CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,483 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 3 of 110
- CVE-2013-4118HIGHCVSS 7.5EG 7.52016-10-03
FreeRDP before 1.1.0-beta1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.
- CVE-2013-4119HIGHCVSS 7.5EG 7.52016-10-03
FreeRDP before 1.1.0-beta+2013071101 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by disconnecting before authentication has finished.
- CVE-2013-4412HIGHCVSS 7.5EG 7.52019-11-04
slim has NULL pointer dereference when using crypt() method from glibc 2.17
- CVE-2013-6954MEDIUMCVSS 6.5EG 6.52014-01-12
The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via (1) a PLTE chunk of zero bytes or (2) a NULL palette, related to pngrtran.c…
- CVE-2013-7339MEDIUMCVSS v2 4.7EG 4.72014-03-24
The rds_ib_laddr_check function in net/rds/ib.c in the Linux kernel before 3.12.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call …
- CVE-2014-0101HIGHCVSS v2 7.8EG 7.82014-03-11
The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause …
- CVE-2014-0146MEDIUMCVSS 5.5EG 5.52017-08-10
The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointer dereference) via a crafted image which causes an error, related to the initialization of…
- CVE-2014-0190MEDIUMCVSS v2 4.3EG 4.32014-05-08
The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image.
- CVE-2014-0198MEDIUMCVSS v2 4.3EG 4.32014-05-06
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of se…
- CVE-2014-0757MEDIUMCVSS v2 5.0EG 5.02014-01-31
Smart Software Solutions (3S) CoDeSys Runtime Toolkit before 2.4.7.44 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.
- CVE-2014-2497MEDIUMCVSS v2 4.3EG 4.32014-03-21
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
- CVE-2014-2678MEDIUMCVSS v2 4.7EG 4.72014-04-01
The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call f…
- CVE-2014-3164HIGHCVSS 7.5EG 7.52017-10-18
cmds/servicemanager/service_manager.c in Android before commit 7d42a3c31ba78a418f9bdde0e0ab951469f321b5 allows attackers to cause a denial of service (NULL pointer dereference, or out-of-bounds write) via vectors related to binder passed l…
- CVE-2014-3469MEDIUMCVSS v2 5.0EG 5.02014-06-05
The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
- CVE-2014-3470MEDIUMCVSS v2 4.3EG 4.32014-06-05
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointe…
- CVE-2014-3581MEDIUMCVSS v2 5.0EG 5.02014-10-10
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an…
- CVE-2014-3640LOWCVSS v2 2.1EG 2.12014-11-07
The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an unin…
- CVE-2014-4344HIGHCVSS v2 7.8EG 7.82014-08-14
The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and applicat…
- CVE-2014-5077HIGHCVSS v2 7.1EG 7.12014-08-01
The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by starting to establi…
- CVE-2014-5353LOWCVSS v2 3.5EG 3.52014-12-16
The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon…
- CVE-2014-7826HIGHCVSS 7.8EG 7.82014-11-10
kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer…
- CVE-2014-7919HIGHCVSS 7.5EG 7.52017-06-08
b/libs/gui/ISurfaceComposer.cpp in Android allows attackers to trigger a denial of service (null pointer dereference and process crash).
- CVE-2014-8241CRITICALCVSS 9.8EG 9.82016-12-14
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
- CVE-2014-9323MEDIUMCVSS v2 5.0EG 5.02014-12-16
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty st…
- CVE-2014-9660HIGHCVSS v2 7.5EG 7.52015-02-08
The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified o…
- CVE-2014-9708MEDIUMCVSS v2 5.0EG 5.02015-03-31
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
- CVE-2014-9812MEDIUMCVSS 5.5EG 5.52017-03-30
ImageMagick allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted ps file.
- CVE-2014-9814MEDIUMCVSS 5.5EG 5.52017-03-30
ImageMagick allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted wpg file.
- CVE-2014-9943HIGHCVSS 7.8EG 7.82017-06-06
In Core Kernel in all Android releases from CAF using the Linux kernel, a Null Pointer Dereference vulnerability could potentially exist.
- CVE-2014-9949HIGHCVSS 7.8EG 7.82017-06-06
In TrustZone in all Android releases from CAF using the Linux kernel, an Untrusted Pointer Dereference vulnerability could potentially exist.
- CVE-2014-9967HIGHCVSS 7.8EG 7.82017-06-13
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.
- CVE-2014-9972CRITICALCVSS 9.8EG 9.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts can potentially cause a NULL pointer dereference during an out-of-memory condition.
- CVE-2015-0003MEDIUMCVSS v2 6.9EG 6.92015-02-11
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows l…
- CVE-2015-0095MEDIUMCVSS v2 5.6EG 5.62015-03-11
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to c…
- CVE-2015-0573CRITICALCVSS 9.8EG 9.82016-08-07
drivers/media/platform/msm/broadcast/tsc.c in the TSC driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (in…
- CVE-2015-0928HIGHCVSS 7.5EG 7.52017-08-28
libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).
- CVE-2015-2297HIGHCVSS 7.5EG 7.52017-10-06
nanohttp in libcsoap allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Authorization header.
- CVE-2015-3839MEDIUMCVSS 5.5EG 5.52017-08-07
The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash).
- CVE-2015-4054HIGHCVSS 7.5EG 7.52017-05-23
PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.
- CVE-2015-5180HIGHCVSS 7.5EG 7.52017-06-27
res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).
- CVE-2015-5316MEDIUMCVSS 5.9EG 5.92018-02-21
The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote attackers to cause a denial of service (NULL pointer dereferenc…
- CVE-2015-6569MEDIUMCVSS 5.9EG 5.92018-02-21
Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and thread crash) via a state manipulation attack.
- CVE-2015-7515MEDIUMCVSS 4.6EG 4.62016-04-27
The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device that lacks en…
- CVE-2015-7516HIGHCVSS 7.5EG 7.52017-08-24
ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switch disconnect) by sending two Ethernet frames with ether_type Jumbo Frame (0x8870).
- CVE-2015-7549MEDIUMCVSS 6.0EG 6.02017-10-30
The MSI-X MMIO support in hw/pci/msix.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by leveraging failure to define the .write method.
- CVE-2015-7977MEDIUMCVSS 5.9EG 5.92017-01-30
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
- CVE-2015-8270HIGHCVSS 7.5EG 7.52017-04-13
The AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to cause a denial of service (invalid pointer dereference and process crash).
- CVE-2015-8272MEDIUMCVSS 6.5EG 6.52017-04-13
RTMPDump 2.4 allows remote attackers to trigger a denial of service (NULL pointer dereference and process crash).
- CVE-2015-8551MEDIUMCVSS 6.0EG 6.02016-04-13
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host…
- CVE-2015-8592CRITICALCVSS 9.8EG 9.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a pointer is not validated prior to being dereferenced potentially resulting in Guest-OS memory corruption.
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →