An issue was discovered in the Linux kernel through 5.16-rc6. amvdec_set_canvases in drivers/staging/media/meson/vdec/vd
An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcode
An issue was discovered in the Linux kernel through 5.16-rc6. imx_register_uart_clocks in drivers/clk/imx/clk.c lacks ch
An issue was discovered in the Linux kernel through 5.16-rc6. malidp_crtc_reset in drivers/gpu/drm/arm/malidp_crtc.c lac
NVIDIA Display Driver for Linux contains a vulnerability in the Virtual GPU Manager, where it does not check the return
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unhandled return
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular use
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkD
Tensorflow is an Open Source Machine Learning Framework. When building an XLA compilation cache, if default settings are
A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. This issue affects the function AP4_Sts
Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Po
Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Po
A race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lead to a NULL pointer dereference and gene
Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.
In sdpu_find_most_specific_service_uuid of sdp_utils.cc, there is a possible way to crash Bluetooth due to a missing nul
TensorFlow is an open source platform for machine learning. An input `encoded` that is not a valid `CompositeTensorVaria
NVIDIA Tegra kernel driver contains a vulnerability in NVHost, where a specific race condition can lead to a null pointe
A NULL pointer dereference flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a
An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem l
A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_bmap_lo
KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to ho
KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to ho
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted appli
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted appli
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted appli
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted appli
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted appli
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted appli
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted appli
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted appli
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted appli
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted appli
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load
A NULL pointer dereference flaw was found in pesign's cms_set_pw_data() function of the cms_common.c file. The function
A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a nul
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to 4.9 con
NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to e
Null Pointer Dereference may occur due to improper validation while processing crafted SDP body in Snapdragon Auto, Snap
A vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.
An issue was discovered in function latm_write_packet in libavformat/latmenc.c in Ffmpeg 4.2.1, allows attackers to caus
TensorFlow is an open source platform for machine learning. In affected versions the code for boosted trees in TensorFlo
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of s
A NULL Pointer Dereference vulnerability in the Captive Portal Content Delivery (CPCD) services daemon (cpcd) of Juniper
TensorFlow is an end-to-end open source platform for machine learning. When restoring tensors via raw APIs, if the tenso
Frequently Asked Questions
What is CWE-476?
CWE-476 (NULL Pointer Dereference) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-476?
There are 6,577 CVE records associated with CWE-476 in our database. Of these, 121 are critical severity, 1458 are high severity, and 3571 are medium severity.
How can I protect against CWE-476 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-476 using AI-powered security agents.
Detect CWE-476 Vulnerabilities
CyberStrike's AI agents automatically detect null pointer dereference vulnerabilities across your infrastructure.
Get Started