CWE-476— NULL Pointer Dereference
4,740 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 46 of 95
- CVE-2023-25660HIGHCVSS 7.5EG 7.52023-03-25
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when the parameter `summarize` of `tf.raw_ops.Print` is zero, the new method `SummarizeArray<bool>` will reference to a nullptr, leading to a …
- CVE-2023-25663HIGHCVSS 7.5EG 7.52023-03-25
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `ctx->step_containter()` is a null ptr, the Lookup function will be executed with a null pointer. A fix is included in TensorFlow 2.12.0 …
- CVE-2023-25665HIGHCVSS 7.5EG 7.52023-03-25
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `SparseSparseMaximum` is given invalid sparse tensors as inputs, it can give a null pointer error. A fix is included in TensorFlow versio…
- CVE-2023-25670HIGHCVSS 7.5EG 7.52023-03-25
TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a null point error in QuantizedMatMulWithBiasAndDequantize with MKL enabled. A fix is included in TensorFlow version 2.12.0 and version 2.…
- CVE-2023-25672HIGHCVSS 7.5EG 7.52023-03-25
TensorFlow is an open source platform for machine learning. The function `tf.raw_ops.LookupTableImportV2` cannot handle scalars in the `values` parameter and gives an NPE. A fix is included in TensorFlow version 2.12.0 and version 2.11.1.
- CVE-2023-25674HIGHCVSS 7.5EG 7.52023-03-25
TensorFlow is an open source machine learning platform. Versions prior to 2.12.0 and 2.11.1 have a null pointer error in RandomShuffle with XLA enabled. A fix is included in TensorFlow 2.12.0 and 2.11.1.
- CVE-2023-25676HIGHCVSS 7.5EG 7.52023-03-25
TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.raw_ops.ParallelConcat` segfaults with a nullptr dereference when given a parameter `shape` with rank that is not greate…
- CVE-2023-25947MEDIUMCVSS 6.2EG 5.52023-03-10
The bundle management subsystem within OpenHarmony-v3.1.4 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause a DoS attack to the system when installing a malicious …
- CVE-2023-2609MEDIUMCVSS 5.5EG 7.82023-05-09
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.
- CVE-2023-2617MEDIUMCVSS 5.3EG 5.32023-05-10
A vulnerability classified as problematic was found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this vulnerability is the function DecodedBitStreamParser::decodeByteSegment of the file qrcode/decoder/decoded_bit_stream_parser.c…
- CVE-2023-26463CRITICALCVSS 9.8EG 9.82023-04-15
strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired po…
- CVE-2023-26916MEDIUMCVSS 5.3EG 7.52023-04-03
libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c.
- CVE-2023-26917HIGHCVSS 7.5EG 7.52023-04-11
libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validate_value at lys_parse_mem.c.
- CVE-2023-27102MEDIUMCVSS 6.5EG 6.52023-03-15
Libde265 v1.0.11 was discovered to contain a segmentation violation via the function decoder_context::process_slice_segment_header at decctx.cc.
- CVE-2023-27114MEDIUMCVSS 5.5EG 5.52023-03-10
radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c.
- CVE-2023-2731MEDIUMCVSS 5.5EG 5.52023-05-17
A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompr…
- CVE-2023-27336HIGHCVSS 7.5EG 7.52024-05-03
Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Sie…
- CVE-2023-27784HIGHCVSS 7.5EG 7.52023-03-16
An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint.
- CVE-2023-27785HIGHCVSS 7.5EG 7.52023-03-16
An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function.
- CVE-2023-27786HIGHCVSS 7.5EG 7.52023-03-16
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the macinstring function.
- CVE-2023-27787HIGHCVSS 7.5EG 7.52023-03-16
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint.
- CVE-2023-28327MEDIUMCVSS 5.5EG 5.52023-04-19
A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly allocated skb does not have sk, leading to a NULL pointer. This flaw allows a local user to crash or po…
- CVE-2023-28328MEDIUMCVSS 5.5EG 5.52023-04-19
A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into the device. This flaw allows a local use…
- CVE-2023-2840CRITICALCVSS 9.8EG 5.32023-05-22
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.
- CVE-2023-28466HIGHCVSS 7.0EG 7.02023-03-16
do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).
- CVE-2023-28484MEDIUMCVSS 6.5EG 6.52023-04-24
In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c.
