CWE-476
5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
CVEs (5,434)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Sound Exchange Project2Debian Linux Sound ExchangeNov 21, 2024 Feb 15, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker t...Show more |
1Microsoft 3Windows 8.1 Windows Rt 8.1Windows Server 2012Nov 21, 2024 Feb 15, 2018 N/A· v4 5.3 MEDIUM· v3 6.3 MEDIUM· v2 The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2 allows a denial of service vulnerability due to how specially crafted requests are handled, aka "SM...Show more |
1Sap 1Internet Graphics Server Nov 21, 2024 Feb 14, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services. |
2Canonical Gnu2Patch Ubuntu LinuxJun 17, 2026 Feb 13, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rena...Show more |
2Canonical Freetype2Freetype Ubuntu LinuxJun 17, 2026 Feb 13, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file. |
A other vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-68342866. |
cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer dereference, and application crash) by leveraging access to the NetMon named pipe. |
3Canonical DebianSquid Cache3Debian Linux SquidUbuntu LinuxNov 21, 2024 Feb 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Ser...Show more |
1Sblim Project 1Small Footprint Cim Broker Jun 17, 2026 Feb 8, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SBLIM Small Footprint CIM Broker (SFCB) 1.4.9 has a null pointer (DoS) vulnerability via a crafted POST request to the /cimom URI. |
ccnl-ext-mgmt.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging missing NULL pointer checks after ccnl_malloc. |
ccn-lite-valid.c in CCN-lite before 2.00 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via vectors involving the keyfile variable. |
In Sophos Tester Tool 3.2.0.7 Beta, the driver accepts a special DeviceIoControl code that doesn't check its argument. This argument is a memory address: if a caller passes a NULL pointer or a random invalid address, the...Show more |
Pointer dereference in subsystem in Intel Graphics Driver 15.40.x.x, 15.45.x.x, 15.46.x.x allows unprivileged user to elevate privileges via local access. |
The "stub_send_ret_submit()" function (drivers/usb/usbip/stub_tx.c) in the Linux Kernel before version 4.14.8, 4.9.71, 4.1.49, and 4.4.107 allows attackers to cause a denial of service (NULL pointer dereference) via a sp...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Jan 29, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 drivers/input/serio/i8042.c in the Linux kernel before 4.12.4 allows attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact because the port->exists v...Show more |
2Clamav Debian2Clamav Debian LinuxNov 21, 2024 Jan 26, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is du...Show more |
2Canonical Tats2Ubuntu Linux W3mJun 17, 2026 Jan 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c. |
4Canonical DebianNetapp+1 more12Cloud Backup Clustered Data OntapData Ontap+9 moreApr 29, 2026 Jan 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packe...Show more |
1Tinysvcmdns Project 1Tinysvcmdns Nov 21, 2024 Jan 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable NULL pointer dereference vulnerability exists in the tinysvcmdns library version 2017-11-05. A specially crafted packet can make the library dereference a NULL pointer leading to a server crash and denial...Show more |
An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. The pre-defined function "strlen" is getting a "NULL" string as a parameter value in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the Key Distributi...Show more |