CWE-476— NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.— MITRE CWE catalog
5,496 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-476page 94 of 110
- CVE-2025-52858MEDIUMCVSS 4.9EG 4.92025-10-03
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) a…
- CVE-2025-52859MEDIUMCVSS 4.9EG 4.92025-10-03
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) a…
- CVE-2025-52860MEDIUMCVSS 4.9EG 4.92025-10-03
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) a…
- CVE-2025-52862MEDIUMCVSS 4.9EG 4.92025-10-03
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) a…
- CVE-2025-52865MEDIUMCVSS 6.5EG 6.52025-11-07
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the …
- CVE-2025-52866MEDIUMCVSS 4.9EG 4.92025-10-03
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) a…
- CVE-2025-52984MEDIUMCVSS 5.9EG 5.92025-07-11
A NULL Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause impact to the availability of the device. When stat…
- CVE-2025-53010HIGHCVSS 7.5EG 7.52025-08-01
MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null…
- CVE-2025-53011HIGHCVSS 7.5EG 7.52025-08-01
MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null…
- CVE-2025-53141HIGHCVSS 7.8EG 7.82025-08-12
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2025-53154HIGHCVSS 7.8EG 7.82025-08-12
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2025-53170MEDIUMCVSS 4.0EG 4.02025-07-07
Null pointer dereference vulnerability in the application exit cause module Impact: Successful exploitation of this vulnerability may affect function stability.
- CVE-2025-53179MEDIUMCVSS 6.5EG 6.52025-07-07
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
- CVE-2025-53180MEDIUMCVSS 6.5EG 6.52025-07-07
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
- CVE-2025-53181MEDIUMCVSS 6.5EG 6.52025-07-07
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
- CVE-2025-53182MEDIUMCVSS 6.5EG 6.52025-07-07
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
- CVE-2025-53183MEDIUMCVSS 6.5EG 6.52025-07-07
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
- CVE-2025-53184MEDIUMCVSS 6.5EG 6.52025-07-07
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
- CVE-2025-53405MEDIUMCVSS 4.9EG 4.92026-01-02
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) a…
- CVE-2025-53408MEDIUMCVSS 6.5EG 6.52025-11-07
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the …
- CVE-2025-53412MEDIUMCVSS 6.5EG 6.52025-11-07
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the …
- CVE-2025-53414MEDIUMCVSS 4.9EG 4.92026-01-02
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) a…
- CVE-2025-53477HIGHCVSS 7.5EG 7.52026-01-10
NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference. This issue requires disabled asserts and broken or bogus Bluetooth con…
- CVE-2025-53589MEDIUMCVSS 4.9EG 4.92026-01-02
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) a…
- CVE-2025-53590MEDIUMCVSS 4.9EG 4.92026-01-02
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) a…
- CVE-2025-53592MEDIUMCVSS 6.5EG 6.52026-01-02
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We…
- CVE-2025-53596MEDIUMCVSS 4.9EG 4.92026-01-02
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) a…
- CVE-2025-53598MEDIUMCVSS 6.5EG 6.52026-02-11
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the v…
- CVE-2025-53603HIGHCVSS 7.5EG 7.52025-07-05
In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the query string is a duplicate of a parameter in the POST body.
- CVE-2025-53716MEDIUMCVSS 6.5EG 6.52025-08-12
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
- CVE-2025-53817HIGHCVSS 7.5EG 7.52025-07-17
7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to version 25.0.0, a null pointer dereference in the Compound handler may lead to denial of service. Version 25.0.0 contains a…
- CVE-2025-54146MEDIUMCVSS 6.5EG 6.52026-02-11
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the v…
- CVE-2025-54147MEDIUMCVSS 6.5EG 6.52026-02-11
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the v…
- CVE-2025-54148MEDIUMCVSS 6.5EG 6.52026-02-11
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the v…
- CVE-2025-54163MEDIUMCVSS 4.9EG 4.92026-02-11
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already …
- CVE-2025-54270MEDIUMCVSS 5.5EG 5.52025-10-15
Animate versions 23.0.13, 24.0.10 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitation…
- CVE-2025-54326HIGHCVSS 7.5EG 7.52025-12-03
An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardware IP address in the Camera device driver can lead to a NULL pointer dereference, resulting in a denial of service.
- CVE-2025-54332HIGHCVSS 7.5EG 7.52025-11-04
An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is a NULL Pointer Dereference of profiler.node in the npu_vertex_profileoff function.
- CVE-2025-54334HIGHCVSS 7.5EG 7.52025-11-04
An issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. There is a NULL Pointer Dereference of hdev in the __npu_vertex_bootup function.
- CVE-2025-54409MEDIUMCVSS 6.2EG 6.22025-08-14
AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extend…
- CVE-2025-54989MEDIUMCVSS 5.3EG 5.32025-08-15
Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL pointer dereference denial-of-service vulnerability in Firebird. This specific flaw exists within the parsing of xdr messag…
- CVE-2025-55312HIGHCVSS 7.8EG 7.82025-12-11
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management o…
- CVE-2025-55314HIGHCVSS 7.8EG 7.82025-12-11
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation ma…
- CVE-2025-55639MEDIUMCVSS 6.5EG 6.52026-06-23
GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
- CVE-2025-55641MEDIUMCVSS 5.5EG 5.52026-06-15
A NULL pointer dereference in the gf_isom_copy_sample_info function (isomedia/isom_write.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
- CVE-2025-55643MEDIUMCVSS 5.5EG 5.52026-06-15
A NULL pointer dereference in the TrackWriter handling component (filters/mux_isom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
- CVE-2025-55649MEDIUMCVSS 5.5EG 5.52026-06-15
A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
- CVE-2025-55651MEDIUMCVSS 5.5EG 5.52026-06-09
A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
- CVE-2025-55657HIGHCVSS 7.5EG 7.52026-06-09
A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
- CVE-2025-55659MEDIUMCVSS 6.5EG 6.52026-06-09
A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Map vulnerabilities like CWE-476 to your infrastructure
EchelonGraph correlates every CVE — across CWE-476 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →