In the Linux kernel, the following vulnerability has been resolved: ice: protect XDP configuration with a mutex The ma
In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Use a cpumask to know what threads
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check debug trap enable before write db
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid race between dcn35_set_drr()
In the Linux kernel, the following vulnerability has been resolved: gfs2: fix double destroy_workqueue error When gfs2
In the Linux kernel, the following vulnerability has been resolved: net/sched: accept TCA_STAB only for root qdisc Mos
In the Linux kernel, the following vulnerability has been resolved: bpf: support non-r10 register spill/fill to/from st
In the Linux kernel, the following vulnerability has been resolved: tracing/probes: Fix MAX_TRACE_ARGS limit handling
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix error propagation of split bios The pur
In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local esca
In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: dcp: fix NULL dereference in AEAD cr
Animate versions 23.0.8, 24.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result i
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix crash when unbinding If there is
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Prevent recovery invocation during prob
In the Linux kernel, the following vulnerability has been resolved: cachefiles: Fix NULL pointer dereference in object-
cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of func
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS Evolved on ACX7024, ACX7100-32C and ACX7100-48L a
Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, t
.NET Denial of Service Vulnerability
When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclose
When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, un
When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traf
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker p
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in vers
A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12,
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix a kernel panic when host sends an in
OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.
In the Linux kernel, the following vulnerability has been resolved: sfc: farch: fix TX queue lookup in TX event handlin
In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: Fix NULL deref when SEND is completed w
A Null pointer dereference in usr/sbin/httpd in ASUS AC68U 3.0.0.4.384.82230 allows remote attackers to trigger DoS via
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix connection failure handling In case
In the Linux kernel, the following vulnerability has been resolved: ipmr: fix kernel panic when forwarding mcast packet
In the Linux kernel, the following vulnerability has been resolved: xsk: fix usage of multi-buffer BPF helpers for ZC X
In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null
In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c f
In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix a NULL pointer dereference in pnfs_mark_
In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content
Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secur
Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.DoubleScramble::
HTTP.sys Denial of Service Vulnerability
JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /labels/BubbleXYItemLabelGenerator.
A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based f
Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the fun
It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects F
A bug in Micrium OS Network HTTP Server permits an invalid pointer dereference during header processing - potentially al
Frequently Asked Questions
What is CWE-476?
CWE-476 (NULL Pointer Dereference) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-476?
There are 6,577 CVE records associated with CWE-476 in our database. Of these, 121 are critical severity, 1458 are high severity, and 3571 are medium severity.
How can I protect against CWE-476 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-476 using AI-powered security agents.
Detect CWE-476 Vulnerabilities
CyberStrike's AI agents automatically detect null pointer dereference vulnerabilities across your infrastructure.
Get Started