CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,487 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 33 of 110
- CVE-2021-33449MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjs_bcode_part_get_by_offset() in mjs.c.
- CVE-2021-33454MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in yasm_expr_get_intnum() in libyasm/expr.c.
- CVE-2021-33455MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in do_directive() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-33456MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in hash() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-33457MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmac_params() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-33458MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in find_cc() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-33459MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in nasm_parser_directive() in modules/parsers/nasm/nasm-parse.c.
- CVE-2021-33460MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in if_condition() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-33463MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in yasm_expr__copy_except() in libyasm/expr.c.
- CVE-2021-33465MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-33466MEDIUMCVSS 5.5EG 5.52022-07-26
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_smacro() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-33572LOWCVSS 3.5EG 3.52021-06-21
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be triggered remotely by…
- CVE-2021-33630MEDIUMCVSS 5.5EG 5.52024-01-18
NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects openEuler kernel: from 4.19.90 …
- CVE-2021-33714MEDIUMCVSS 5.5EG 5.52021-07-13
A vulnerability has been identified in JT Utilities (All versions < V13.0.2.0). When parsing specially crafted JT files, a missing check for the validity of an iterator leads to NULL pointer deference condition, causing the application to …
- CVE-2021-33715MEDIUMCVSS 5.5EG 5.52021-07-13
A vulnerability has been identified in JT Utilities (All versions < V13.0.2.0). When parsing specially crafted JT files, a race condition could cause an object to be released before being operated on, leading to NULL pointer deference cond…
- CVE-2021-33717MEDIUMCVSS 5.5EG 5.52021-08-10
A vulnerability has been identified in JT2Go (All versions < V13.2.0.1), Teamcenter Visualization (All versions < V13.2.0.1). When parsing specially crafted CGM Files, a NULL pointer deference condition could cause the application to crash…
- CVE-2021-33798MEDIUMCVSS 4.7EG 4.72023-07-07
A null pointer dereference was found in libpano13, version libpano13-2.9.20. The flow allows attackers to cause a denial of service and potential code execute via a crafted file.
- CVE-2021-34122MEDIUMCVSS 5.5EG 5.52022-03-10
The function bitstr_tell at bitstr.c in ffjpeg commit 4ab404e has a NULL pointer dereference.
- CVE-2021-34405MEDIUMCVSS 5.5EG 5.52022-01-18
NVIDIA Linux distributions contain a vulnerability in TrustZone’s TEE_Malloc function, where an unchecked return value causing a null pointer dereference may lead to denial of service.
- CVE-2021-34406MEDIUMCVSS 4.7EG 4.72022-01-18
NVIDIA Tegra kernel driver contains a vulnerability in NVHost, where a specific race condition can lead to a null pointer dereference, which may lead to a system reboot.
- CVE-2021-34418MEDIUMCVSS 4.0EG 4.02021-11-11
The login routine of the web console in the Zoom On-Premise Meeting Connector before version 4.6.239.20200613, Zoom On-Premise Meeting Connector MMR before version 4.6.239.20200613, Zoom On-Premise Recording Connector before version 3.8.42…
- CVE-2021-3443MEDIUMCVSS 5.5EG 5.52021-03-25
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to cras…
- CVE-2021-3449HIGHCVSS 5.9EG 7.82021-03-25
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello…
- CVE-2021-34555HIGHCVSS 7.5EG 7.52021-06-10
OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a multi-value From header field.
- CVE-2021-34586HIGHCVSS 7.5EG 7.52021-10-26
In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition.
- CVE-2021-3463MEDIUMCVSS 4.2EG 4.22021-04-13
A null pointer dereference vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could cause systems to experience a blue screen error.
- CVE-2021-3467MEDIUMCVSS 5.5EG 5.52021-03-25
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper lib…
- CVE-2021-34737MEDIUMCVSS 5.8EG 5.82021-09-09
A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to trigger a crash of the dhcpd process, resulting in a denial of service (DoS) condition. This vulnerab…
- CVE-2021-34798HIGHCVSS 7.5EG 8.42021-09-16
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
- CVE-2021-3480HIGHCVSS 7.5EG 7.52021-05-20
A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulner…
- CVE-2021-3502MEDIUMCVSS 5.5EG 5.52021-05-07
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods…
- CVE-2021-35068CRITICALCVSS 8.4EG 9.82022-02-11
Lack of null check while freeing the device information buffer in the Bluetooth HFP protocol can lead to a NULL pointer dereference in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Indust…
- CVE-2021-35075HIGHCVSS 8.4EG 8.42022-02-11
Possible null pointer dereference due to lack of WDOG structure validation during registration in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2021-35076HIGHCVSS 7.5EG 7.52022-06-14
Possible null pointer dereference due to improper validation of RRC connection reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2021-35087HIGHCVSS 7.5EG 7.52022-06-14
Possible null pointer access due to improper validation of system information message to be processed in Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2021-35135MEDIUMCVSS 6.2EG 6.22022-09-02
A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdr…
- CVE-2021-3514MEDIUMCVSS 6.5EG 6.52021-05-28
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
- CVE-2021-35306MEDIUMCVSS 6.5EG 6.52021-08-05
An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the function AP4_StszAtom::WriteFields located in Ap4StszAtom.cpp. It allows an attacker to cause a denial of service (DOS).
- CVE-2021-35307MEDIUMCVSS 6.5EG 6.52021-08-05
An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the AP4_DescriptorFinder::Test component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).
- CVE-2021-3537MEDIUMCVSS 5.9EG 5.92021-05-14
A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and post-validated, the…
- CVE-2021-3543MEDIUMCVSS 6.7EG 6.72021-06-01
A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate t…
- CVE-2021-3596MEDIUMCVSS 6.5EG 6.52022-02-24
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value direc…
- CVE-2021-35984MEDIUMCVSS 5.5EG 5.52021-08-20
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Null pointer dereference vulnerability. An authenticated attacker could leverage this vulnerability ac…
- CVE-2021-35985MEDIUMCVSS 5.5EG 5.52021-08-20
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability …
- CVE-2021-36143HIGHCVSS 7.5EG 7.52021-07-02
ACRN before 2.5 has a hw/pci/virtio/virtio.c vq_endchains NULL Pointer Dereference.
- CVE-2021-36146HIGHCVSS 7.5EG 7.52021-07-02
ACRN before 2.5 has a devicemodel/hw/pci/xhci.c NULL Pointer Dereference for a trb pointer.
- CVE-2021-36147HIGHCVSS 7.5EG 7.52021-07-02
An issue was discovered in ACRN before 2.5. It allows a devicemodel/hw/pci/virtio/virtio_net.c virtio_net_ping_rxq NULL pointer dereference for vq->used.
- CVE-2021-36222HIGHCVSS 7.5EG 7.52021-07-22
ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a …
- CVE-2021-3659MEDIUMCVSS 5.5EG 5.52022-08-22
A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from thi…
- CVE-2021-36613MEDIUMCVSS 6.5EG 6.52022-05-11
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →