VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,508)

page 256 of 276
  • CVE-2024-13978LowAug 1, 2025
    risk 0.00cvss 2.5epss 0.00

    A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the file tools/tiff2pdf.c of the component fax2ps. The manipulation leads to null pointer dereference. The attack needs to…

  • CVE-2025-7797MedJul 18, 2025
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf_dash_download_init_segment of the file src/media_tools/dash_client.c. The manipulation of the argument base_init_url leads to null pointer dereference. The…

  • CVE-2024-25177HigJul 7, 2025
    risk 0.00cvss 7.5epss 0.00

    LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS).

  • CVE-2025-45333HigJun 25, 2025
    risk 0.00cvss 7.5epss 0.00

    berkeley-abc abc 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the Abc_NtkCecFraigPart function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.

  • CVE-2025-45331HigJun 20, 2025
    risk 0.00cvss 7.5epss 0.00

    brplot v420.69.1 contains a Null Pointer Dereference (NPD) vulnerability in the br_dagens_handle_once function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.

  • CVE-2023-47466LowMay 22, 2025
    risk 0.00cvss 2.9epss 0.00

    TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the only valid chunk.

  • CVE-2025-43967LowApr 21, 2025
    risk 0.00cvss 2.9epss 0.00

    libheif before 1.19.6 has a NULL pointer dereference in ImageItem_Grid::get_decoder in image-items/grid.cc because a grid image can reference a nonexistent image item.

  • CVE-2025-43966LowApr 21, 2025
    risk 0.00cvss 2.9epss 0.00

    libheif before 1.19.6 has a NULL pointer dereference in ImageItem_iden in image-items/iden.cc.

  • CVE-2025-1470MedFeb 21, 2025
    risk 0.00cvss 5.5epss 0.00

    In Eclipse OMR, from the initial contribution to version 0.4.0, some OMR internal port library and utilities consumers of z/OS atoe functions do not check their return values for NULL memory pointers or for memory allocation failures. This can lead to NULL pointer dereference…

  • CVE-2025-25475HigFeb 18, 2025
    risk 0.00cvss 7.5epss 0.01

    A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.

  • CVE-2024-51738HigJan 20, 2025
    risk 0.00cvss 8.1epss 0.01

    Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementation does not validate request order and is thereby vulnerable to a MITM attack, potentially allowing an unauthenticated attacker to pair a client by hijacking…

  • CVE-2024-53270HigDec 18, 2024
    risk 0.00cvss 7.5epss 0.01

    Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request exists when `envoy.load_shed_points.http1_server_abort_dispatch` is configured. If `active_request` is nullptr, only…

  • CVE-2024-44856HigDec 6, 2024
    risk 0.00cvss 7.5epss 0.01

    Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner().

  • CVE-2024-44855HigDec 6, 2024
    risk 0.00cvss 7.5epss 0.01

    Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner().

  • CVE-2024-44854HigDec 6, 2024
    risk 0.00cvss 7.5epss 0.01

    Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component smoothPlan().

  • CVE-2024-44853HigDec 6, 2024
    risk 0.00cvss 7.5epss 0.01

    Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl().

  • CVE-2024-36626MedNov 29, 2024
    risk 0.00cvss 5.3epss 0.01

    In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php.

  • CVE-2024-42491MedSep 5, 2024
    risk 0.00cvss 5.7epss 0.01

    Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7-cert2 of certified-asterisk, if Asterisk attempts to send a SIP request to a URI whose host portion starts with `.1` or `[.1]`,…

  • CVE-2024-8006MedAug 31, 2024
    risk 0.00cvss 4.4epss 0.00

    Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture support enabled, one of the functions that become available is pcap_findalldevs_ex(). One of the function arguments can be a filesystem path, which normally…

  • CVE-2024-6063LowJun 17, 2024
    risk 0.00cvss 3.3epss 0.00

    A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been classified as problematic. This affects the function m2tsdmx_on_event of the file src/filters/dmx_m2ts.c of the component MP4Box. The manipulation leads to null pointer dereference. An attack has to…