CWE-476
NULL Pointer Dereference
Description
The product dereferences a pointer that it expects to be valid but is NULL.
Hierarchy (View 1000)
CVEs mapped to this weakness (5,669)
page 106 of 284| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-25168 | Med | 0.40 | 6.2 | 0.00 | Mar 10, 2026 | Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally. | ||
| CVE-2026-22722 | Med | 0.40 | 6.1 | 0.00 | Feb 26, 2026 | A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix' | ||
| CVE-2025-8090 | Med | 0.40 | 6.2 | 0.00 | Jan 13, 2026 | Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execution abilities to crash the QNX Neutrino kernel. | ||
| CVE-2025-65835 | Med | 0.40 | 6.2 | 0.00 | Dec 15, 2025 | The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter. The onReceive implementation accesses… | ||
| CVE-2025-39694 | Hig | 0.40 | 7.3 | 0.00 | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: s390/sclp: Fix SCCB present check Tracing code called by the SCLP interrupt handler contains early exits if the SCCB address associated with an interrupt is NULL. This check is performed after physical to… | ||
| CVE-2025-48073 | Med | 0.40 | 6.2 | 0.00 | Jul 31, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target… | ||
| CVE-2025-21433 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. | ||
| CVE-2025-31181 | Med | 0.40 | 6.2 | 0.00 | Mar 27, 2025 | A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash. | ||
| CVE-2025-31180 | Med | 0.40 | 6.2 | 0.00 | Mar 27, 2025 | A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash. | ||
| CVE-2025-31179 | Med | 0.40 | 6.2 | 0.00 | Mar 27, 2025 | A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash. | ||
| CVE-2025-31178 | Med | 0.40 | 6.2 | 0.00 | Mar 27, 2025 | A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash. | ||
| CVE-2025-31176 | Med | 0.40 | 6.2 | 0.00 | Mar 27, 2025 | A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash. | ||
| CVE-2025-21682 | Hig | 0.40 | 7.3 | 0.00 | Jan 31, 2025 | In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: always recalculate features after XDP clearing, fix null-deref Recalculate features when XDP is detached. Before: # ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp # ip li set dev eth0 xdp… | ||
| CVE-2024-39440 | Med | 0.40 | 6.2 | 0.00 | Oct 9, 2024 | In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution privileges needed. | ||
| CVE-2024-35215 | Med | 0.40 | 6.2 | 0.00 | Oct 8, 2024 | NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Networking Stack process. | ||
| CVE-2024-8235 | Med | 0.40 | 6.2 | 0.00 | Aug 30, 2024 | A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent… | ||
| CVE-2024-23357 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2024 | Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. | ||
| CVE-2024-21478 | Med | 0.40 | 6.2 | 0.00 | Jun 3, 2024 | transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA. | ||
| CVE-2024-36888 | Med | 0.40 | 6.2 | 0.00 | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: workqueue: Fix selection of wake_cpu in kick_pool() With cpu_possible_mask=0-63 and cpu_online_mask=0-7 the following kernel oops was observed: smp: Bringing up secondary CPUs ... smp: Brought up 1 node, 8… | ||
| CVE-2021-47503 | Med | 0.40 | 6.2 | 0.00 | May 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Do not call scsi_remove_host() in pm8001_alloc() Calling scsi_remove_host() before scsi_add_host() results in a crash: BUG: kernel NULL pointer dereference, address: 0000000000000108 RIP:… |
- risk 0.40cvss 6.2epss 0.00
Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
- risk 0.40cvss 6.1epss 0.00
A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix'
- risk 0.40cvss 6.2epss 0.00
Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execution abilities to crash the QNX Neutrino kernel.
- risk 0.40cvss 6.2epss 0.00
The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter. The onReceive implementation accesses…
- risk 0.40cvss 7.3epss 0.00
In the Linux kernel, the following vulnerability has been resolved: s390/sclp: Fix SCCB present check Tracing code called by the SCLP interrupt handler contains early exits if the SCCB address associated with an interrupt is NULL. This check is performed after physical to…
- risk 0.40cvss 6.2epss 0.00
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target…
- risk 0.40cvss 6.2epss 0.00
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
- risk 0.40cvss 6.2epss 0.00
A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.
- risk 0.40cvss 6.2epss 0.00
A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.
- risk 0.40cvss 6.2epss 0.00
A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.
- risk 0.40cvss 6.2epss 0.00
A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.
- risk 0.40cvss 6.2epss 0.00
A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.
- risk 0.40cvss 7.3epss 0.00
In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: always recalculate features after XDP clearing, fix null-deref Recalculate features when XDP is detached. Before: # ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp # ip li set dev eth0 xdp…
- risk 0.40cvss 6.2epss 0.00
In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution privileges needed.
- risk 0.40cvss 6.2epss 0.00
NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Networking Stack process.
- risk 0.40cvss 6.2epss 0.00
A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent…
- risk 0.40cvss 6.2epss 0.00
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
- risk 0.40cvss 6.2epss 0.00
transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.
- risk 0.40cvss 6.2epss 0.00
In the Linux kernel, the following vulnerability has been resolved: workqueue: Fix selection of wake_cpu in kick_pool() With cpu_possible_mask=0-63 and cpu_online_mask=0-7 the following kernel oops was observed: smp: Bringing up secondary CPUs ... smp: Brought up 1 node, 8…
- risk 0.40cvss 6.2epss 0.00
In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Do not call scsi_remove_host() in pm8001_alloc() Calling scsi_remove_host() before scsi_add_host() results in a crash: BUG: kernel NULL pointer dereference, address: 0000000000000108 RIP:…