← Back
CWE-476

5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

JSON object

Loading...

CVEs (5,434)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
3Iphone Os
TvosWatchos
May 6, 2026
Jul 22, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IOAcceleratorFamily in Apple iOS before 9.3.3, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Jul 22, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
IOHIDFamily in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vector...Show more
IOHIDFamily in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.Show less
1Apple
1Iphone Os
May 6, 2026
Jul 22, 2016
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
Calendar in Apple iOS before 9.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference and device restart) via a crafted invitation.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Jul 22, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.
5Novell
NtpOpensuse+2 more
9Leap
Linux Enterprise DesktopLinux Enterprise Server+6 more
May 6, 2026
Jul 5, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
3Canonical
DebianQemu
3Debian Linux
QemuUbuntu Linux
May 6, 2026
Jun 16, 2016
N/A· v4
5.0 MEDIUM· v3
2.1 LOW· v2
The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors re...Show more
The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.Show less
3Canonical
DebianF5
3Debian Linux
NginxUbuntu Linux
May 6, 2026
Jun 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a clie...Show more
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.Show less
1Apple
3Iphone Os
Mac Os XTvos
May 6, 2026
May 20, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted app.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
May 20, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cau...Show more
The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
May 20, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
ImageIO in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
May 20, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer derefe...Show more
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.Show less
2Linux
Suse
8Linux Enterprise Debuginfo
Linux Enterprise DesktopLinux Enterprise Module For Public Cloud+5 more
May 6, 2026
Apr 27, 2016
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspec...Show more
The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint.Show less
1Linux
1Linux Kernel
May 6, 2026
Apr 27, 2016
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB d...Show more
The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device that lacks endpoints.Show less
4Debian
LinuxOpensuse+1 more
8Debian Linux
Linux Enterprise DesktopLinux Enterprise Real Time Extension+5 more
May 6, 2026
Apr 13, 2016
N/A· v4
6.0 MEDIUM· v3
4.7 MEDIUM· v2
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer d...Show more
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and a crafted sequence of XEN_PCI_OP_* operations, aka "Linux pciback missing sanity checks."Show less
6Apple
CanonicalDebian+3 more
6Debian Linux
LeapNginx+3 more
May 6, 2026
Feb 15, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
1Linux
1Linux Kernel
May 6, 2026
Feb 8, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspec...Show more
The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending certain IPv4 packets to an incompletely configured interface, a related issue to CVE-2003-1604.Show less
1Apple
4Iphone Os
Mac Os XTvos+1 more
May 6, 2026
Dec 11, 2015
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference)...Show more
IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an app that provides an unspecified userclient type.Show less
4Canonical
DebianNodejs+1 more
4Debian Linux
Node.jsOpenssl+1 more
May 6, 2026
Dec 6, 2015
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lack...Show more
crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parameter.Show less
1Adobe
4Acrobat
Acrobat DcAcrobat Reader+1 more
May 6, 2026
Jul 15, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X al...Show more
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to cause a denial of service (NULL pointer dereference) via unspecified vectors, a different vulnerability than CVE-2015-4443.Show less
1Adobe
4Acrobat
Acrobat DcAcrobat Reader+1 more
May 6, 2026
Jul 15, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X al...Show more
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to cause a denial of service (NULL pointer dereference) via unspecified vectors, a different vulnerability than CVE-2015-4444.Show less