- CVE-2023-28625HIGHCVSS 7.5EG 7.52023-04-03
mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In versions 2.0.0 through 2.4.13.1, when `OIDCStripCookies` is set and a crafted …
- CVE-2023-2871LOWCVSS 3.3EG 3.32023-05-24
A vulnerability was found in FabulaTech USB for Remote Desktop 6.1.0.0. It has been rated as problematic. Affected by this issue is the function 0x220448/0x220420/0x22040c/0x220408 of the component IoControlCode Handler. The manipulation l…
- CVE-2023-2872MEDIUMCVSS 5.5EG 5.52023-05-24
A vulnerability classified as problematic has been found in FlexiHub 5.5.14691.0. This affects the function 0x220088 in the library fusbhub.sys of the component IoControlCode Handler. The manipulation leads to null pointer dereference. An …
- CVE-2023-2875MEDIUMCVSS 5.5EG 5.52023-05-24
A vulnerability, which was classified as problematic, was found in eScan Antivirus 22.0.1400.2443. Affected is the function 0x22E008u in the library PROCOBSRVESX.SYS of the component IoControlCode Handler. The manipulation leads to null po…
- CVE-2023-28766HIGHCVSS 7.5EG 7.52023-04-11
A vulnerability has been identified in SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD86 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD89 (CP300) (All versions >= V7.80 < V9.64), SIPROTEC 5 6MU85 (CP300) (…
- CVE-2023-28827MEDIUMCVSS 5.9EG 5.92024-09-10
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions …
- CVE-2023-2898MEDIUMCVSS 4.7EG 4.72023-05-26
There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem.
- CVE-2023-2908MEDIUMCVSS 5.5EG 5.52023-06-30
A null pointer dereference issue was found in Libtiff's tif_dir.c file. This issue may allow an attacker to pass a crafted TIFF image file to the tiffcp utility which triggers a runtime error that causes undefined behavior. This will resul…
- CVE-2023-29179MEDIUMCVSS 6.5EG 6.52024-02-22
A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 allows attacker to denial of service via specially crafte…
- CVE-2023-29180HIGHCVSS 7.5EG 7.52024-02-22
A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.3, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12,…
- CVE-2023-2953HIGHCVSS 7.5EG 7.52023-05-30
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
- CVE-2023-29539HIGHCVSS 8.8EG 6.52023-06-02
When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to instal…
- CVE-2023-29569MEDIUMCVSS 5.5EG 5.52023-04-14
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via ffi_cb_impl_wpwwwww at src/mjs_ffi.c. This vulnerability can lead to a Denial of Service (DoS).
- CVE-2023-29984HIGHCVSS 7.5EG 7.52023-07-11
Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As…
- CVE-2023-29996HIGHCVSS 7.5EG 7.52023-05-04
In NanoMQ v0.15.0-0, segment fault with Null Pointer Dereference occurs in the process of decoding subinfo_decode and unsubinfo_decode.
- CVE-2023-3012HIGHCVSS 7.8EG 5.32023-05-31
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.
- CVE-2023-30755MEDIUMCVSS 4.4EG 4.42024-09-10
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions …
- CVE-2023-30756MEDIUMCVSS 5.9EG 5.92024-09-10
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions …
- CVE-2023-31018MEDIUMCVSS 6.5EG 6.52023-11-02
NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service.
- CVE-2023-31021MEDIUMCVSS 5.5EG 5.52023-11-02
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a malicious user in the guest VM can cause a NULL-pointer dereference, which may lead to denial of service.
- CVE-2023-31022MEDIUMCVSS 5.5EG 5.52023-11-02
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service.
- CVE-2023-31026MEDIUMCVSS 6.0EG 6.02023-11-02
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a NULL-pointer dereference may lead to denial of service.
- CVE-2023-3106MEDIUMCVSS 6.6EG 6.62023-07-12
A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause …
- CVE-2023-31081MEDIUMCVSS 5.5EG 5.52023-04-24
An issue was discovered in drivers/media/test-drivers/vidtv/vidtv_bridge.c in the Linux kernel 6.2. There is a NULL pointer dereference in vidtv_mux_stop_thread. In vidtv_stop_streaming, after dvb->mux=NULL occurs, it executes vidtv_mux_st…
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →