Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-476

MITRE ↗

NULL Pointer Dereference

121
CRITICAL
1,458
HIGH
3,571
MEDIUM
180
LOW
5,370 CVEs · Page 23/108
6.5
CVE-2023-37033

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 0

6.5
CVE-2023-37034

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 0

6.5
CVE-2023-37035

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 0

6.5
CVE-2023-37036

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 0

6.5
CVE-2023-37037

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 0

6.5
CVE-2023-37038

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 0

6.5
CVE-2024-24443

An uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface

6.5
CVE-2023-37039

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 0

6.5
CVE-2024-57719

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.

6.5
CVE-2024-57435

In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a nul

6.5
CVE-2025-1103

A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802. This affects the funct

6.5
CVE-2025-22921

FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/

6.5
CVE-2025-20647

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i

6.5
CVE-2025-1877

A vulnerability, which was classified as critical, was found in D-Link DAP-1562 1.10. This affects the function pure_aut

6.5
CVE-2025-2956

A vulnerability was found in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ and classified as problematic. This issue affects th

6.5
CVE-2025-2957

A vulnerability was found in TRENDnet TEW-411BRP+ 2.07. It has been classified as problematic. Affected is the function

6.5
CVE-2025-2959

A vulnerability was found in TRENDnet TEW-410APB 1.3.06b. It has been rated as problematic. Affected by this issue is th

6.5
CVE-2025-2960

A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106. This affe

6.5
CVE-2025-30670

Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of

6.5
CVE-2025-30671

Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of

6.5
CVE-2025-32910

A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This iss

6.5
CVE-2025-32912

A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause

6.5
CVE-2025-24251

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequ

6.5
CVE-2025-29835

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor

6.5
CVE-2025-20071

NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial

6.5
CVE-2025-30665

NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of

6.5
CVE-2025-30666

NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of

6.5
CVE-2025-30667

NULL pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of

6.5
CVE-2025-4478

A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a se

6.5
CVE-2025-33057

Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a

6.5
CVE-2025-53179

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m

6.5
CVE-2025-53180

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m

6.5
CVE-2025-53181

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m

6.5
CVE-2025-53182

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m

6.5
CVE-2025-53183

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m

6.5
CVE-2025-53184

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability m

6.5
CVE-2025-6395

A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().

6.5
CVE-2025-8033

The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr

6.5
CVE-2025-8175

A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown p

6.5
CVE-2025-49832

Asterisk is an open source private branch exchange and telephony toolkit. In versions up to and including 18.26.2, betwe

6.5
CVE-2025-50952

openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

6.5
CVE-2025-24515

NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial

6.5
CVE-2025-53716

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to

6.5
CVE-2025-29901

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

6.5
CVE-2025-29874

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

6.5
CVE-2025-29875

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

6.5
CVE-2025-29878

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

6.5
CVE-2025-29879

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

6.5
CVE-2025-29882

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote

6.5
CVE-2025-29886

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a

Frequently Asked Questions

What is CWE-476?

CWE-476 (NULL Pointer Dereference) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-476?

There are 6,577 CVE records associated with CWE-476 in our database. Of these, 121 are critical severity, 1458 are high severity, and 3571 are medium severity.

How can I protect against CWE-476 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-476 using AI-powered security agents.

Detect CWE-476 Vulnerabilities

CyberStrike's AI agents automatically detect null pointer dereference vulnerabilities across your infrastructure.

Get Started