← Back
CWE-476

5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

JSON object

Loading...

CVEs (5,434)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Long Range Zip Project
1Long Range Zip
May 13, 2026
May 8, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.
1Long Range Zip Project
1Long Range Zip
May 13, 2026
May 8, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.
2Openssl
Oracle
7Agile Engineering Data Management
Communications Application Session ControllerCommunications Eagle Lnp Application Processor+4 more
May 13, 2026
May 4, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This co...Show more
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.Show less
1Openssl
1Openssl
May 13, 2026
May 4, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In OpenSSL 1.1.0 before 1.1.0c, applications parsing invalid CMS structures can crash with a NULL pointer dereference. This is caused by a bug in the handling of the ASN.1 CHOICE type in OpenSSL 1.1.0 which can result in...Show more
In OpenSSL 1.1.0 before 1.1.0c, applications parsing invalid CMS structures can crash with a NULL pointer dereference. This is caused by a bug in the handling of the ASN.1 CHOICE type in OpenSSL 1.1.0 which can result in a NULL value being passed to the structure callback if an attempt is made to free certain invalid encodings. Only CHOICE structures using a callback which do not handle NULL value are affected.Show less
1Gnu
1Binutils
May 13, 2026
May 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid write of size 8 because of missing a malloc() return-value check to see if memory had actually been...Show more
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid write of size 8 because of missing a malloc() return-value check to see if memory had actually been allocated in the _bfd_generic_get_section_contents function. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objcopy, to crash.Show less
1Gnu
1Binutils
May 13, 2026
May 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 4 due to NULL pointer dereferencing of _bfd_elf_large_com_section. This vulnerability c...Show more
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 4 due to NULL pointer dereferencing of _bfd_elf_large_com_section. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objcopy, to crash.Show less
1Gnu
1Binutils
May 13, 2026
May 1, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a check to determine whether symbols are NULL in the _bfd_dwarf2_f...Show more
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a check to determine whether symbols are NULL in the _bfd_dwarf2_find_nearest_line function. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump, to crash.Show less
1Oneplus
1Oxygenos
May 13, 2026
Apr 25, 2017
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertext content of an arbitrary partition (except 'keystore') by issuing the 'fastboot...Show more
In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertext content of an arbitrary partition (except 'keystore') by issuing the 'fastboot oem dump <partition>' fastboot command.Show less
1Linux
1Linux Kernel
May 13, 2026
Apr 24, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a single-context I...Show more
The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a single-context INVEPT instruction with a NULL EPT pointer.Show less
1Opendaylight
1Opendaylight
May 13, 2026
Apr 24, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested vers...Show more
StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.Show less
1Opendaylight
1Opendaylight
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature contains this flaw. Version: OpenDaylight 4.0 is affected by this flaw.
1Podofo Project
1Podofo
May 13, 2026
Apr 21, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The function TextExtractor::ExtractText in TextExtractor.cpp:77 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.
1Moxa
1Awk 3131a Firmware
May 13, 2026
Apr 13, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runScript iw_filename functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. An HTTP POST request with a...Show more
An exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runScript iw_filename functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. An HTTP POST request with a blank line in the header will cause a segmentation fault in the web server.Show less
1Moxa
1Awk 3131a Firmware
May 13, 2026
Apr 13, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded by an '/' will cause a segmentation faul...Show more
An exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Any HTTP GET request not preceded by an '/' will cause a segmentation fault in the web server. An attacker can send any of a multitude of potentially unexpected HTTP get requests to trigger this vulnerability.Show less
1Samsung
2Galaxy Note 3 Firmware
Galaxy S6 Firmware
May 13, 2026
Apr 13, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The getURL function in drivers/secfilter/urlparser.c in secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to trigge...Show more
The getURL function in drivers/secfilter/urlparser.c in secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to trigger a NULL pointer dereference via a "GET HTTP/1.1" request, aka SVE-2016-5036.Show less
1Rtmpdump Project
1Rtmpdump
May 13, 2026
Apr 13, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
RTMPDump 2.4 allows remote attackers to trigger a denial of service (NULL pointer dereference and process crash).
1Rtmpdump Project
1Rtmpdump
May 13, 2026
Apr 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to cause a denial of service (invalid pointer dereference and process crash).
1Xmlsoft
1Libxml2
May 13, 2026
Apr 11, 2017
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recov...Show more
libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.Show less
1Libdwarf Project
1Libdwarf
May 13, 2026
Apr 10, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a debugging information entry using DWARF5 and without a DW_AT_name.
1Gnu
1Binutils
May 13, 2026
Apr 9, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" undefined behavior issue, which might allow remote attackers to cause a d...Show more
elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an "int main() {return 0;}" program.Show less