026 Jul 29, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client crash by sending a PREAUTH response to imap_mbox_connect in libbalsa/imap/imap-handle.c. |
2Debian Gnome2Debian Linux Evolution Data ServerJun 17, 2026 Jul 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on a connection attempt. This is related t...Show more |
Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request to protected resources using a malformed...Show more |
In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Network Manager due to a race condition. This can result in blocking connections and queries to PI Data Archive. |
An authenticated remote attacker could crash PI Archive Subsystem when the subsystem is working under memory pressure. This can result in blocking queries to PI Data Archive (2018 SP2 and prior versions). |
4Canonical ClamavDebian+1 more4Clamav Debian LinuxFedora+1 moreJun 17, 2026 Jul 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the EGG archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.0 - 0.102.3 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected devic...Show more |
GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files. |
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec. |
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec. |
6Apache CanonicalDebian+3 more14Agile Engineering Data Management Agile PlmCommunications Instant Messaging Server+11 moreJun 17, 2026 Jul 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were ma...Show more |
Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service...Show more |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jul 7, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise...Show more |
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a null pointer dereference vulnerability, w...Show more |