← Back
CWE-476

5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

JSON object

Loading...

CVEs (5,434)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Linux
1Linux Kernel
May 6, 2026
Nov 28, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denia...Show more
crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted application that does not supply a key, related to the lrw_crypt function in crypto/lrw.c.Show less
1Sap
1Netweaver Application Server Java
May 6, 2026
Nov 23, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the sap.com~P4TunnelingApp!web/myServlet URI, aka SAP Security Note 2313835...Show more
SAP NetWeaver AS JAVA 7.4 allows remote attackers to cause a Denial of Service (null pointer exception and icman outage) via an HTTPS request to the sap.com~P4TunnelingApp!web/myServlet URI, aka SAP Security Note 2313835.Show less
1Linux
1Linux Kernel
May 6, 2026
Nov 16, 2016
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memor...Show more
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and out-of-bounds read) via an application that uses associative-array data structures, as demonstrated by the keyutils test suite.Show less
17 Zip
1P7zip
May 6, 2026
Nov 12, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/...Show more
A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications, will cause a crash and a denial of service when decoding malformed 7z files.Show less
1Artifex
1Mujs
May 6, 2026
Nov 12, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Artifex Software, Inc. MuJS before 5008105780c0b0182ea6eda83ad5598f225be3ee allows context-dependent attackers to conduct "denial of service (application crash)" attacks by using the "malformed labeled break/continue in...Show more
Artifex Software, Inc. MuJS before 5008105780c0b0182ea6eda83ad5598f225be3ee allows context-dependent attackers to conduct "denial of service (application crash)" attacks by using the "malformed labeled break/continue in JavaScript" approach, related to a "NULL pointer dereference" issue affecting the jscompile.c component.Show less
1Nvidia
1Gpu Driver
May 6, 2026
Nov 8, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
For the NVIDIA Quadro, NVS, and GeForce products, there is a Remote Desktop denial of service. A successful exploit of a vulnerable system will result in a kernel null pointer dereference, causing a blue screen crash.
1Samsung
1Samsung Mobile
May 6, 2026
Nov 3, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A vulnerability on Samsung Mobile M(6.0) devices exists because external access to SystemUI activities is not properly restricted, leading to a SystemUI crash and device restart, aka SVE-2016-6248.
1Uclouvain
1Openjpeg
May 6, 2026
Oct 30, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
1Uclouvain
1Openjpeg
May 6, 2026
Oct 30, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
1Uclouvain
1Openjpeg
May 6, 2026
Oct 30, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service.
1Uclouvain
1Openjpeg
May 6, 2026
Oct 30, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service.
1Realnetworks
1Realplayer
May 6, 2026
Oct 28, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file.
1Linux
1Linux Kernel
May 6, 2026
Oct 16, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
drivers/infiniband/ulp/srpt/ib_srpt.c in the Linux kernel before 4.5.1 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an ABORT_TASK command to abort a device write op...Show more
drivers/infiniband/ulp/srpt/ib_srpt.c in the Linux kernel before 4.5.1 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an ABORT_TASK command to abort a device write operation.Show less
1Google
1Android
May 6, 2026
Oct 10, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
drivers/video/msm/mdss/mdss_mdp_pp.c in the Qualcomm MDSS driver in Android before 2016-10-05 allows attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact via unknown v...Show more
drivers/video/msm/mdss/mdss_mdp_pp.c in the Qualcomm MDSS driver in Android before 2016-10-05 allows attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact via unknown vectors, aka Qualcomm internal bug CR 1004933.Show less
2Google
Linux
2Android
Linux Kernel
May 6, 2026
Oct 10, 2016
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 4.2 allows local users to obtain sensitive information or cause a denial of service (NULL pointer dereference) via vectors involving...Show more
The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 4.2 allows local users to obtain sensitive information or cause a denial of service (NULL pointer dereference) via vectors involving a bind system call on a Bluetooth RFCOMM socket.Show less
2Debian
Libav
2Debian Linux
Libav
May 6, 2026
Oct 7, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The put_no_rnd_pixels8_xy2_mmx function in x86/rnd_template.c in libav 11.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted MP3 file.
1Freerdp
1Freerdp
May 6, 2026
Oct 3, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FreeRDP before 1.1.0-beta+2013071101 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by disconnecting before authentication has finished.
2Freerdp
Opensuse
3Freerdp
LeapOpensuse
May 6, 2026
Oct 3, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FreeRDP before 1.1.0-beta1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.
2Opensuse
Uclouvain
2Leap
Openjpeg
May 6, 2026
Oct 3, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.
3Nodejs
NovellOpenssl
3Node.js
OpensslSuse Linux Enterprise Module For Web Scripting
May 6, 2026
Sep 26, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.