CWE-476
5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
CVEs (5,434)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 9Windows 7 Windows 8Windows 8.1+6 moreMay 6, 2026 Jun 10, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold...Show more |
5Canonical DebianF5+2 more25Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+22 moreMay 6, 2026 May 29, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests. |
3Embedthis JuniperOracle3Appweb Enterprise Communications BrokerJunosMay 6, 2026 Mar 31, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,". |
1Microsoft 9Windows 7 Windows 8Windows 8.1+6 moreMay 6, 2026 Mar 11, 2015 N/A· v4 N/A· v3 5.6 MEDIUM· v2 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 all...Show more |
1Microsoft 9Windows 7 Windows 8Windows 8.1+6 moreMay 6, 2026 Feb 11, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Go...Show more |
7Canonical DebianFedoraproject+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+9 moreMay 6, 2026 Feb 8, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly...Show more |
7Canonical DebianFedoraproject+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Dec 16, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial...Show more |
4Canonical DebianFirebirdsql+1 more4Debian Linux EvergreenFirebird+1 moreMay 6, 2026 Dec 16, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action...Show more |
3Linux OpensuseSuse3Evergreen Linux KernelSuse Linux Enterprise ServerMay 6, 2026 Nov 10, 2014 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of servi...Show more |
4Canonical DebianQemu+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+4 moreMay 6, 2026 Nov 7, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which trigger...Show more |
4Apache CanonicalOracle+1 more9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Oct 10, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and applic...Show more |
3Debian MitRedhat6Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+3 moreMay 6, 2026 Aug 14, 2014 N/A· v4 N/A· v3 7.8 HIGH· v2 The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer deref...Show more |
4Canonical LinuxRedhat+1 more8Enterprise Linux Eus Enterprise Linux Server AusEnterprise Linux Server Tus+5 moreMay 6, 2026 Aug 1, 2014 N/A· v4 N/A· v3 7.1 HIGH· v2 The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by...Show more |
6Fedoraproject MariadbOpenssl+3 more11Enterprise Linux FedoraLeap+8 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of s...Show more |
4Debian GnuRedhat+1 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue...Show more |
4Canonical FedoraprojectOpensuse+1 more4Fedora OpensuseQt+1 moreMay 6, 2026 May 8, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image. |
6Debian FedoraprojectMariadb+3 more9Debian Linux FedoraLinux Enterprise Desktop+6 moreMay 6, 2026 May 6, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to c...Show more |
3Fedoraproject LinuxOracle3Fedora LinuxLinux KernelMay 6, 2026 Apr 1, 2014 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a...Show more |
The rds_ib_laddr_check function in net/rds/ib.c in the Linux kernel before 3.12.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via...Show more |
6Canonical DebianOracle+3 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Mar 21, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in...Show more |