VYPR

CWE-476

NULL Pointer Dereference

BaseStableLikelihood: Medium

Description

The product dereferences a pointer that it expects to be valid but is NULL.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (5,530)

page 99 of 277
  • CVE-2021-4186MedDec 30, 2021
    risk 0.41cvss 6.3epss 0.02

    Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

  • CVE-2018-0833MedFeb 15, 2018
    risk 0.41cvss 5.3epss 0.40

    The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2 allows a denial of service vulnerability due to how specially crafted requests are handled, aka "SMBv2/SMBv3 Null Dereference Denial of Service Vulnerability".

  • CVE-2017-15102MedNov 15, 2017
    risk 0.41cvss 6.3epss 0.00

    The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occurs after a race condition and…

  • CVE-2026-20771MedMay 12, 2026
    risk 0.40cvss 6.1epss 0.00

    Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of…

  • CVE-2026-28985MedMay 11, 2026
    risk 0.40cvss 6.2epss 0.00

    A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5. An attacker on the local network may be able to cause a denial-of-service.

  • CVE-2026-25168MedMar 10, 2026
    risk 0.40cvss 6.2epss 0.00

    Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.

  • CVE-2026-22722MedFeb 26, 2026
    risk 0.40cvss 6.1epss 0.00

    A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix'

  • CVE-2025-8090MedJan 13, 2026
    risk 0.40cvss 6.2epss 0.00

    Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execution abilities to crash the QNX Neutrino kernel.

  • CVE-2025-65835MedDec 15, 2025
    risk 0.40cvss 6.2epss 0.00

    The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter. The onReceive implementation accesses…

  • CVE-2025-48073MedJul 31, 2025
    risk 0.40cvss 6.2epss 0.00

    OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, when reading a deep scanline image with a large sample count in reduceMemory mode, it is possible to crash a target…

  • CVE-2025-21433MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.

  • CVE-2025-31181MedMar 27, 2025
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.

  • CVE-2025-31180MedMar 27, 2025
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.

  • CVE-2025-31179MedMar 27, 2025
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.

  • CVE-2025-31178MedMar 27, 2025
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.

  • CVE-2025-31176MedMar 27, 2025
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.

  • CVE-2025-21682HigJan 31, 2025
    risk 0.40cvss 7.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: always recalculate features after XDP clearing, fix null-deref Recalculate features when XDP is detached. Before: # ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp # ip li set dev eth0 xdp…

  • CVE-2024-39440MedOct 9, 2024
    risk 0.40cvss 6.2epss 0.00

    In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution privileges needed.

  • CVE-2024-35215MedOct 8, 2024
    risk 0.40cvss 6.2epss 0.00

    NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Networking Stack process.

  • CVE-2024-8235MedAug 30, 2024
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case would lead to a NULL-pointer dereference and subsequent…