← Back
CWE-476

5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

JSON object

Loading...

CVEs (5,434)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mp3splt Project
1Mp3splt
May 13, 2026
Mar 1, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file. NOTE: this typically has no risk; this crash...Show more
The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file. NOTE: this typically has no risk; this crash of this command-line program has no further consequences for availability.Show less
1Libmp3splt Project
1Libmp3splt
May 13, 2026
Mar 1, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The splt_cue_export_to_file function in cue.c in libmp3splt 0.9.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
2Debian
Imagemagick
2Debian Linux
Imagemagick
May 13, 2026
Mar 1, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
coders/tiff.c in ImageMagick before 7.0.3.7 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted image.
1Libdwarf Project
1Libdwarf
May 13, 2026
Feb 24, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
dwarf_form.c in libdwarf 20160115 allows remote attackers to cause a denial of service (crash) via a crafted elf file.
2Debian
Ytnef Project
2Debian Linux
Ytnef
May 13, 2026
Feb 24, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "1 of 9. Null Pointer Deref / calloc return value not checked."
1Radare
1Radare2
May 13, 2026
Feb 24, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The r_read_* functions in libr/include/r_endian.h in radare2 1.2.1 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by the r_...Show more
The r_read_* functions in libr/include/r_endian.h in radare2 1.2.1 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by the r_read_le32 function.Show less
1Aerospike
1Database Server
May 13, 2026
Feb 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An exploitable denial-of-service vulnerability exists in the fabric-worker component of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause the server process to dereference a null pointer. An attack...Show more
An exploitable denial-of-service vulnerability exists in the fabric-worker component of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause the server process to dereference a null pointer. An attacker can simply connect to a TCP port in order to trigger this vulnerability.Show less
1Apple
3Iphone Os
Mac Os XWatchos
May 13, 2026
Feb 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "CoreGraphics" component. It allows attackers to...Show more
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "CoreGraphics" component. It allows attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted font.Show less
1Apple
1Mac Os X
May 13, 2026
Feb 20, 2017
N/A· v4
6.2 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "AppleGraphicsPowerManagement" component. It allows local users to cause a denial of service (NULL pointer deref...Show more
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "AppleGraphicsPowerManagement" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.Show less
1Apple
1Mac Os X
May 13, 2026
Feb 20, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted...Show more
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.Show less
1Apple
1Mac Os X
May 13, 2026
Feb 20, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "CoreCapture" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspe...Show more
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "CoreCapture" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.Show less
1Apple
1Mac Os X
May 13, 2026
Feb 20, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "CoreStorage" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspe...Show more
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "CoreStorage" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.Show less
1Apple
1Mac Os X
May 13, 2026
Feb 20, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "Thunderbolt" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial...Show more
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "Thunderbolt" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.Show less
1Apple
1Mac Os X
May 13, 2026
Feb 20, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "AppleSMC" component. It allows local users to gain privileges or cause a denial of service (NULL pointer derefe...Show more
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "AppleSMC" component. It allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.Show less
1Libdwarf Project
1Libdwarf
May 13, 2026
Feb 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The _dwarf_load_section function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
1Libdwarf Project
1Libdwarf
May 13, 2026
Feb 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The _dwarf_calculate_info_section_end_ptr function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
1Libdwarf Project
1Libdwarf
May 13, 2026
Feb 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The create_fullest_file_path function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted dwarf file.
1Libdwarf Project
1Libdwarf
May 13, 2026
Feb 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The print_frame_inst_bytes function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via an object file with empty bss-like sections.
1Google
1Chrome
May 13, 2026
Feb 17, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Type confusion in Histogram in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit a near null dereference via a crafted HTML pag...Show more
Type confusion in Histogram in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit a near null dereference via a crafted HTML page.Show less
1Libming
1Libming
May 13, 2026
Feb 17, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The dumpBuffer function in read.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SWF file.