← Back
CWE-476

5,434 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

JSON object

Loading...

CVEs (5,434)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Linux
2Debian Linux
Linux Kernel
Apr 16, 2026
Oct 21, 2005
N/A· v4
4.7 MEDIUM· v3
1.2 LOW· v2
Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to e...Show more
Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection table is being flushed before the appropriate lock is acquired.Show less
2Debian
Linux
2Debian Linux
Linux Kernel
Apr 16, 2026
Aug 23, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed fi...Show more
The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointer dereference, a different vulnerability than CVE-2005-2458.Show less
1Veritas
1Backup Exec
Apr 16, 2026
Jun 28, 2005
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1) a crafted packet in NDMLSRVR.DLL or (2...Show more
VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1) a crafted packet in NDMLSRVR.DLL or (2) a request packet with an invalid (non-0) "Error Status" value, which triggers a null dereference.Show less
234d
AppleAvaya+20 more
66Aaa Server
Access RegistrarApache Based Web Server+63 more
Apr 16, 2026
Nov 23, 2004
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
2Debian
Nicolas Boullis
2Debian Linux
Mah Jong
Apr 16, 2026
Sep 28, 2004
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.
1Realnetworks
1Helix Universal Server
Apr 16, 2026
Jun 1, 2004
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESC...Show more
RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests.Show less
1Microsoft
3Windows 2000
Windows Server 2003Windows Xp
Apr 16, 2026
Jun 1, 2004
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code...Show more
The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.Show less
1Ethereal
1Ethereal
Apr 16, 2026
May 4, 2004
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.
1Ethereal
1Ethereal
Apr 16, 2026
Jan 5, 2004
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference.
1Xchat
1Xchat
Apr 16, 2026
Jan 5, 2004
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
xchat 2.0.6 allows remote attackers to cause a denial of service (crash) via a passive DCC request with an invalid ID number, which causes a null dereference.
1Skystream
1Emr5000
Apr 16, 2026
Dec 31, 2002
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SkyStream EMR5000 1.16 through 1.18 does not drop packets or disable the Ethernet interface when the buffers are full, which allows remote attackers to cause a denial of service (null pointer exception and kernel panic)...Show more
SkyStream EMR5000 1.16 through 1.18 does not drop packets or disable the Ethernet interface when the buffers are full, which allows remote attackers to cause a denial of service (null pointer exception and kernel panic) via a large number of packets.Show less
2Debian
Ethereal
2Debian Linux
Ethereal
Apr 16, 2026
Jun 18, 2002
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dereference a NULL pointer.
1Openbsd
1Openbsd
Apr 16, 2026
Dec 31, 2001
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigg...Show more
The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigger a null dereference.Show less
3Bsdi
FreebsdOpenbsd
3Bsd Os
FreebsdOpenbsd
Apr 16, 2026
Nov 4, 1998
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.