Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-476

MITRE ↗

NULL Pointer Dereference

121
CRITICAL
1,458
HIGH
3,571
MEDIUM
180
LOW
5,370 CVEs · Page 15/108
5.3
CVE-2026-1973

A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the

5.3
CVE-2026-1975

A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pf

5.3
CVE-2026-1976

A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component

5.3
CVE-2026-2062

A vulnerability was identified in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_modify_bearer_response/

5.3
CVE-2025-10256

A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a

5.3
CVE-2026-25795

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1

5.3
CVE-2026-25798

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1

5.3
CVE-2026-26983

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1

5.3
CVE-2026-32249

Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encoun

5.3
CVE-2026-4751

NULL Pointer Dereference vulnerability in tmate-io tmate.This issue affects tmate: before 2.4.0.

5.3
CVE-2026-6778

Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

5.3
CVE-2026-33007

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated r

5.3
CVE-2026-8723

### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on

5.3
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be c

5.3
CVE-2026-12329

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 14

5.3
CVE-2026-58369

Woodpecker before 3.15.0 registers the /api/orgs/lookup/*org_full_name endpoint without authentication middleware, and t

5.3
CVE-2026-20457

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

5.3
CVE-2026-62299

CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an

5.3
CVE-2026-13070

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP respons

5.3
CVE-2026-17500

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file

5.3
CVE-2026-19012

Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service

5.3
CVE-2026-73502

kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can enc

5.3
CVE-2026-16829

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL p

5.3
CVE-2026-78148

A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of t

5.3
CVE-2026-13213

The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set uncondit

5.3
CVE-2026-54084

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I

5.1
CVE-2026-47271

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, src/mem.c implemented

5.1
CVE-2026-47143

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMR

5.0
CVE-2026-6845

A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to c

5.0
CVE-2025-60477

A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Pr

4.9
CVE-2025-52426

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52430

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-52431

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-53405

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-53414

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-53589

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-53590

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-53596

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-47205

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-54163

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains an admin

4.9
CVE-2025-58472

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains an admini

4.9
CVE-2025-59386

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-66274

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

4.9
CVE-2025-11845

A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware ve

4.9
CVE-2025-11846

A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions

4.9
CVE-2025-11847

A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions thro

4.9
CVE-2025-11848

A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version throu

4.9
CVE-2026-0401

A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.

4.9
CVE-2026-71920

Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vul

4.9
CVE-2026-75125

PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /c

Frequently Asked Questions

What is CWE-476?

CWE-476 (NULL Pointer Dereference) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-476?

There are 6,577 CVE records associated with CWE-476 in our database. Of these, 121 are critical severity, 1458 are high severity, and 3571 are medium severity.

How can I protect against CWE-476 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-476 using AI-powered security agents.

Detect CWE-476 Vulnerabilities

CyberStrike's AI agents automatically detect null pointer dereference vulnerabilities across your infrastructure.

Get Started