CWE-476
5,437 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
CVEs (5,437)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
8Debian NetappOpensuse+5 more11Backports Sle Cloud BackupDebian Linux+8 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19...Show more |
1Codesys 3Plcwinnt Runtime ToolkitSp Realtime NtJun 17, 2026 Dec 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference. |
bitstr_tell at bitstr.c in ffjpeg through 2019-08-21 has a NULL pointer dereference related to jfif_encode. |
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15. A malicious application may be able to determine kernel memory layout. |
8Debian NetappOpensuse+5 more11Backports Sle Cloud BackupDebian Linux+8 moreJun 17, 2026 Dec 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled. |
1Qualcomm 50Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+47 moreJun 17, 2026 Dec 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Use of local variable as argument to netlink CB callback goes out of it scope when callback triggered lead to invalid stack memory in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, S...Show more |
1Qualcomm 49Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+46 moreJun 17, 2026 Dec 18, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Possibility of Null pointer access if the SPDM commands are executed in the non-standard way in Trustzone in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Sna...Show more |
2Elog Project Fedoraproject2Elog FedoraJun 17, 2026 Dec 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker can crash the ELOG server by sending a crafted HTTP GET request. |
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in fs/f2fs/recovery.c. This is related to F2FS_P_SB in fs/f2fs/f2fs.h. |
Null pointer dereference in the FPGA kernel driver for Intel(R) Quartus(R) Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable denial of service via local access. |
1Huawei 50Alp Al00b Firmware Alp Tl00b FirmwareBla Al00b Firmware+47 moreJun 17, 2026 Dec 14, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected...Show more |
1Huawei 17Ap2000 Firmware Espace U1981 FirmwareIps Firmware+14 moreJun 17, 2026 Dec 13, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981)...Show more |
2Dovecot Fedoraproject2Dovecot FedoraJun 17, 2026 Dec 13, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the s...Show more |
An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated "Invalid request" response. This internally generated response is dispatched throu...Show more |
1Qualcomm 37Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+34 moreJun 17, 2026 Dec 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Accessing data buffer beyond the available data while parsing ogg clip can lead to null-pointer dereference and then memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer...Show more |
1Qualcomm 6Qcs605 Firmware Sdm670 FirmwareSdm710 Firmware+3 moreJun 17, 2026 Dec 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Null pointer dereference issue in kernel due to missing check related to LLC support in GPU in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice &...Show more |
marc-q libwav through 2017-04-20 has a NULL pointer dereference in wav_content_read() at libwav.c. |
1Trendmicro 4Antivirus+ Security 2020 Internet Security 2020Maximum Security 2020+1 moreJun 17, 2026 Dec 9, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution un...Show more |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Dec 9, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ultimately leading to an arbitrary write. This allows remote attackers to cause a denial of service (a...Show more |
3Debian FedoraprojectProftpd3Debian Linux FedoraProftpdJun 17, 2026 Nov 30, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL inst...Show more |