CWE-476
5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
CVEs (5,434)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical F5Linux+1 more27Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+24 moreMay 6, 2026 Mar 11, 2014 N/A· v4 N/A· v3 7.8 HIGH· v2 The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote...Show more |
13s Software 1Codesys Runtime Toolkit Apr 29, 2026 Jan 31, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Smart Software Solutions (3S) CoDeSys Runtime Toolkit before 2.4.7.44 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors. |
The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via (1) a PLTE chunk of zero bytes or (2) a NULL palette, re...Show more |
2Redhat Xen4Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+1 moreApr 29, 2026 Dec 27, 2013 N/A· v4 N/A· v3 5.5 MEDIUM· v2 Xen in the Linux kernel, when running a guest on a host without hardware assisted paging (HAP), allows guest users to cause a denial of service (invalid pointer dereference and hypervisor crash) via the SAHF instruction. |
3Debian MitOpensuse3Debian Linux Kerberos 5OpensuseApr 29, 2026 Nov 18, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are configured, allows remote attackers to cause a denial of service (NULL p...Show more |
2Opensuse Trustwave2Modsecurity OpensuseApr 29, 2026 Jul 15, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 29, 2026 Jul 8, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an auth_reply message t...Show more |
A certain Red Hat patch to the sctp_sock_migrate function in net/sctp/socket.c in the Linux kernel before 2.6.21, as used in Red Hat Enterprise Linux (RHEL) 5, allows remote attackers to cause a denial of service (NULL p...Show more |
4Fedoraproject MitOpensuse+1 more8Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+5 moreApr 29, 2026 Apr 19, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticate...Show more |
The pkinit_check_kdc_pkid function in plugins/preauth/pkinit/pkinit_crypto_openssl.c in the PKINIT implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4 and 1.11.x before 1.11.1 d...Show more |
The pkinit_server_return_padata function in plugins/preauth/pkinit/pkinit_srv.c in the PKINIT implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4 attempts to find an agility KDF...Show more |
fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string. |
4Adobe OpensuseRedhat+1 more9Air Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 29, 2026 Jun 9, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on An...Show more |
crypto/ghash-generic.c in the Linux kernel before 3.1 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact by triggering a failed or missing ghash_...Show more |
3Fedoraproject LinuxSuse5Fedora Linux Enterprise DesktopLinux Enterprise High Availability Extension+2 moreApr 29, 2026 May 17, 2012 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a deni...Show more |
3Linux RedhatSuse6Enterprise Linux Enterprise MrgLinux Enterprise Desktop+3 moreApr 29, 2026 May 17, 2012 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or p...Show more |
The __sys_sendmsg function in net/socket.c in the Linux kernel before 3.1 allows local users to cause a denial of service (system crash) via crafted use of the sendmmsg system call, leading to an incorrect pointer derefe...Show more |
2Linux Redhat2Enterprise Linux Linux KernelApr 29, 2026 May 17, 2012 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that trigger an m_start error. |
2Linux Redhat2Enterprise Linux Linux KernelApr 29, 2026 Feb 2, 2012 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka CQ_F_BUILTIN) Qdisc structures, which allows local users to cause...Show more |
The napi_reuse_skb function in net/core/dev.c in the Generic Receive Offload (GRO) implementation in the Linux kernel before 2.6.38 does not reset the values of certain structure members, which might allow remote attacke...Show more |