← Back
CWE-476

5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

JSON object

Loading...

CVEs (5,434)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
May 13, 2026
Aug 18, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause a NULL pointer dereference during an out-of-memory condition.
1Strongswan
1Strongswan
May 13, 2026
Aug 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature.
1Qemu
1Qemu
May 13, 2026
Aug 10, 2017
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointer dereference) via a crafted image which causes an error, related to th...Show more
The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointer dereference) via a crafted image which causes an error, related to the initialization of the snapshot_offset and nb_snapshots fields.Show less
1Google
1Android
May 13, 2026
Aug 7, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash).
1Gnu
1Binutils
May 13, 2026
Aug 4, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The bfd_make_section_with_flags function in section.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a NULL dereference via a c...Show more
The bfd_make_section_with_flags function in section.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a NULL dereference via a crafted file.Show less
1Libid3tag Project
1Libid3tag
May 13, 2026
Jul 31, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (NULL Pointer Dereference and application crash) via a crafted mp3 file.
1Xiph.org
1Libvorbis
May 13, 2026
Jul 31, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 30, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
2Debian
Libming
2Debian Linux
Ming
May 13, 2026
Jul 29, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A null pointer dereference vulnerability was found in the function stackswap (called from decompileSTACKSWAP) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
1Nvidia
1Gpu Driver
May 13, 2026
Jul 28, 2017
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where a NULL pointer dereference may lead to denial of service or potential escalation of privileges
1Nvidia
1Gpu Driver
May 13, 2026
Jul 28, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler where a NULL pointer dereference may lead to a denial of service or potential escalation of privileges.
1Apache
1Http Server
May 13, 2026
Jul 26, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the server process.
1Graphicsmagick
1Graphicsmagick
May 13, 2026
Jul 26, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
GraphicsMagick 1.3.26 has a NULL pointer dereference in the WriteMAPImage() function in coders/map.c when processing a non-colormapped image, a different vulnerability than CVE-2017-11638.
1Graphicsmagick
1Graphicsmagick
May 13, 2026
Jul 26, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GraphicsMagick 1.3.26 has a NULL pointer dereference in the WritePCLImage() function in coders/pcl.c during writes of monochrome images.
1Gnome
1Libgxps
May 13, 2026
Jul 24, 2017
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.
1Imagemagick
1Imagemagick
May 13, 2026
Jul 22, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The WriteOnePNGImage function in coders/png.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
4Canonical
FedoraprojectJasper Project+1 more
6Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+3 more
May 13, 2026
Jul 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.
1Rarzilla
1Unrar Free
May 13, 2026
Jul 12, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
unrarlib.c in unrar-free 0.0.1 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash), which could be relevant if unrarlib is used as library code for a long-running ap...Show more
unrarlib.c in unrar-free 0.0.1 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash), which could be relevant if unrarlib is used as library code for a long-running application. NOTE: one of the several test cases in the references may be the same as what was separately reported as CVE-2017-14121.Show less
1Xar Project
1Xar
May 13, 2026
Jul 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_get_path function in util.c.
1Xar Project
1Xar
May 13, 2026
Jul 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_unserialize function in archive.c.