CWE-476: NULL Pointer Dereference

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

1,252
Total CVEs
21
Critical
303
High
6.1
Avg CVSS

Yearly Trend

2026
76
2025
628
2024
382
2023
55
2022
37

Top Affected Vendors

1 Linux 754
2 Debian 96
3 Qnap 44
4 Google 21
5 Adobe 21
6 Microsoft 20
7 Qualcomm 19
8 Fedoraproject 18
9 Linuxfoundation 11
10 Huawei 10

All NULL Pointer Dereference CVEs (1,252)

CVE-2025-38610
5.5

A NULL pointer dereference vulnerability in the Linux kernel's powercap subsystem allows local attackers to crash the kernel when a CPU becomes unavai...

Aug 19, 2025
CVE-2025-38604
5.5

A use-after-free vulnerability in the Linux kernel's RTL8187/8187B USB WiFi driver allows a NULL pointer dereference when stopping the device. This ca...

Aug 19, 2025
CVE-2025-38606
5.5

A null pointer dereference vulnerability in the Linux kernel's ath12k WiFi driver allows local attackers to cause a kernel panic (denial of service) w...

Aug 19, 2025
CVE-2025-38586
5.5

A flaw in the ARM64 BPF JIT compiler in the Linux kernel fails to initialize the frame pointer for exception boundary programs, potentially causing ke...

Aug 19, 2025
CVE-2025-38581
5.5

A NULL pointer dereference vulnerability in the Linux kernel's AMD Cryptographic Coprocessor (CCP) driver causes a kernel crash when rebinding the CCP...

Aug 19, 2025
CVE-2025-38558
5.5

A NULL pointer dereference vulnerability in the Linux kernel's USB gadget UVC driver causes kernel crashes when userspace configures frame-based video...

Aug 19, 2025
CVE-2025-38559
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's Intel Platform Monitoring Technology (PMT) driver. When accessing cr...

Aug 19, 2025
CVE-2025-38562
5.5

A null pointer dereference vulnerability in the Linux kernel's ksmbd module could cause kernel crashes or denial of service when clients send multiple...

Aug 19, 2025
CVE-2025-38543
5.5

This CVE is a NULL pointer dereference vulnerability in the Linux kernel's NVIDIA Tegra NVDEC driver. It occurs when dma_alloc_coherent fails to alloc...

Aug 16, 2025
CVE-2025-38526
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Intel Ethernet Controller (ice) driver could cause kernel panics or system crashes when...

Aug 16, 2025
CVE-2025-38522
5.5

A NULL pointer dereference vulnerability in the Linux kernel's scheduler extension (SCX) subsystem could cause a kernel warning or system instability ...

Aug 16, 2025
CVE-2025-38510
5.5

This CVE describes a potential deadlock vulnerability in the Linux kernel's KASAN (Kernel Address SANitizer) subsystem. When KASAN attempts to report ...

Aug 16, 2025
CVE-2025-38516
5.5

A vulnerability in the Linux kernel's Qualcomm pinctrl-msm driver allows user-space applications to trigger a kernel BUG() and potentially crash the s...

Aug 16, 2025
CVE-2025-38517
5.5

A NULL pointer dereference vulnerability in the Linux kernel's memory allocation tagging subsystem causes a kernel crash when attempting to lock a non...

Aug 16, 2025
CVE-2025-47807
5.5

A NULL pointer dereference vulnerability in GStreamer's subparse plugin allows attackers to cause denial of service by crashing applications that proc...

Aug 7, 2025
CVE-2025-38473
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's Bluetooth L2CAP socket implementation. When exploited, it can cause ...

Jul 28, 2025
CVE-2025-38475
5.5

A type confusion vulnerability in the Linux kernel's SMC (Shared Memory Communications) subsystem allows non-INET sockets to incorrectly reuse INET so...

Jul 28, 2025
CVE-2025-38455
5.5

This CVE describes a race condition vulnerability in the Linux kernel's KVM SVM implementation for SEV/SEV-ES virtual machines. It allows a crash or u...

Jul 25, 2025
CVE-2025-38458
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ATM CLIP (Classical IP over ATM) subsystem allows local attackers to cause a kernel pan...

Jul 25, 2025
CVE-2025-38408
5.5

A NULL pointer dereference vulnerability in the Linux kernel's genirq/irq_sim module occurs when simulation work context pointers are not properly ini...

Jul 25, 2025
CVE-2025-38398
5.5

A memory corruption vulnerability in the Linux kernel's SPI-QPIC-SNAND driver allows out-of-bounds memory access when handling NAND flash operations. ...

Jul 25, 2025
CVE-2025-38381
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's cs40l50-vibra driver where memory allocation failure isn't properly handled. Thi...

Jul 25, 2025
CVE-2025-38371
5.5

A race condition in the Linux kernel's v3d graphics driver allows interrupts to be triggered during GPU resets, leading to NULL pointer dereferences a...

Jul 25, 2025
CVE-2025-38362
5.5

A null pointer dereference vulnerability in the Linux kernel's AMD display driver could cause kernel crashes or denial of service. This affects system...

Jul 25, 2025
CVE-2025-38364
5.5

A Linux kernel vulnerability in the maple_tree subsystem causes improper handling of the MA_STATE_PREALLOC flag in mas_preallocate(). This can lead to...

