iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR)
Windows TCP/IP Denial of Service Vulnerability
In the Linux kernel, the following vulnerability has been resolved: drm/exynos: vidi: fix to avoid directly dereferenci
Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio
llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrap
Address read vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect
Null pointer dereference in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability within Ring 0: Kernel
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,
A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows an adjacent attacker to cau
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and belo
A segmentation violation in the oneflow.logical_or component of OneFlow v0.9.0 allows attackers to cause a Denial of Ser
A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior versi
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing /
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A vulnerability in of Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker t
Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vul
arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An att
Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Tra
Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted
Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Respo
An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeomet
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora
An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When
Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an
Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline back
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch betwee
Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a netw
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequen
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-policyauthoriz
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attacker
In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines
Frequently Asked Questions
What is CWE-476?
CWE-476 (NULL Pointer Dereference) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-476?
There are 6,577 CVE records associated with CWE-476 in our database. Of these, 121 are critical severity, 1458 are high severity, and 3571 are medium severity.
How can I protect against CWE-476 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-476 using AI-powered security agents.
Detect CWE-476 Vulnerabilities
CyberStrike's AI agents automatically detect null pointer dereference vulnerabilities across your infrastructure.
Get Started