VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,564)

page 249 of 279
  • CVE-2026-0968LowMar 26, 2026
    risk 0.20cvss 3.1epss 0.00

    A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory…

  • CVE-2025-32787LowApr 16, 2025
    risk 0.20cvss 3.1epss 0.00

    SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. Versions 5.02.5184 to 5.02.5187 are vulnerable to NULL dereference in `DeleteIPv6DefaultRouterInRA` called by `StorePacket`. Before dereferencing, `DeleteIPv6DefaultRouterInRA` does not account for…

  • CVE-2025-3122LowApr 2, 2025
    risk 0.20cvss 3.1epss 0.01

    A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file src/interp/binary-reader-interp.cc. The manipulation leads to null pointer dereference. The attack can…

  • CVE-2023-3603LowJul 21, 2023
    risk 0.20cvss 3.1epss 0.01

    A missing allocation check in sftp server processing read requests may cause a NULL dereference on low-memory conditions. The malicious client can request up to 4GB SFTP reads, causing allocation of up to 4GB buffers, which was not being checked for failure. This will likely…

  • CVE-2022-31076MedJun 27, 2022
    risk 0.20cvss 4.2epss 0.01

    KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message can crash CloudCore by triggering a nil-pointer dereference in the UDS Server. Since the UDS Server…

  • CVE-2026-50126MedAug 18, 2026
    risk 0.19cvss 4.0epss 0.00

    Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data via OGC standards. Versions prior to 7.2.2 crash with a memory-safety fault when it parses a GeoJSON document…

  • CVE-2026-32776MedMar 16, 2026
    risk 0.19cvss 4.0epss 0.00

    libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.

  • CVE-2022-31077MedJun 27, 2022
    risk 0.19cvss 4.0epss 0.01

    KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message response from KubeEdge can crash the CSI Driver controller server by triggering a nil-pointer…

  • CVE-2026-55984LowAug 13, 2026
    risk 0.18cvss 2.7epss 0.00

    Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

  • CVE-2026-24641LowMar 10, 2026
    risk 0.18cvss 2.7epss 0.00

    A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon…

  • CVE-2025-1698LowJun 11, 2025
    risk 0.18cvss 2.8epss 0.00

    Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker to cause a denial of service.

  • CVE-2024-43167LowAug 12, 2024
    risk 0.18cvss 2.8epss 0.00

    DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red…

  • CVE-2024-29947LowApr 2, 2024
    risk 0.18cvss 2.7epss 0.00

    There is a NULL dereference pointer vulnerability in some Hikvision NVRs. Due to an insufficient validation of a parameter in a message, an attacker may send specially crafted messages to an affected product, causing a process abnormality.

  • CVE-2022-42878LowMay 10, 2023
    risk 0.18cvss 2.8epss 0.00

    Null pointer dereference for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2026-44638LowMay 14, 2026
    risk 0.16cvss 2.5epss 0.00

    libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode causes a NULL pointer dereference whenever the allocation fails. The check tests the address of the…

  • CVE-2025-8534LowAug 5, 2025
    risk 0.16cvss 2.5epss 0.00

    A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local…

  • CVE-2020-10066LowMay 25, 2021
    risk 0.16cvss 2.5epss 0.00

    Incorrect Error Handling in Bluetooth HCI core. Zephyr versions >= v1.14.2, >= v2.2.0 contain NULL Pointer Dereference (CWE-476). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-gc66-xfrc-24qr

  • CVE-2020-13659LowJun 2, 2020
    risk 0.16cvss 2.5epss 0.00

    address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.

  • CVE-2021-47440LowMay 22, 2024
    risk 0.15cvss 2.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net: encx24j600: check error in devm_regmap_init_encx24j600 devm_regmap_init may return error which caused by like out of memory, this will results in null pointer dereference later when reading or writing…

  • CVE-2021-25491LowOct 6, 2021
    risk 0.15cvss 2.3epss 0.00

    A vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-pointer dereference.