An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO
A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a
GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomed
Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticat
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9
The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications.
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with per
SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript
In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attac
A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator
Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash th
Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo
An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the ser
A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the func
A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the fi
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate t
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a null p
Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api/boards/:boardId/att
A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer derefere
A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been re
A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options.
Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execut
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service loc
Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, t
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5
mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of sm
A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allow
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow
A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null poi
jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin
Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Appl
Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an un
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affec
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18
An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leadin
In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_c
A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before us
Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decr
Frequently Asked Questions
What is CWE-476?
CWE-476 (NULL Pointer Dereference) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-476?
There are 6,577 CVE records associated with CWE-476 in our database. Of these, 121 are critical severity, 1458 are high severity, and 3571 are medium severity.
How can I protect against CWE-476 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-476 using AI-powered security agents.
Detect CWE-476 Vulnerabilities
CyberStrike's AI agents automatically detect null pointer dereference vulnerabilities across your infrastructure.
Get Started