Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the
A NULL pointer dereference vulnerability in the Linux kernel NVMe functionality, in nvmet_setup_auth(), allows an attack
In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer
On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, whe
On version 14.1.x before 14.1.5.3, and all versions of 13.1.x, when the BIG-IP APM system is configured with all the fol
On BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and a
In Wi-Fi driver, there is a possible system crash due to null pointer dereference. This could lead to remote denial of s
An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the
An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by
A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In cas
Denial of service in modem due to null pointer dereference while processing DNS packets
Denial of service in modem due to missing null check while processing TCP or UDP packets from server
Windows iSCSI Discovery Service Denial of Service Vulnerability
In crasm 1.8-3, invalid input validation, specific files passed to the command line application, can lead to a NULL poin
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring functio
An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoint
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the macinstring function.
An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at t
A vulnerability was found in Filseclab Twister Antivirus 8. It has been rated as critical. This issue affects the functi
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when the parameter `sum
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `ctx->step_contain
TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, when `SparseSparseMaxim
TensorFlow is an open source platform for machine learning. Versions prior to 2.12.0 and 2.11.1 have a null point error
TensorFlow is an open source platform for machine learning. The function `tf.raw_ops.LookupTableImportV2` cannot handle
TensorFlow is an open source machine learning platform. Versions prior to 2.12.0 and 2.11.1 have a null pointer error in
TensorFlow is an open source machine learning platform. When running versions prior to 2.12.0 and 2.11.1 with XLA, `tf.r
The Heimdal Software Kerberos 5 implementation is vulnerable to a null pointer dereferance. An attacker with network acc
mod_auth_openidc is an authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID
An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function
A vulnerability has been identified in SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V9.40), SIPROTEC 5 6MD86 (CP300
libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validat
Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call
Transient DOS in Modem due to null pointer dereference while processing the incoming packet with http chunked encoding.
Transient DOS in Modem due to NULL pointer dereference while receiving response of lwm2m registration/update/bootstrap r
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc
RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to proc
Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet.
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH.
In NanoMQ v0.15.0-0, segment fault with Null Pointer Dereference occurs in the process of decoding subinfo_decode and un
The Contiki-NG operating system versions 4.8 and prior can be triggered to dereference a NULL pointer in the message han
Windows Pragmatic General Multicast (PGM) Denial of Service Vulnerability
A null pointer dereference bug in Hermes prior to commit 5cae9f72975cf0e5a62b27fdd8b01f103e198708 could have been used b
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function
Frequently Asked Questions
What is CWE-476?
CWE-476 (NULL Pointer Dereference) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-476?
There are 6,577 CVE records associated with CWE-476 in our database. Of these, 121 are critical severity, 1458 are high severity, and 3571 are medium severity.
How can I protect against CWE-476 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-476 using AI-powered security agents.
Detect CWE-476 Vulnerabilities
CyberStrike's AI agents automatically detect null pointer dereference vulnerabilities across your infrastructure.
Get Started