CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,484 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 16 of 110
- CVE-2018-16004HIGHCVSS 7.8EG 7.82019-01-18
Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 an…
- CVE-2018-16328CRITICALCVSS 9.8EG 9.82018-09-01
In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.
- CVE-2018-16329CRITICALCVSS 9.8EG 9.82018-09-01
In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the GetMagickProperty function in MagickCore/property.c.
- CVE-2018-16428CRITICALCVSS 9.8EG 9.82018-09-04
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
- CVE-2018-16517MEDIUMCVSS 5.5EG 5.52018-09-06
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file.
- CVE-2018-16657CRITICALCVSS 9.8EG 9.82018-09-07
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. The reason is missing input validation in the crcitt_string_array core function for calcula…
- CVE-2018-16749MEDIUMCVSS 6.5EG 6.52018-09-09
In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows an attacker to cause a denial of service (WriteBlob assertion failure and application exit) via a crafted file.
- CVE-2018-16851MEDIUMCVSS 6.5EG 6.52018-11-28
Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the processing of an LDAP search before Samba's AD DC returns the LDAP entries to the client, the entries are cached in a single…
- CVE-2018-16852MEDIUMCVSS 6.5EG 6.52018-11-28
Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of an DNS zone in the DNS management DCE/RPC server, the internal DNS server or the Samba DLZ plugin for BIND9, if the DS…
- CVE-2018-16871HIGHCVSS 7.5EG 7.52019-07-30
A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NF…
- CVE-2018-17000MEDIUMCVSS 6.5EG 6.52018-09-13
A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an attacker to cause a denial-of-service through a crafted tiff file. This vulnerability can b…
- CVE-2018-17073HIGHCVSS 7.5EG 7.52018-09-16
wernsey/bitmap before 2018-08-18 allows a NULL pointer dereference via a 4-bit image.
- CVE-2018-17075HIGHCVSS 7.5EG 7.52018-09-16
The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of <template><object>, <template><applet>, or <template><marquee>. This is related to HTM…
- CVE-2018-17127HIGHCVSS 7.5EG 7.52018-09-17
blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (NULL pointer dereference and device crash) via a request that lacks a timestap parameter.
- CVE-2018-17142HIGHCVSS 7.5EG 7.52018-09-17
The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "panic: runtime error" in parseCurrentToken in parse.go during an html.Parse call.
- CVE-2018-17154MEDIUMCVSS 5.5EG 5.52018-09-28
In FreeBSD before 11.2-STABLE(r338987), 11.2-RELEASE-p4, and 11.1-RELEASE-p15, due to insufficient memory checking in the freebsd4_getfsstat system call, a NULL pointer dereference can occur. Unprivileged authenticated local users may be a…
- CVE-2018-17282MEDIUMCVSS 6.5EG 6.52018-09-20
An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
- CVE-2018-17293HIGHCVSS 8.8EG 8.82018-09-21
An issue was discovered in WAVM before 2018-09-16. The run function in Programs/wavm/wavm.cpp does not check whether there is Emscripten memory to store the command-line arguments passed by the input WebAssembly file's main function, which…
- CVE-2018-17419HIGHCVSS 7.5EG 7.52019-03-07
An issue was discovered in setTA in scan_rr.go in the Miek Gieben DNS library before 1.0.10 for Go. A dns.ParseZone() parsing error causes a segmentation violation, leading to denial of service.
- CVE-2018-17432MEDIUMCVSS 6.5EG 6.52018-09-24
A NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file.
- CVE-2018-17794MEDIUMCVSS 6.5EG 6.52018-09-30
An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.
- CVE-2018-17893CRITICALCVSS 9.8EG 9.82018-10-17
LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution.
- CVE-2018-18065MEDIUMCVSS 6.5EG 6.52018-10-08
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Serv…
- CVE-2018-18066HIGHCVSS 7.5EG 7.52018-10-08
snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
- CVE-2018-18088MEDIUMCVSS 6.5EG 6.52018-10-09
OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c
- CVE-2018-18192MEDIUMCVSS 6.5EG 6.52018-10-09
An issue was discovered in libgig 4.1.0. There is a NULL pointer dereference in the function DLS::File::GetFirstSample() in DLS.cpp.
