CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,496 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 104 of 110
- CVE-2026-33064HIGHCVSS 7.5EG 7.52026-03-20
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to procedure panic caused by Nil Pointer Dereference in the /sdm-subscriptions endpoint. A remote attac…
- CVE-2026-33164HIGHCVSS 7.5EG 7.52026-03-20
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.…
- CVE-2026-33179MEDIUMCVSS 5.5EG 5.52026-03-20
libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer dereference and memory leak in fuse_uring_init_queue allows a local user to crash the FUSE daemon or cause resource exh…
- CVE-2026-33262MEDIUMCVSS 5.9EG 5.92026-04-22
An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default.
- CVE-2026-33282HIGHCVSS 7.5EG 7.52026-03-24
Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP LocationReport message with `ue-presence-in-area-of-interest` event type and omitting the optional `UEPresenceInAreaOfInt…
- CVE-2026-33283HIGHCVSS 7.5EG 7.52026-03-24
Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Transport NAS messages without a Request Type. An attacker able to send crafted NAS messages to Ella Core can crash the pr…
- CVE-2026-33600MEDIUMCVSS 4.4EG 4.42026-04-22
An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.
- CVE-2026-33601MEDIUMCVSS 4.4EG 4.42026-04-22
If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.
- CVE-2026-33853HIGHCVSS 7.5EG 7.52026-03-24
NULL Pointer Dereference vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.
- CVE-2026-3387LOWCVSS 5.5EG 3.32026-03-01
A vulnerability has been found in wren-lang wren up to 0.4.0. Affected by this issue is the function getByteCountForArguments of the file src/vm/wren_compiler.c. Such manipulation leads to null pointer dereference. Local access is required…
- CVE-2026-3389LOWCVSS 5.5EG 3.32026-03-01
A vulnerability was determined in Squirrel up to 3.2. This vulnerability affects the function sqstd_rex_newnode in the library sqstdlib/sqstdrex.cpp. Executing a manipulation can lead to null pointer dereference. The attack can only be exe…
- CVE-2026-33903MEDIUMCVSS 6.5EG 6.52026-03-27
Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted NGAP LocationReport message. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing…
- CVE-2026-33907MEDIUMCVSS 6.5EG 6.52026-03-27
Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Response and Authentication Failure NAS message missing IEs. An attacker able to send crafted NAS messages to Ella Core can …
- CVE-2026-3392LOWCVSS 5.5EG 3.32026-03-01
A weakness has been identified in FascinatedBox lily up to 2.3. The affected element is the function eval_tree of the file src/lily_emitter.c. This manipulation causes null pointer dereference. The attack is restricted to local execution. …
- CVE-2026-33996MEDIUMCVSS 5.5EG 5.52026-03-27
LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file could exp…
- CVE-2026-3408MEDIUMCVSS 6.5EG 4.32026-03-02
A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the file isrc/atom.cpp of the component CDXML File Handler. Such manipulation leads to null pointer dereference. The attack c…
- CVE-2026-34339MEDIUMCVSS 5.5EG 5.52026-05-12
Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.
- CVE-2026-34350MEDIUMCVSS 6.5EG 6.52026-05-12
Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.
- CVE-2026-34541MEDIUMCVSS 5.5EG 6.22026-03-31
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger Undefined Behavior (UB) via a null-pointer member call in CIccCombinedConnectionCondit…
- CVE-2026-34551MEDIUMCVSS 5.5EG 6.22026-03-31
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a null-pointer dereference (NPD) in CIccTagLut16::Write() can be triggered when processing a crafted ICC profile (embedd…
- CVE-2026-34552MEDIUMCVSS 5.5EG 6.22026-03-31
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) issue in IccTagLut.cpp where the code performs member access through a null pointer …
- CVE-2026-34662MEDIUMCVSS 5.5EG 5.52026-05-12
Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to…
- CVE-2026-34703MEDIUMCVSS 5.5EG 5.52026-06-09
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leadi…
- CVE-2026-34704MEDIUMCVSS 5.5EG 5.52026-06-09
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leadi…
- CVE-2026-34761MEDIUMCVSS 6.5EG 6.52026-04-02
Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP handover failure message. An attacker able to cause a gNodeB to send NGAP handover failure messages to Ella Core can cras…
- CVE-2026-34781LOWCVSS 3.3EG 3.32026-04-07
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that call clipboard.readImage() may be vulnerable to a denial of service. If …
- CVE-2026-34874HIGHCVSS 7.5EG 7.52026-04-01
An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allows an attacker to write to address 0.
- CVE-2026-3665LOWCVSS 5.5EG 3.32026-03-07
A vulnerability was identified in xlnt-community xlnt up to 1.6.1. The affected element is the function xlnt::detail::xlsx_consumer::read_office_document of the file source/detail/serialization/xlsx_consumer.cpp of the component XLSX File …
- CVE-2026-36909MEDIUMCVSS 6.2EG 6.22026-07-01
A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
- CVE-2026-36912HIGHCVSS 7.5EG 7.52026-07-01
A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
- CVE-2026-37226HIGHCVSS 7.5EG 7.52026-06-01
FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup function returns NULL, which is enforced by assert() in Debug builds (SIGABRT) and dereferenced in Release builds …
- CVE-2026-37230HIGHCVSS 7.5EG 7.52026-06-01
FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in its registry. The lookup returns NULL, triggering assert() in Debug builds (SIGABRT) or NULL pointer dereference in Rel…
- CVE-2026-3776MEDIUMCVSS 5.5EG 5.52026-04-01
The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated obje…
- CVE-2026-38976HIGHCVSS 7.5EG 7.52026-07-06
mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-level super.
- CVE-2026-39835MEDIUMCVSS 5.3EG 5.32026-05-22
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these c…
- CVE-2026-39836HIGHCVSS 7.5EG 7.52026-05-07
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
- CVE-2026-39956MEDIUMCVSS 6.1EG 6.12026-04-13
jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_s…
- CVE-2026-40195MEDIUMCVSS 6.5EG 6.52026-05-06
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon…
- CVE-2026-40197MEDIUMCVSS 6.5EG 6.52026-05-06
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon…
- CVE-2026-40355HIGHCVSS 7.5EG 7.52026-04-28
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigge…
- CVE-2026-40401HIGHCVSS 7.1EG 7.12026-05-12
Windows TCP/IP Denial of Service Vulnerability
- CVE-2026-40405HIGHCVSS 7.5EG 7.52026-05-12
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
- CVE-2026-40413HIGHCVSS 7.4EG 7.42026-05-12
Windows TCP/IP Denial of Service Vulnerability
- CVE-2026-40414HIGHCVSS 7.4EG 7.42026-05-12
Windows TCP/IP Denial of Service Vulnerability
- CVE-2026-41069MEDIUMCVSS 6.5EG 6.52026-05-22
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_co…
- CVE-2026-41642HIGHCVSS 7.5EG 7.52026-05-07
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UP…
- CVE-2026-41647MEDIUMCVSS 6.5EG 6.52026-05-07
Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to cause a daemon crash through the import of a truncated storage bucket backup file. This iss…
- CVE-2026-41684MEDIUMCVSS 6.5EG 6.52026-05-07
Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline backup/index.yaml config when present and only falls back to parsing the legacy backup/container/backup.yaml file if result…
- CVE-2026-42183MEDIUMCVSS 6.5EG 6.52026-05-09
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, a nil pointer dereference in server/auth/gatekeeper.go rbacAuthorization() causes …
- CVE-2026-42285HIGHCVSS 7.5EG 7.52026-05-07
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, an unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending a specially crafted BGP UPDATE message.…
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →