← Back
CWE-476

5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

JSON object

Loading...

CVEs (5,434)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Nov 21, 2024
Jan 11, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference.
1Podofo Project
1Podofo
Nov 21, 2024
Jan 9, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
PoDoFo 0.9.5 does not properly validate memcpy arguments in the PdfMemoryOutputStream::Write function (base/PdfOutputStream.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service or possibl...Show more
PoDoFo 0.9.5 does not properly validate memcpy arguments in the PdfMemoryOutputStream::Write function (base/PdfOutputStream.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.Show less
2Debian
Irssi
2Debian Linux
Irssi
Nov 21, 2024
Jan 6, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.
1Advantech
1Webaccess
Nov 21, 2024
Jan 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple vulnerabilities that may allow an attacker to cause the program to use an invalid memory address, res...Show more
An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple vulnerabilities that may allow an attacker to cause the program to use an invalid memory address, resulting in a program crash.Show less
1Embedthis
1Goahead
Nov 21, 2024
Jan 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service.
3Ffmpeg
GoogleLibav
3Chrome
FfmpegLibav
Nov 21, 2024
Jan 3, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, whic...Show more
In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.Show less
3Canonical
DebianImagemagick
3Debian Linux
ImagemagickUbuntu Linux
Nov 21, 2024
Jan 2, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore component and might lead to denial of service
1Libtiff
1Libtiff
Nov 21, 2024
Jan 1, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.
2Debian
Exiv2
2Debian Linux
Exiv2
May 13, 2026
Dec 31, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a TIFF file.
2Debian
Wireshark
2Debian Linux
Wireshark
May 13, 2026
Dec 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and crashes. This was addressed in epan/dissectors/packet-mrdisc.c by validating an IPv4 address. This vulnerability is similar to CVE-2017-9343.
1Ffmpeg
1Ffmpeg
May 13, 2026
Dec 27, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted mov file.
2Canonical
Nasm
2Netwide Assembler
Ubuntu Linux
May 13, 2026
Dec 21, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function find_cc() in asm/preproc.c that will cause a remote denial of service attack, because pointers associated with skip_white_ calls are...Show more
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function find_cc() in asm/preproc.c that will cause a remote denial of service attack, because pointers associated with skip_white_ calls are not validated.Show less
1K7computing
1Antivirus
May 13, 2026
Dec 15, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025c8 DeviceIoControl request.
1K7computing
1Antivirus
May 13, 2026
Dec 15, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025a4 DeviceIoControl request.
1K7computing
1Antivirus
May 13, 2026
Dec 15, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025ac DeviceIoControl request.
2Aubio
Ffmpeg
3Aubio
FfmpegLibswresample
May 13, 2026
Dec 12, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The swri_audio_convert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to cause a denial of service (NULL pointer dere...Show more
The swri_audio_convert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.Show less
1Aubio
1Aubio
May 13, 2026
Dec 12, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A NULL pointer dereference (DoS) Vulnerability was found in the function aubio_source_avcodec_readframe in io/source_avcodec.c of aubio 0.4.6, which may lead to DoS when playing a crafted audio file.
1Hdfgroup
1Hdf5
May 13, 2026
Dec 11, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In HDF5 1.10.1, there is a NULL pointer dereference in the function H5O_pline_decode in the H5Opline.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.
1K7computing
1Antivirus
May 13, 2026
Dec 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x95002574 DeviceIoControl request.
1K7computing
1Antivirus
May 13, 2026
Dec 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x95002570 DeviceIoControl request.