- CVE-2018-18227HIGHCVSS 7.5EG 7.52018-10-12
In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was addressed in epan/dissectors/packet-mswsp.c by properly handling NULL return values.
- CVE-2018-18318HIGHCVSS 7.5EG 7.52018-10-15
The /dev/block/mmcblk0rpmb driver kernel module on Qiku 360 Phone N6 Pro 1801-A01 devices allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted 0xc0d8b300 ioctl call.
- CVE-2018-18327HIGHCVSS 7.8EG 7.82018-10-23
A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue resul…
- CVE-2018-18328HIGHCVSS 7.8EG 7.82018-10-23
A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue resul…
- CVE-2018-18329HIGHCVSS 7.8EG 7.82018-10-23
A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue resul…
- CVE-2018-18457MEDIUMCVSS 5.5EG 5.52018-10-18
The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.
- CVE-2018-18458MEDIUMCVSS 5.5EG 5.52018-10-18
The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.
- CVE-2018-18459MEDIUMCVSS 5.5EG 5.52018-10-18
The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.
- CVE-2018-18508MEDIUMCVSS 6.5EG 6.52020-10-22
In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.
- CVE-2018-18513HIGHCVSS 7.5EG 7.52019-04-26
A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service (DOS) attack because Thunderbird reopens the last seen message on restart, triggering the …
- CVE-2018-18585MEDIUMCVSS 4.3EG 4.32018-10-23
chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).
- CVE-2018-18606MEDIUMCVSS 5.5EG 5.52018-10-23
An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in _bfd_add_merge_section when attempting t…
- CVE-2018-18607MEDIUMCVSS 5.5EG 5.52018-10-23
An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in elf_link_input_bfd when used for finding STT_T…
- CVE-2018-18661MEDIUMCVSS 6.5EG 6.52018-10-26
An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c.
- CVE-2018-18829MEDIUMCVSS 6.5EG 6.52018-10-30
There exists a NULL pointer dereference in ff_vc1_parse_frame_header_adv in vc1.c in Libav 12.3, which allows attackers to cause a denial-of-service through a crafted aac file.
- CVE-2018-18873MEDIUMCVSS 5.5EG 5.52018-10-31
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.
- CVE-2018-18883HIGHCVSS 8.8EG 8.82018-11-01
An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, allowing x86 HVM and PVH guests to cause a host OS denial of service (NULL pointer dereference) or possibly have unspecified other impact because nested VT-x is n…
- CVE-2018-18937HIGHCVSS 7.5EG 7.52018-11-05
An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in ClientDataSet_getValues in client/ied_connection.c.
- CVE-2018-19029HIGHCVSS 7.8EG 7.82019-02-05
LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a pointer for a controlled memory address, which may allow remote code execution, data exfiltration, or cause a system crash.
- CVE-2018-19060MEDIUMCVSS 6.5EG 6.52018-11-07
An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating a filename of an embedded file before constructing a sa…
- CVE-2018-19121MEDIUMCVSS 4.3EG 4.32018-11-09
An issue has been found in libIEC61850 v1.3. It is a SEGV in Ethernet_receivePacket in ethernet_bsd.c.
- CVE-2018-19122MEDIUMCVSS 4.3EG 4.32018-11-09
An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in Ethernet_sendPacket in ethernet_bsd.c.
- CVE-2018-19129MEDIUMCVSS 6.5EG 6.52018-11-09
In Libav 12.3, a NULL pointer dereference (RIP points to zero) issue in ff_mpa_synth_filter_float in libavcodec/mpegaudiodsp_template.c can cause a segmentation fault (application crash) via a crafted mov file.
- CVE-2018-19149MEDIUMCVSS 6.5EG 6.52018-11-10
Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →