In the Linux kernel, the following vulnerability has been resolved: dmaengine: sf-pdma: Add multithread support for a D
In the Linux kernel, the following vulnerability has been resolved: dma-buf: insert memory barrier before updating num_
In the Linux kernel, the following vulnerability has been resolved: tipc: fix null-ptr-deref when acquiring remote ip o
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Avoid NULL pointer dereference in `v3d_job
In the Linux kernel, the following vulnerability has been resolved: net: clear the dst when changing skb protocol A no
Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
In the Linux kernel, the following vulnerability has been resolved: tty: serial: uartlite: register uart driver in init
In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: reallocate BAM transactions U
In the Linux kernel, the following vulnerability has been resolved: genirq/irq_sim: Initialize work context pointers pr
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Reject SEV{-ES} intra host migration if v
In the Linux kernel, the following vulnerability has been resolved: smc: Fix various oops due to inet_sock type confusi
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi
In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Fix fp initialization for exception bou
In the Linux kernel, the following vulnerability has been resolved: wifi: rtl818x: Kill URBs before clearing tx status
In the Linux kernel, the following vulnerability has been resolved: media: ti: j721e-csi2rx: fix list_del corruption I
In the Linux kernel, the following vulnerability has been resolved: gfs2: No more self recovery When a node withdraws
SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service
In the Linux kernel, the following vulnerability has been resolved: s390/mm: Do not map lowcore with identity mapping
In the Linux kernel, the following vulnerability has been resolved: gve: prevent ethtool ops after shutdown A crash ca
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix kfd_process_device_init_vm error ha
In the Linux kernel, the following vulnerability has been resolved: skbuff: skb_segment, Call zero copy functions befor
In the Linux kernel, the following vulnerability has been resolved: net/tunnel: wait until all sk_user_data reader fini
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix sysfs interface lifetime The current n
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: remove oem i2c adapter on finish
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate the box size for the snooped c
In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: iscsi_tcp: Fix null-ptr-deref while ca
In the Linux kernel, the following vulnerability has been resolved: null_blk: fix poll request timeout handling When d
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: fix null deref on elemen
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix missing initialisation affecti
In the Linux kernel, the following vulnerability has been resolved: tipc: fix a null-ptr-deref in tipc_topsrv_accept s
In the Linux kernel, the following vulnerability has been resolved: memcontrol: ensure memcg acquired by id is properly
In the Linux kernel, the following vulnerability has been resolved: scsi: hisi_sas: Grab sas_dev lock when traversing t
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: don't access released socket during error
In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_no
Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privilege
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. When pages in
Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network.
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated atta
A vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerabili
Belledonne Communications Linphone-Desktop is vulnerable to a NULL Dereference vulnerability, which could allow a remo
A NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3
In the Linux kernel, the following vulnerability has been resolved: net: fec: handle page_pool_dev_alloc_pages error T
When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are
An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The absence of a null check leads to a Denial
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table
Frequently Asked Questions
What is CWE-476?
CWE-476 (NULL Pointer Dereference) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-476?
There are 6,577 CVE records associated with CWE-476 in our database. Of these, 121 are critical severity, 1458 are high severity, and 3571 are medium severity.
How can I protect against CWE-476 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-476 using AI-powered security agents.
Detect CWE-476 Vulnerabilities
CyberStrike's AI agents automatically detect null pointer dereference vulnerabilities across your infrastructure.
Get Started