VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,669)

page 106 of 284
  • CVE-2026-25168MedMar 10, 2026
    risk 0.40cvss 6.2epss 0.00

    Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.

  • CVE-2026-22722MedFeb 26, 2026
    risk 0.40cvss 6.1epss 0.00

    A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix'

  • CVE-2025-8090MedJan 13, 2026
    risk 0.40cvss 6.2epss 0.00

    Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execution abilities to crash the QNX Neutrino kernel.

  • CVE-2025-65835MedDec 15, 2025
    risk 0.40cvss 6.2epss 0.00

    The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter. The onReceive implementation accesses…

  • CVE-2025-39694HigSep 5, 2025
    risk 0.40cvss 7.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: s390/sclp: Fix SCCB present check Tracing code called by the SCLP interrupt handler contains early exits if the SCCB address associated with an interrupt is NULL. This check is performed after physical to…

  • CVE-2025-48073MedJul 31, 2025
    risk 0.40cvss 6.2epss 0.00

    OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target…

  • CVE-2025-21433MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.

  • CVE-2025-31181MedMar 27, 2025
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.

  • CVE-2025-31180MedMar 27, 2025
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.

  • CVE-2025-31179MedMar 27, 2025
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.

  • CVE-2025-31178MedMar 27, 2025
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.

  • CVE-2025-31176MedMar 27, 2025
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.

  • CVE-2025-21682HigJan 31, 2025
    risk 0.40cvss 7.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: always recalculate features after XDP clearing, fix null-deref Recalculate features when XDP is detached. Before: # ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp # ip li set dev eth0 xdp…

  • CVE-2024-39440MedOct 9, 2024
    risk 0.40cvss 6.2epss 0.00

    In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution privileges needed.

  • CVE-2024-35215MedOct 8, 2024
    risk 0.40cvss 6.2epss 0.00

    NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Networking Stack process.

  • CVE-2024-8235MedAug 30, 2024
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent…

  • CVE-2024-23357MedAug 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.

  • CVE-2024-21478MedJun 3, 2024
    risk 0.40cvss 6.2epss 0.00

    transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA.

  • CVE-2024-36888MedMay 30, 2024
    risk 0.40cvss 6.2epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: workqueue: Fix selection of wake_cpu in kick_pool() With cpu_possible_mask=0-63 and cpu_online_mask=0-7 the following kernel oops was observed: smp: Bringing up secondary CPUs ... smp: Brought up 1 node, 8…

  • CVE-2021-47503MedMay 24, 2024
    risk 0.40cvss 6.2epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Do not call scsi_remove_host() in pm8001_alloc() Calling scsi_remove_host() before scsi_add_host() results in a crash: BUG: kernel NULL pointer dereference, address: 0000000000000108 RIP:…