VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,659)

page 73 of 283
  • CVE-2026-30072HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.

  • CVE-2026-30069HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.

  • CVE-2026-63076HigAug 25, 2026
    risk 0.42cvss 7.5epss 0.01

    Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced…

  • CVE-2026-14457HigAug 25, 2026
    risk 0.42cvss 7.5epss 0.01

    Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the…

  • CVE-2026-76905HigAug 21, 2026
    risk 0.42cvss 7.5epss 0.00

    kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A malformed non-string scalar field in a…

  • CVE-2026-73199MedAug 20, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol (LDAP) extended operation. By omitting the request value for the `JOIN_OID` in…

  • CVE-2026-16846MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a null pointer dereference.

  • CVE-2026-75618MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.00

    Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful…

  • CVE-2026-75013MedAug 17, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation results in null pointer dereference. The attack can be launched remotely. The exploit is now public and may be used.

  • CVE-2026-75012MedAug 17, 2026
    risk 0.42cvss 6.5epss 0.00

    A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Password Configuration Handler. The manipulation leads to null pointer dereference. The…

  • CVE-2026-18699MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. This could result in a denial of service,…

  • CVE-2026-61345MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

  • CVE-2026-59138MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

  • CVE-2026-18638MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.

  • CVE-2026-11810HigAug 10, 2026
    risk 0.42cvss 7.5epss 0.00

    The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned by the update server into a fixed two-level nested-array struct. After parsing it validates only the outer array length…

  • CVE-2026-17510HigAug 9, 2026
    risk 0.42cvss 7.5epss 0.00

    Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attribute. print_attribute() sizes the destination buffer for a BMPSTRING attribute from its declared byte length with `Renew(*attribute, length,…

  • CVE-2026-52878HigAug 7, 2026
    risk 0.42cvss 7.5epss 0.00

    Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawData to decode to nil. Every…

  • CVE-2026-67304HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process…

  • CVE-2026-67288HigAug 1, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send…

  • CVE-2026-18064HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.00

    An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause…