← Back
CWE-476

5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

JSON object

Loading...

CVEs (5,434)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
May 13, 2026
Apr 7, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An elevation of privilege vulnerability in SurfaceFlinger could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be u...Show more
An elevation of privilege vulnerability in SurfaceFlinger could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32628763.Show less
1Entropymine
1Imageworsener
May 13, 2026
Apr 6, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The iwgif_record_pixel function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
1Entropymine
1Imageworsener
May 13, 2026
Apr 6, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The iwbmp_read_info_header function in imagew-bmp.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
1Linux
1Linux Kernel
May 13, 2026
Apr 4, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The msm_ipc_router_close function in net/ipc_router/ipc_router_socket.c in the ipc_router component for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other p...Show more
The msm_ipc_router_close function in net/ipc_router/ipc_router_socket.c in the ipc_router component for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact by triggering failure of an accept system call for an AF_MSM_IPC socket.Show less
1Podofo Project
1Podofo
May 13, 2026
Apr 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The PdfFontFactory.cpp:195:62 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.
1Podofo Project
1Podofo
May 13, 2026
Apr 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The PdfFontFactory.cpp:200:88 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.
1Podofo Project
1Podofo
May 13, 2026
Apr 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The doc/PdfPage.cpp:609:23 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.
1Podofo Project
1Podofo
May 13, 2026
Apr 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The doc/PdfPage.cpp:614:20 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.
1Php
1Php
May 13, 2026
Apr 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: t...Show more
The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: the vendor disputes the classification of this as a vulnerability, stating "Please do not request CVEs for ordinary bugs. CVEs are relevant for security issues only.Show less
1Artifex
1Ghostscript
May 13, 2026
Apr 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
1Artifex
1Ghostscript
May 13, 2026
Apr 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file t...Show more
The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file that is mishandled in the PDF Transparency module.Show less
1Artifex
1Ghostscript
May 13, 2026
Apr 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The pdf14_pop_transparency_group function in base/gdevp14.c in the PDF Transparency module in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and app...Show more
The pdf14_pop_transparency_group function in base/gdevp14.c in the PDF Transparency module in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.Show less
1Virustotal
1Yara
May 13, 2026
Apr 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libyara/lexer.l in YARA 3.5.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted rule that is mishandled in the yy_get_next_buffer function.
1Libarchive
1Libarchive
May 13, 2026
Apr 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file.
1Apple
1Mac Os X
May 13, 2026
Apr 2, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireFamily" component. It allows attackers to cause a denial of service (NULL pointer dereference) via a...Show more
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireFamily" component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.Show less
1Linux
1Linux Kernel
May 13, 2026
Mar 31, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for...Show more
Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing cryptographic transform objects to be freed prematurely.Show less
1Illumos
1Illumos
May 13, 2026
Mar 31, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
illumos smbsrv NULL pointer dereference allows system crash.
1Linux
1Linux Kernel
May 13, 2026
Mar 31, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match fie...Show more
The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterator function in keyring.c.Show less
1Imagemagick
1Imagemagick
May 13, 2026
Mar 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted wpg file.
1Imagemagick
1Imagemagick
May 13, 2026
Mar 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageMagick allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted ps file.