VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,553)

page 212 of 278
  • CVE-2025-48726MedOct 3, 2025
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-47214MedOct 3, 2025
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2025-47213MedOct 3, 2025
    risk 0.32cvss 4.9epss 0.00

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2024-11499MedMar 25, 2025
    risk 0.32cvss 4.9epss 0.00

    A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can be triggered if certificates are updated while in use on active connections. The affected CMU…

  • CVE-2025-2487MedMar 18, 2025
    risk 0.32cvss 4.9epss 0.01

    A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a…

  • CVE-2024-37048MedNov 22, 2024
    risk 0.32cvss 4.9epss 0.01

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2024-37045MedNov 22, 2024
    risk 0.32cvss 4.9epss 0.01

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2024-37042MedNov 22, 2024
    risk 0.32cvss 4.9epss 0.01

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the…

  • CVE-2023-32970MedOct 13, 2023
    risk 0.32cvss 4.9epss 0.01

    A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network. QES is not affected. We have already…

  • CVE-2023-0845MedMar 9, 2023
    risk 0.32cvss 4.9epss 0.01

    Consul and Consul Enterprise allowed an authenticated user with service:write permissions to trigger a workflow that causes Consul server and client agents to crash under certain circumstances. This vulnerability was fixed in Consul 1.14.5.

  • CVE-2020-1995MedMay 13, 2020
    risk 0.32cvss 4.9epss 0.01

    A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by restarting the…

  • CVE-2019-19269MedNov 30, 2019
    risk 0.32cvss 4.9epss 0.02

    An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs…

  • CVE-2019-19242MedNov 27, 2019
    risk 0.32cvss 5.9epss 0.03

    SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c.

  • CVE-2019-14847MedNov 6, 2019
    risk 0.32cvss 4.9epss 0.02

    A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.

  • CVE-2016-9572MedAug 1, 2018
    risk 0.32cvss 5.9epss 0.03

    A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.

  • CVE-2015-6569MedFeb 21, 2018
    risk 0.32cvss 5.9epss 0.02

    Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and thread crash) via a state manipulation attack.

  • CVE-2026-17009MedAug 20, 2026
    risk 0.31cvss 4.7epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a NULL pointer dereference.

  • CVE-2026-76927MedAug 19, 2026
    risk 0.31cvss 4.7epss 0.00

    H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76881MedAug 19, 2026
    risk 0.31cvss 4.7epss 0.00

    CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-55717MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: redirect' /'response-ip-data: CNAME ' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain…