PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer derefere
In the Linux kernel, the following vulnerability has been resolved: ice: Fix PTP NULL pointer dereference during VSI re
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service
The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that,
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a NULL po
In the Linux kernel, the following vulnerability has been resolved: ALSA: usx2y: us144mkii: fix NULL deref on missing i
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/device.c passed t
The MAX32xxx USB device controller driver (drivers/usb/udc/udc_max32.c, compatible adi_max32_usbhs) dereferenced an endp
The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer der
An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistenc
If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a
A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolve
A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the fi
A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function Requ
A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function smf_nsmf_handle_create_data_in_hsmf of t
A security flaw has been discovered in omec-project amf up to 2.1.3-dev. The impacted element is the function RANConfigu
A weakness has been identified in omec-project amf up to 2.1.3-dev. This affects an unknown function of the file ngap/ha
A security vulnerability has been detected in omec-project amf up to 2.1.3-dev. This impacts the function UERadioCapabil
A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can r
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscript
Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer deref
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multica
A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/na
libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a
Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affe
Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affe
Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteo
A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could al
In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to
Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.
A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::pa
A security flaw has been discovered in nicbarker clay up to 0.14. This affects the function Clay__MeasureTextCached in t
A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file
A security flaw has been discovered in GPAC up to 2.4.0. Affected by this vulnerability is the function DumpMovieInfo of
A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file app
A security vulnerability has been detected in oatpp up to 1.3.1. This impacts the function oatpp::data::type::ObjectWrap
A vulnerability was detected in libuvc up to 0.0.7. Affected is the function uvc_scan_streaming of the file src/device.c
A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompt
A security vulnerability has been detected in ggreer the_silver_searcher up to 2.2.0. The impacted element is the functi
A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_rules of the file src
A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_he
A vulnerability has been found in wren-lang wren up to 0.4.0. Affected by this issue is the function getByteCountForArgu
A vulnerability was determined in Squirrel up to 3.2. This vulnerability affects the function sqstd_rex_newnode in the l
A weakness has been identified in FascinatedBox lily up to 2.3. The affected element is the function eval_tree of the fi
A vulnerability was identified in xlnt-community xlnt up to 1.6.1. The affected element is the function xlnt::detail::xl
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the U
Frequently Asked Questions
What is CWE-476?
CWE-476 (NULL Pointer Dereference) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-476?
There are 6,577 CVE records associated with CWE-476 in our database. Of these, 121 are critical severity, 1458 are high severity, and 3571 are medium severity.
How can I protect against CWE-476 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-476 using AI-powered security agents.
Detect CWE-476 Vulnerabilities
CyberStrike's AI agents automatically detect null pointer dereference vulnerabilities across your infrastructure.
Get Started