CWE-476
5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
CVEs (5,434)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Linux2Debian Linux Linux KernelApr 16, 2026 Oct 21, 2005 N/A· v4 4.7 MEDIUM· v3 1.2 LOW· v2 Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to e...Show more |
2Debian Linux2Debian Linux Linux KernelApr 16, 2026 Aug 23, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed fi...Show more |
VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1) a crafted packet in NDMLSRVR.DLL or (2...Show more |
234d AppleAvaya+20 more66Aaa Server Access RegistrarApache Based Web Server+63 moreApr 16, 2026 Nov 23, 2004 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference. |
2Debian Nicolas Boullis2Debian Linux Mah JongApr 16, 2026 Sep 28, 2004 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference. |
1Realnetworks 1Helix Universal Server Apr 16, 2026 Jun 1, 2004 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESC...Show more |
1Microsoft 3Windows 2000 Windows Server 2003Windows XpApr 16, 2026 Jun 1, 2004 N/A· v4 7.5 HIGH· v3 7.5 HIGH· v2 The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code...Show more |
The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference. |
The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference. |
xchat 2.0.6 allows remote attackers to cause a denial of service (crash) via a passive DCC request with an invalid ID number, which causes a null dereference. |
SkyStream EMR5000 1.16 through 1.18 does not drop packets or disable the Ethernet interface when the buffers are full, which allows remote attackers to cause a denial of service (null pointer exception and kernel panic)...Show more |
2Debian Ethereal2Debian Linux EtherealApr 16, 2026 Jun 18, 2002 N/A· v4 7.5 HIGH· v3 7.5 HIGH· v2 SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dereference a NULL pointer. |
The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigg...Show more |
3Bsdi FreebsdOpenbsd3Bsd Os FreebsdOpenbsdApr 16, 2026 Nov 4, 1998 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash. |