Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12
liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with
Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the
In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticat
Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE W
A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthent
MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10
Null pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0
Lack of null check while freeing the device information buffer in the Bluetooth HFP protocol can lead to a NULL pointer
Possible null pointer dereference due to lack of WDOG structure validation during registration in Snapdragon Auto, Snapd
Insufficient validation of trust input in WebOTP in Google Chrome on Android prior to 100.0.4896.60 allowed a remote att
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availabil
A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to ex
A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() i
Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a den
GPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8_wcslen is a renamed Unicode utf8_wcslen
XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff
Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseTensorSliceDataset` has an undefin
A NULL pointer dereference in the main() function dhry_1.c of dhrystone 2.1 causes a denial of service (DoS).
There is a Null pointer dereference in Smartphones.Successful exploitation of this vulnerability may cause the kernel to
The HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may c
The HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may c
The eID module has a null pointer reference vulnerability. Successful exploitation of this vulnerability may affect data
The bone voice ID TA has a vulnerability in calculating the buffer length,Successful exploitation of this vulnerability
There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this v
There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this v
Possible null pointer dereference due to improper validation of APE clip in Snapdragon Auto, Snapdragon Compute, Snapdra
ROPium v3.1 was discovered to contain an invalid memory address dereference via the find() function.
A NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a
A NULL pointer dereference in CS104_IPAddress_setFromString at src/iec60870/cs104/cs104_slave.c of lib60870 commit 0d5e7
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon cras
mruby is vulnerable to NULL Pointer Dereference
There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that coul
There is a NULL pointer deference in the Allwinner R818 SoC Android Q SDK V1.0 camera driver /dev/cedar_dev that could u
There is a NULL pointer dereference in media/libcedarc/vdecoder of Allwinner R818 SoC Android Q SDK V1.0, which could ca
On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP SSL Forward Proxy with TLS 1.3 is configured on
On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when a
On BIG-IP version 16.1.x before 16.1.2, when the 'Respond on Error' setting is enabled on the Request Logging profile an
On BIG-IP version 16.1.x before 16.1.2, when any of the following configurations are configured on a virtual server, und
On BIG-IP version 16.1.x before 16.1.2, when an HTTP profile is configured on a virtual server, undisclosed requests can
On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a
Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack o
NULL Pointer Dereference in Homebrew mruby prior to 3.2.
Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted r
An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client
A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts c
A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of S
Frequently Asked Questions
What is CWE-476?
CWE-476 (NULL Pointer Dereference) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-476?
There are 6,577 CVE records associated with CWE-476 in our database. Of these, 121 are critical severity, 1458 are high severity, and 3571 are medium severity.
How can I protect against CWE-476 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-476 using AI-powered security agents.
Detect CWE-476 Vulnerabilities
CyberStrike's AI agents automatically detect null pointer dereference vulnerabilities across your infrastructure.
Get Started