CWE-476
5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
CVEs (5,434)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel Gigabit Ethernet (aka igb) subsystem in the Linux kernel before 2.6.34, when Single Root I/O Virtualization (SR-IOV) and promiscuous mode are enable...Show more |
2Linux Suse2Linux Enterprise Server Linux KernelApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 7.1 HIGH· v2 The aun_incoming function in net/econet/af_econet.c in the Linux kernel before 2.6.37-rc6, when Econet is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending an Ac...Show more |
4Canonical DebianLinux+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a s...Show more |
The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions a...Show more |
browser/worker_host/message_port_dispatcher.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle certain postMessage calls, which allows remote attackers to cause a denial of s...Show more |
9Apple CanonicalDebian+6 more11Cups Debian LinuxEnterprise Linux Desktop+8 moreApr 29, 2026 Nov 5, 2010 N/A· v4 N/A· v3 7.5 HIGH· v2 The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a deni...Show more |
5Canonical DebianLinux+2 more8Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+5 moreApr 29, 2026 Oct 4, 2010 N/A· v4 N/A· v3 6.6 MEDIUM· v2 Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of...Show more |
3Canonical LinuxSuse5Linux Enterprise Desktop Linux Enterprise High Availability ExtensionLinux Enterprise Server+2 moreApr 29, 2026 Sep 30, 2010 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of servi...Show more |
3Canonical LinuxSuse4Linux Kernel Suse Linux Enterprise DesktopSuse Linux Enterprise Server+1 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL p...Show more |
7Avaya CanonicalDebian+4 more15Aura Communication Manager Aura Presence ServicesAura Session Manager+12 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial o...Show more |
3Canonical LinuxSuse5Linux Kernel Suse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+2 moreApr 29, 2026 Sep 8, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 29, 2026 Sep 8, 2010 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecif...Show more |
The WebSockets implementation in Google Chrome before 6.0.472.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors. |
4Canonical LinuxOpensuse+1 more5Linux Enterprise Desktop Linux Enterprise ServerLinux Kernel+2 moreApr 29, 2026 Sep 3, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The irda_bind function in net/irda/af_irda.c in the Linux kernel before 2.6.36-rc3-next-20100901 does not properly handle failure of the irda_open_tsap function, which allows local users to cause a denial of service (NUL...Show more |
7Canonical DebianFedoraproject+4 more7Database Server Debian LinuxFedora+4 moreApr 29, 2026 May 19, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for inva...Show more |
The cifs_create function in fs/cifs/dir.c in the Linux kernel 2.6.33.2 and earlier allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a NULL...Show more |
2Fedoraproject Libnids Project2Fedora LibnidsApr 29, 2026 Apr 6, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsniff and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via crafted fragme...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The Transparent Inter-Process Communication (TIPC) functionality in Linux kernel 2.6.16-rc1 through 2.6.33, and possibly other versions, allows local users to cause a denial of service (kernel OOPS) by sending datagrams...Show more |
The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers to cause a denial of service (NULL pointer dereference) via an invalid I...Show more |
8Canonical FedoraprojectLinux+5 more14Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+11 moreApr 23, 2026 Nov 4, 2009 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous...Show more |