In the Linux kernel before 5.16.3, drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return va
In the Linux kernel before 5.19, drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expect
In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NUL
In the Linux kernel before 5.15.13, drivers/net/ethernet/mellanox/mlx5/core/steering/dr_domain.c misinterprets the mlx5_
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392.
radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c.
Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1402.
A vulnerability classified as problematic was found in Watchdog Anti-Virus 1.4.214.0. Affected by this vulnerability is
A NULL pointer dereference was found in io_file_bitmap_get in io_uring/filetable.c in the io_uring sub-component in the
A vulnerability classified as problematic has been found in Jianming Antivirus 16.2.2022.418. Affected is an unknown fun
A vulnerability, which was classified as problematic, was found in JiangMin Antivirus 16.2.2022.418. This affects the fu
NASM v2.16 was discovered to contain a null pointer deference in the NASM component
NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious user in a guest VM can cause
In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via ffi_cb_impl_wpwwwww at src/mjs_ffi.c. This vulner
A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Ke
A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel
A null pointer dereference issue was found in can protocol in net/can/af_can.c in the Linux before Linux. ml_priv may no
A null pointer dereference issue was found in the sctp network protocol in net/sctp/stream_sched.c in Linux Kernel. If s
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a NULL pointer dereference
An issue was discovered in drivers/media/test-drivers/vidtv/vidtv_bridge.c in the Linux kernel 6.2. There is a NULL poin
In soter service, there is a possible missing permission check. This could lead to local denial of service with no addit
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no a
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.
A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw all
A vulnerability classified as problematic has been found in FlexiHub 5.5.14691.0. This affects the function 0x220088 in
A vulnerability, which was classified as problematic, was found in eScan Antivirus 22.0.1400.2443. Affected is the funct
iniparser v4.1 is vulnerable to NULL Pointer Dereference in function iniparser_getlongint which misses check NULL for fu
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no addi
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no a
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no a
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no a
An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_
A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local use
A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a
An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the r
A null pointer dereference issue was found in Libtiff's tif_dir.c file. This issue may allow an attacker to pass a craft
An issue was discovered in asn1c through v0.9.28. A NULL pointer dereference exists in the function _default_error_logge
In NATO Communications and Information Agency anet (aka Advisor Network) through 3.3.0, an attacker can provide a crafte
A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a ma
Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacke
An issue was discovered in ecma-helpers.c in jerryscript version 2.3.0, allows local attackers to cause a denial of serv
An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (Do
vim 8.2.2348 is affected by null pointer dereference, allows local attackers to cause a denial of service (DoS) via the
QEMU through 8.0.4 accesses a NULL pointer in nvme_directive_receive in hw/nvme/ctrl.c because there is no check for whe
Frequently Asked Questions
What is CWE-476?
CWE-476 (NULL Pointer Dereference) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-476?
There are 6,577 CVE records associated with CWE-476 in our database. Of these, 121 are critical severity, 1458 are high severity, and 3571 are medium severity.
How can I protect against CWE-476 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-476 using AI-powered security agents.
Detect CWE-476 Vulnerabilities
CyberStrike's AI agents automatically detect null pointer dereference vulnerabilities across your infrastructure.
Get Started