VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,564)

page 243 of 279
  • CVE-2023-38670MedJul 26, 2023
    risk 0.24cvss 4.7epss 0.01

    Null pointer dereference in paddle.flip in PaddlePaddle before 2.5.0. This resulted in a runtime crash and denial of service.

  • CVE-2022-41909MedNov 18, 2022
    risk 0.24cvss 4.8epss 0.00

    TensorFlow is an open source platform for machine learning. An input `encoded` that is not a valid `CompositeTensorVariant` tensor will trigger a segfault in `tf.raw_ops.CompositeTensorVariantToComponents`. We have patched the issue in GitHub commits…

  • CVE-2019-20919MedSep 17, 2020
    risk 0.24cvss 4.7epss 0.01

    An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.

  • CVE-2026-12051MedAug 11, 2026
    risk 0.23cvss 4.6epss 0.00

    The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer dereference in handle_download() (subsys/usb/device_next/class/usbd_dfu.c). The handler computes MIN(setup->wLength, buf->len) and passes buf->data to the image…

  • CVE-2026-10656MedJul 5, 2026
    risk 0.23cvss 4.6epss 0.00

    The MAX32xxx USB device controller driver (drivers/usb/udc/udc_max32.c, compatible adi_max32_usbhs) dereferenced an endpoint buffer in its OUT and IN transfer-completion handlers without checking it for NULL. udc_event_xfer_out_done() called net_buf_add(buf, ep_request->actlen)…

  • CVE-2026-44710MedMay 27, 2026
    risk 0.23cvss 4.6epss 0.00

    pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/device.c passed the return values of udisks_drive_get_serial(), udisks_drive_get_vendor(), and udisks_drive_get_model() directly to strcmp() without NULL checks. The GIO/UDisks…

  • CVE-2026-31620MedApr 24, 2026
    risk 0.23cvss 4.6epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ALSA: usx2y: us144mkii: fix NULL deref on missing interface 0 A malicious USB device with the TASCAM US-144MKII device id can have a configuration containing bInterfaceNumber=1 but no interface 0. USB…

  • CVE-2024-11588LowNov 21, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in AVL-DiTEST-DiagDev libdoip 1.0.0. It has been rated as problematic. This issue affects the function DoIPConnection::reactOnReceivedTcpMessage of the file DoIPConnection.cpp. The manipulation leads to null pointer dereference.

  • CVE-2023-52371LowFeb 18, 2024
    risk 0.23cvss 3.5epss 0.00

    Vulnerability of null references in the motor module.Successful exploitation of this vulnerability may affect availability.

  • CVE-2021-33572LowJun 21, 2021
    risk 0.23cvss 3.5epss 0.01

    A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will…

  • CVE-2026-47753MedAug 21, 2026
    risk 0.22cvss epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with permission to create instances in any project can…

  • CVE-2022-41603LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41602LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41601LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41600LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41598LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41597LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41595LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41594LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

  • CVE-2022-41593LowOct 14, 2022
    risk 0.22cvss 3.4epss 0.00

    The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.