CWE-476
5,612 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
CVEs (5,612)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianLinux+1 more7Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a s...Show more |
The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions a...Show more |
browser/worker_host/message_port_dispatcher.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle certain postMessage calls, which allows remote attackers to cause a denial of s...Show more |
9Apple CanonicalDebian+6 more11Cups Debian LinuxEnterprise Linux Desktop+8 moreApr 29, 2026 Nov 5, 2010 N/A· v4 N/A· v3 7.5 HIGH· v2 The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a deni...Show more |
5Canonical DebianLinux+2 more8Debian Linux Linux Enterprise DesktopLinux Enterprise Real Time Extension+5 moreApr 29, 2026 Oct 4, 2010 N/A· v4 N/A· v3 6.6 MEDIUM· v2 Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of...Show more |
3Canonical LinuxSuse5Linux Enterprise Desktop Linux Enterprise High Availability ExtensionLinux Enterprise Server+2 moreApr 29, 2026 Sep 30, 2010 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of servi...Show more |
3Canonical LinuxSuse4Linux Kernel Suse Linux Enterprise DesktopSuse Linux Enterprise Server+1 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL p...Show more |
7Avaya CanonicalDebian+4 more15Aura Communication Manager Aura Presence ServicesAura Session Manager+12 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial o...Show more |
3Canonical LinuxSuse5Linux Kernel Suse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+2 moreApr 29, 2026 Sep 8, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 29, 2026 Sep 8, 2010 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecif...Show more |
The WebSockets implementation in Google Chrome before 6.0.472.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors. |
4Canonical LinuxOpensuse+1 more5Linux Enterprise Desktop Linux Enterprise ServerLinux Kernel+2 moreApr 29, 2026 Sep 3, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The irda_bind function in net/irda/af_irda.c in the Linux kernel before 2.6.36-rc3-next-20100901 does not properly handle failure of the irda_open_tsap function, which allows local users to cause a denial of service (NUL...Show more |
7Canonical DebianFedoraproject+4 more7Database Server Debian LinuxFedora+4 moreApr 29, 2026 May 19, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for inva...Show more |
The cifs_create function in fs/cifs/dir.c in the Linux kernel 2.6.33.2 and earlier allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a NULL...Show more |
2Fedoraproject Libnids Project2Fedora LibnidsApr 29, 2026 Apr 6, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsniff and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via crafted fragme...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The Transparent Inter-Process Communication (TIPC) functionality in Linux kernel 2.6.16-rc1 through 2.6.33, and possibly other versions, allows local users to cause a denial of service (kernel OOPS) by sending datagrams...Show more |
The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers to cause a denial of service (NULL pointer dereference) via an invalid I...Show more |
8Canonical FedoraprojectLinux+5 more14Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+11 moreApr 23, 2026 Nov 4, 2009 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous...Show more |
6Canonical FedoraprojectLinux+3 more8Fedora Linux Enterprise DebuginfoLinux Enterprise Desktop+5 moreApr 23, 2026 Oct 22, 2009 N/A· v4 7.8 HIGH· v3 4.9 MEDIUM· v2 The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointe...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Oct 14, 2009 N/A· v4 7.1 HIGH· v3 6.9 MEDIUM· v2 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a c...Show more |