In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix possible wrong descriptor comp
In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by referen
In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before building DA
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_strto
In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB
In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4
Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local E
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
In the Linux kernel, the following vulnerability has been resolved: ext4: publish jinode after initialization ext4_ino
In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: validate packet IDs before indexing t
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refco
A flaw was found in SIPp. A remote attacker could exploit this by sending specially crafted Session Initiation Protocol
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management
NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a N
The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writ
In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Zero-initialize the eb.vma array in i
In the Linux kernel, the following vulnerability has been resolved: KVM: Don't clobber irqfd routing type when deassign
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi
Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally.
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix use of NULL folio in move_pages
In the Linux kernel, the following vulnerability has been resolved: xfs: avoid dereferencing log items after push callb
In the Linux kernel, the following vulnerability has been resolved: media: mtk-mdp: Fix error handling in probe functio
In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Fix Null reference while
In the Linux kernel, the following vulnerability has been resolved: ceph: add a bunch of missing ceph_path_info initial
In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix a crash due to incorrect cleanup
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initi
In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: handle empty bo and UAF races Ther
In the Linux kernel, the following vulnerability has been resolved: bpf: Use RCU-safe iteration in dev_map_redirect_mul
In the Linux kernel, the following vulnerability has been resolved: ALSA: PCM: Fix wait queue list corruption in snd_pc
Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.
Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Don't setup bogus iov_iter for silencing
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers
A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling
A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create
fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be t
NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command T
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker t
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: avoid NULL deref on zero lengt
A Null Pointer Dereference vulnerability exists in the referer header check of the web portal of TP-Link TL-WR841N v14,
HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability
NULL pointer dereference in the daap_reply_groups function in src/httpd_daap.c in owntone-server through commit 5e6f19a
NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through co
A NULL pointer dereference in the parse_meta function (src/httpd_daap.c) of owntone-server commit 334beb allows attacker
A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e
Frequently Asked Questions
What is CWE-476?
CWE-476 (NULL Pointer Dereference) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-476?
There are 881 CVE records associated with CWE-476 in our database. Of these, 8 are critical severity, 201 are high severity, and 572 are medium severity.
How can I protect against CWE-476 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-476 using AI-powered security agents.
Detect CWE-476 Vulnerabilities
CyberStrike's AI agents automatically detect null pointer dereference vulnerabilities across your infrastructure.
Get Started