Jul 25, 2025
CVE-2025-38368
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's tps6594-pfsm driver. If exploited, it could cause a kernel panic or ...

Jul 25, 2025
CVE-2025-38337
5.5

This CVE addresses a null pointer dereference and data race condition in the Linux kernel's jbd2 journaling subsystem. Attackers could potentially cau...

Jul 10, 2025
CVE-2025-38319
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's AMD GPU driver. If exploited, it could cause a kernel panic or syste...

Jul 10, 2025
CVE-2025-38304
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's Bluetooth subsystem within the eir_get_service_data function. This vulnerability...

Jul 10, 2025
CVE-2025-38308
5.5

This CVE describes a null pointer dereference vulnerability in the Linux kernel's ASoC Intel AVS driver. If exploited, it could cause kernel crashes o...

Jul 10, 2025
CVE-2025-38269
5.5

A NULL pointer dereference vulnerability in the Linux kernel's Btrfs filesystem could cause kernel panic or system crash when CONFIG_BUG is disabled. ...

Jul 10, 2025
CVE-2025-38274
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's FPGA manager test function fpga_mgr_test_img_load_sgt(). This could cause kernel...

Jul 10, 2025
CVE-2025-38266
5.5

A NULL pointer dereference vulnerability in the Linux kernel's MediaTek pinctrl subsystem causes kernel crashes on v1 platform devices. This affects L...

Jul 10, 2025
CVE-2025-38263
5.5

A NULL pointer dereference vulnerability in the Linux kernel's bcache subsystem allows local attackers to cause a kernel panic (denial of service) by ...

Jul 9, 2025
CVE-2025-47119
5.5

Adobe Framemaker versions 2020.8, 2022.6 and earlier contain a NULL pointer dereference vulnerability that allows attackers to cause denial-of-service...

Jul 8, 2025
CVE-2025-49524
5.5

Adobe Illustrator versions 28.7.6, 29.5.1 and earlier contain a NULL pointer dereference vulnerability that allows attackers to crash the application ...

Jul 8, 2025
CVE-2025-43583
5.5

Substance3D Viewer versions 0.22 and earlier contain a NULL pointer dereference vulnerability that allows attackers to cause denial-of-service by cras...

Jul 8, 2025
CVE-2025-38220
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ext4 filesystem can cause kernel crashes when processing orphaned symlink inodes. This ...

Jul 4, 2025
CVE-2025-38214
5.5

A null pointer dereference vulnerability in the Linux kernel's framebuffer subsystem allows local attackers to cause a kernel panic (denial of service...

Jul 4, 2025
CVE-2025-38203
5.5

A null pointer dereference vulnerability in the Linux kernel's JFS filesystem allows local attackers to trigger a kernel panic (denial of service) by ...

Jul 4, 2025
CVE-2025-38208
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's SMB client automount functionality. When tcon->origin_fullpath is se...

Jul 4, 2025
CVE-2025-38191
5.5

A NULL pointer dereference vulnerability in the Linux kernel's ksmbd module allows denial-of-service attacks when clients set PreviousSessionId during...

Jul 4, 2025
CVE-2025-38197
5.5

A NULL pointer dereference vulnerability in the Linux kernel's dell_rbu driver allows local attackers to cause denial of service or potentially escala...

Jul 4, 2025
CVE-2025-38184
5.5

A null pointer dereference vulnerability in the Linux kernel's TIPC (Transparent Inter-Process Communication) subsystem allows local attackers to caus...

Jul 4, 2025
CVE-2025-38189
5.5

A NULL pointer dereference vulnerability in the Linux kernel's v3d graphics driver allows local attackers to cause a kernel panic (denial of service) ...

Jul 4, 2025
CVE-2025-38181
5.5

A NULL pointer dereference vulnerability in the Linux kernel's CALIPSO subsystem allows denial-of-service attacks when SYN cookies are enabled. The vu...

Jul 4, 2025
CVE-2025-38167
5.5

A NULL pointer dereference vulnerability in the Linux kernel's NTFS3 filesystem driver could cause kernel crashes or denial of service. This affects s...

Jul 3, 2025
CVE-2025-38171
5.5

A NULL pointer dereference vulnerability in the Linux kernel's max77705 power supply driver could cause kernel panics or system crashes when device pr...

Jul 3, 2025
CVE-2025-38163
5.5

This CVE describes a NULL pointer dereference vulnerability in the Linux kernel's F2FS filesystem driver. When processing a specially crafted filesyst...

Jul 3, 2025
CVE-2025-38145
5.5

A NULL pointer dereference vulnerability exists in the Linux kernel's aspeed_lpc_enable_snoop() function due to missing NULL check after memory alloca...

Jul 3, 2025

About NULL Pointer Dereference (CWE-476)

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Our database tracks 1,252 CVEs classified as CWE-476, with 21 rated critical and 303 rated high severity. The average CVSS score for NULL Pointer Dereference vulnerabilities is 6.1.

External reference: View CWE-476 on MITRE CWE →

Monitor NULL Pointer Dereference Vulnerabilities

Get alerted when new NULL Pointer Dereference CVEs affect your infrastructure.

Start Monitoring Free